New Jersey

New Jersey DGE Announces Second Geolocation-Failure Operator Fine

The New Jersey Division of Gaming Enforcement has, for the second time, announced a fine levied against an online-gambling operator or a third-party service provider related to failures in the geolocation protocols intended to prevent out-of-state gamblers from wagering on New Jersey’s licensed sites. This time, the DGE has announced a $25,000 fine levied against Malta’s Gaming Innovation Group (GiG) for a flaw in its geolocation protocols that allowed a Nevada-based gambler to spoof his location and appear to be located within New Jersey.

Though only a small wagering sum was involved, Gaming Innovation Group received a reasonably severe wristslap. The unnamed Nevada gambler lost the princely amount of $29 on www.hardrockcasino.com, the online home of Hard Rock Atlantic City, at casino games. The incident occurred sometime before July 4, 2018, when a geolocation audit of GiG’s services uncovered a browser-based vulnerability that allowed users with sufficient technical skill to change the data being transmitted to GiG’s servers and thus falsely report the gambler’s computer as being within New Jersey.

Discovery of the vulnerability led to a short-term (and previously unreported) shutdown of the hardrockcasino.com site last July, for a handful of hours, while a fix was put into place. Then came the work of seeing if anyone had exploited the vulnerability and spoofed his location, and it turned out that a single Nevada-based gambler had done so. (Nevada has legalized online poker but, to date, has not legalized any other form of online gambling, thus explaining in part the Nevada gambler’s interest in the NJ-based site.)

The DGE did not file its mandatory complaint about the vulnerability until December 12, 2018, and the two sides then negotiated the appropriate penalty for what was an isolated instance but could have been a significant issue. DGE director David L. Rebuck signed the director’s action confirming the $25,000 fine against GiG on April 30, 2019.

According to Associated Press writer Wayne Parry, who covers the New Jersey gambling beat, the DGE “did not take adequate steps ensure that the computer server made the final call on whether a patron was within New Jersey. Instead, the patron was able to trick the system.” More on this in a bit.

“This one-off single incidence of out-of-state gambling was due to a technical vulnerability which was quickly discovered and reported to the regulator in New Jersey in the first week the company went live in New Jersey,” Gaming Innovation said to Parry. “An end user from outside the state of New Jersey with technical knowledge managed to access the front end debugger to change the location and pretend to be from New Jersey.”

There’s just a little bit of an unanswered question regarding this situation, which is the second time an out-of-state gambler has successfully evaded New Jersey’s largely-robust geolocation defenses. That question is: How did the site manage to go live in the first place that allowed user-changeable browser data to be employed as the sole indicator of a customer’s supposed location? The hardrockcasino.com site was live for real money for less than a week before the vulnerability was detected and fixed. However, it should never have made it to the live-money stage in the first place.

Given that this was a fuck-up engineered by GiG, it still should have been caught by the New Jersey DGE’s pre-launch testing of the products and protocols being submitted for approval. The DGE itself bears some secondary responsibility for this violation to have occurred, not the first time the agency has screwed the pooch on someone else’s dime. Ah, well, we’re all imperfect creatures, right?

COMMENTS

Leave a Comment

*

LATEST NEWS

filter by

Dan Katz

19th May 2019 // Industry, Legal News, News

Three More States Legalize Sports Betting

Last year was the year of sports betting, as the U.S. Supreme Court overturned PASPA, killing the law that made sports...

Haley Hintze

18th May 2019 // Industry, Misc, News, Online Poker Action

PartyPoker Identifies and Closes Another 91 Bot Accounts in April

Partypoker has published the second update in what it promises will be a series of monthly updates regarding...

Dan Katz

17th May 2019 // Industry, Legal News, Misc, News

Georgia Governor Worried Wire Act Opinion Could Hurt Lottery

It must be a really bad feeling when someone who you thought liked you actually didn’t give a shit about you at all,...

Haley Hintze

17th May 2019 // Gossip, Industry, Legal News, Misc, News

Austria Legal Advocacy Firm Advofin Plans Shakedown of EU Online Gambling Operators

An Austrian legal advocacy firm, Advofin, has launched what the vast majority of the European Union’s...

Haley Hintze

17th May 2019 // Industry, Legal News, News

UKGC Slaps Fines on Four More Online Gambling Operators

The United Kingdom Gambling Commission (UKGC), has slapped another series of fines on UK-licensed operators. This...

Haley Hintze

14th May 2019 // Legal News, Misc, News

IRS Seizes Over $4M in Piracy Case Involving Oregon “Professional Poker Player”

One of the strangest stories in recent memory to touch on the fringes of the poker world continues playing out in a...