New Jersey

New Jersey DGE Announces Second Geolocation-Failure Operator Fine

The New Jersey Division of Gaming Enforcement has, for the second time, announced a fine levied against an online-gambling operator or a third-party service provider related to failures in the geolocation protocols intended to prevent out-of-state gamblers from wagering on New Jersey’s licensed sites. This time, the DGE has announced a $25,000 fine levied against Malta’s Gaming Innovation Group (GiG) for a flaw in its geolocation protocols that allowed a Nevada-based gambler to spoof his location and appear to be located within New Jersey.

Though only a small wagering sum was involved, Gaming Innovation Group received a reasonably severe wristslap. The unnamed Nevada gambler lost the princely amount of $29 on www.hardrockcasino.com, the online home of Hard Rock Atlantic City, at casino games. The incident occurred sometime before July 4, 2018, when a geolocation audit of GiG’s services uncovered a browser-based vulnerability that allowed users with sufficient technical skill to change the data being transmitted to GiG’s servers and thus falsely report the gambler’s computer as being within New Jersey.

Discovery of the vulnerability led to a short-term (and previously unreported) shutdown of the hardrockcasino.com site last July, for a handful of hours, while a fix was put into place. Then came the work of seeing if anyone had exploited the vulnerability and spoofed his location, and it turned out that a single Nevada-based gambler had done so. (Nevada has legalized online poker but, to date, has not legalized any other form of online gambling, thus explaining in part the Nevada gambler’s interest in the NJ-based site.)

The DGE did not file its mandatory complaint about the vulnerability until December 12, 2018, and the two sides then negotiated the appropriate penalty for what was an isolated instance but could have been a significant issue. DGE director David L. Rebuck signed the director’s action confirming the $25,000 fine against GiG on April 30, 2019.

According to Associated Press writer Wayne Parry, who covers the New Jersey gambling beat, the DGE “did not take adequate steps ensure that the computer server made the final call on whether a patron was within New Jersey. Instead, the patron was able to trick the system.” More on this in a bit.

“This one-off single incidence of out-of-state gambling was due to a technical vulnerability which was quickly discovered and reported to the regulator in New Jersey in the first week the company went live in New Jersey,” Gaming Innovation said to Parry. “An end user from outside the state of New Jersey with technical knowledge managed to access the front end debugger to change the location and pretend to be from New Jersey.”

There’s just a little bit of an unanswered question regarding this situation, which is the second time an out-of-state gambler has successfully evaded New Jersey’s largely-robust geolocation defenses. That question is: How did the site manage to go live in the first place that allowed user-changeable browser data to be employed as the sole indicator of a customer’s supposed location? The hardrockcasino.com site was live for real money for less than a week before the vulnerability was detected and fixed. However, it should never have made it to the live-money stage in the first place.

Given that this was a fuck-up engineered by GiG, it still should have been caught by the New Jersey DGE’s pre-launch testing of the products and protocols being submitted for approval. The DGE itself bears some secondary responsibility for this violation to have occurred, not the first time the agency has screwed the pooch on someone else’s dime. Ah, well, we’re all imperfect creatures, right?

COMMENTS

Leave a Comment

*

LATEST NEWS

filter by

Dan Katz

16th July 2019 // Industry, News

David Oppenheim, Chris Moneymaker Elected to Poker Hall of Fame

The third and final night of the 2019 World Series of Poker Main Event final table is tonight, but there was other...

Haley Hintze

16th July 2019 // Legal News, Misc, News

Backer Lawsuit Against Maurice Hawkins Comes to Light

An alleged failure to pay back $103,000 to a backer has Florida poker pro Maurice Hawkins in continuing legal...

Haley Hintze

16th July 2019 // Industry, Legal News, Misc, News

Suncity Macau Junket Operation Under Duress Amid Online Gambling Accusations

There’s again a sense of unease in the junketeering world through which affluent Chinese gamblers have been able...

Haley Hintze

14th July 2019 // Legal News, Misc, News

Southern Missouri Cardroom Raided, Closed by Authorities

A relatively new poker room that attempted to operate in Missouri’s capital city of Springfield has been...

Haley Hintze

14th July 2019 // Industry, Misc, News

Rob Yong, John Duthie Announce Launch of Anti-Cheating Cooperative Fairplay

UK-based online-poker stalwarts Rob Yong and John Duthie have announced the launch of Fairplay, an anti-cheating...

Haley Hintze

12th July 2019 // Legal News, Misc, News

WPT Winner Dennis Blieden Charged with Embezzlement of $22 Million

Ohio native and current Nevada resident Dennis Blieden, known best in poker circles for winning the 2018 World Poker...