I have this feeling that the other shoe is about to drop, and we're going to find out something big is missing from the reporting, they they had a friend working at the company.
Also, this logic:
“All these guys did is simply push a sequence of buttons that they were legally entitled to push.”
is very annoying. You can describe any illegal action as innocuous. I'm not saying this case deserves to be hacking (IMHO if you learn, say, that the sequence of cards resets every 256th turn through, more power to you), but this is a weak argument.
Not that weak. Imagine you had computer chess instead of computer poker, and imagine you discovered that if you play black and choose some special kind of Sicilian defense, the computer plays very weakly because of the bug in the algorithm and your chances of winning are greater. Is that illegal now? Would it be illegal if you played chess with human (for a wager) and knew he's weak at certain positions and specifically played for those? Using opponent's weakness in the specific area of the game to win is a very common thing in sports, not making it illegal in casino setting is a very strong argument IMO.
Doing something like magnets is different of course because it violates implicit assumption of the playing on the machines, but just pressing buttons is not.
If he outsmarted the poker-logic, I'd say great for him. If the game always shuffled two aces next to each other, that would be fine knowledge for him to use.
He didn't use something like that, though. The payout was supposed to be $820 and by messing with the denominations he got it to be $8,200.
No, by the very rules of the game (the code), the payout was supposed to be $8200, and the machine dispensed it accordingly.
To impose criminal liability upon someone because they didn't make the assumption that the programmer/casino/manufacturer really meant for something else to happen instead is an exceptionally dangerous state of affairs.
Weev is doing 41 months right now for conspiracy to commit unauthorized access and identity fraud (possession of a list of email addresses) because his team spidered a website run by AT&T. AT&T themselves said that there was no crime and no damages, and said in court that they (AT&T) were the ones who published the data on the web.
The US Attorney felt differently, and now he's in federal prison for a few years while we try to sort out his appeal.
This is what happens when you make someone who requests data or a system state change criminally liable for that independent, autonomous system responding with data or changing to that state by its own software's defined operation. It's a blatant misapplication of responsibility.
The rules of the game are not in the code. If the bug would be the other way around, where it would suddenly payout 82$ if you'd press this sequence of buttons, the casino would definitely return the money.
It's like giving money to strangers. If you surprise them by giving them money that's OK, it's your money. If you surprise them by stealing from them, that's not OK.
So a game that surprises you by giving more winnings than expected is fine; a game that suddenly reduces the winnings by taking some of the money you've won is not fine.
Or another way: Sometimes I feel generous and forgo a customer the decimal part of their bill to save them trying to find the money or if they haven't enough, that's fine, it's my "game". I can't decide to take their change though.
When the giving more is built in to the game, so you play it a a particular way and the you win more, that's just a game that you're winning.
I can't seem to find a source for this but I remember reading an article about Kasparov playing Deep Blue talking about how Kasparov intentionally tried to use some unpredictable moves to exploit Deep Blue's algorithm. I don't think anyone considered this cheating.
The issue is that we as a society expect the user to guess at the intent of the programmer (even when it seems obvious) instead of going by their code's behavior, which is fundamentally flawed. In the weev/ATT thing, they were even leveraging this insane duality for profit - the publishing of the email addresses by ATT was an explicit design decision for user convenience, and they relied only on obscurity and the law to protect the data. Weev and Gawker made sure that the obscurity argument was a non-starter, and we'll see about the legal one in the next few years.
I think that the casinos should have the liability, because they are the ones who deployed automatic money dispensers with poorly-designed software running on them. I don't see criminal behavior, here. If you program (or load software) onto your robot, you are responsible for when it carries out those instructions, even if you did not fully envision the consequences in advance. Same goes for replying to packets on the internet. It's impossible to rob a server of information at gunpoint.
This is DWIM carried through the machine and legally imposed onto the end-user, and that's a load of crap.
Fortunately we don't live in the wild west. If the bank forgets to lock its vault it's not free money season.
He didn't just find some way to, say, outsmart the random number generator. (And I think that would be fine: casinos encourage people to think they have founds ways to beat the system, because they keep on trying them, putting more money in the casinos' pockets. If someone manages to somehow actually beat the system, good for him.) He found a bug in the payout calculator.
If you figure out a way to press buttons on an ATM that makes your withdrawal credited as a deposit, it's neither legal or right to repeatedly exploit that. There is no "gee, I really thought it meant to do that."
You are forcing people to make assumptions about the intent of a system with a defined interface.
An ATM has but one function, assumptions about those seem reasonable (though I think laws against using them without those assumptions are unnecessary, as ATM operators are incentivized already to prevent circumstances in which they lose money). When you generalize that to remote computers, or touchscreen gaming, it becomes less reasonable to force users of those systems to assume the intent of the programmer to stay out of jail.
It's a much more elegant and workable and fair solution to simply let the rule lie with the code, which is defined formally, and let the potential negative consequences of deploying code that is not fully understood incentivize people to be careful about what they deploy for interaction with the general public (be it slots, ATMs, or networked computers).
(An aside, PLEASE stop with the terrible physical analogies about locks and vaults. They are simple straw man arguments. It is impossible to break a lock by force over the internet, or to rob a web service at gunpoint. The intent of a locked door is a safe and reasonable assumption to make, and to punish others for not making. That is simply not so on the internet - a perfect example being spidering email addresses from a public web service that was expressly configured to emit them.)
It is disingenuous to assume that we as a society should leave this to courts full of non-technical people to determine what is and is not disingenuous in terms of end-user assumptions about the correct workings of a system, versus letting the responsibility lie simply on the operators of that system because THEY ARE RESPONSIBLE FOR DEPLOYING IT.
The harm that this is causing is already great, and will increase tremendously. It's simply dangerous to say "it's obvious" because, while this case may or may not be, to have to make a determination of obviousness of the intent of the programmer/casino/bank/whatever, is something courts are famously bad at. You really don't want that state of affairs.
I have this feeling that the other shoe is about to drop, and we're going to find out something big is missing from the reporting, they they had a friend working at the company.
I doubt it - all that he would have had to do to discover this bug was to accidentally press "change game" at the point where it offered him the double-or-nothing, which would be easy to do if he was intending to press "no" then "change game" in quick succession.
I don't think it's black and white. Inserting money into the machine and pressing buttons is a lot more innocuous than, say, taking a screwdriver to the machine, manipulating it with an electromagnet, etc. I can't think of any way to describe those kind of manipulations in an innocuous manner.
The point is using the phrasing "inserting money into the machine and pressing buttons" is intended to distract from the actual legal question around more difficult questions of intent and liability: if someone willfully exploits a bug in a poker video game, are they guilty of a crime?
Also, this logic:
“All these guys did is simply push a sequence of buttons that they were legally entitled to push.”
is very annoying. You can describe any illegal action as innocuous. I'm not saying this case deserves to be hacking (IMHO if you learn, say, that the sequence of cards resets every 256th turn through, more power to you), but this is a weak argument.