Pinnacle's Reply To Security Question

Search

sd2

New member
Joined
Sep 21, 2004
Messages
1,928
Tokens
Earlier today I emailed Pinnacle to ask if their requirement that customers change thier password was related to any security threat to thier online opetation. Here is the reply I received.


Dear Sir,

Please always provide your client ID for a prompt reply.


Regarding your question please be informed that it is because of Pinnacle Sports' ongoing commitment to provide the safest and most secure environment for all your gaming needs that we upgraded our network security in anticipation of the busiest sports betting weekend of the year - the Super Bowl.
While your password may have met the new requirements, many passwords did not. In addition, it is an industry standard that passwords should be changed every three months. It is also not recommended by many internet security experts to use the same password at multiple locations.


Regards,

There's a lot of stonewalling in the response. Did Pin require clients to change their pw before last year's super bowl? Or the year before that? And the stuff about "industry standard" and recommendations by "industry experts" is strictly gratuitous. It may be true, and sound advice, but has nothing to do with the issue at hand.

I think it quite likely that Pinnacle did have a security issue, either via hackers,a disgruntled ex-employee with some client data, or whatnot. How much better it would be if they respected the intelligence of their clientele and said "we did have a security issue, but we fixed it. And just to keep it that way in the future, we are asking everyone to change their pw."

Much better than stonewalling. My consolation is that now everyone has to use a six digit pw!
 

New member
Joined
Feb 1, 2005
Messages
7,373
Tokens
It has been that way for a long time. If you didn't have a 6+ digit password before than you have been there for a few years at least. Not sure about it being an industry standard...I know of at books where you can do 3 letters as a password.

sd2 said:
Earlier today I emailed Pinnacle to ask if their requirement that customers change thier password was related to any security threat to thier online opetation. Here is the reply I received.


Dear Sir,

Please always provide your client ID for a prompt reply.


Regarding your question please be informed that it is because of Pinnacle Sports' ongoing commitment to provide the safest and most secure environment for all your gaming needs that we upgraded our network security in anticipation of the busiest sports betting weekend of the year - the Super Bowl.
While your password may have met the new requirements, many passwords did not. In addition, it is an industry standard that passwords should be changed every three months. It is also not recommended by many internet security experts to use the same password at multiple locations.


Regards,

There's a lot of stonewalling in the response. Did Pin require clients to change their pw before last year's super bowl? Or the year before that? And the stuff about "industry standard" and recommendations by "industry experts" is strictly gratuitous. It may be true, and sound advice, but has nothing to do with the issue at hand.

I think it quite likely that Pinnacle did have a security issue, either via hackers,a disgruntled ex-employee with some client data, or whatnot. How much better it would be if they respected the intelligence of their clientele and said "we did have a security issue, but we fixed it. And just to keep it that way in the future, we are asking everyone to change their pw."

Much better than stonewalling. My consolation is that now everyone has to use a six digit pw!
 

New member
Joined
Sep 21, 2004
Messages
3,447
Tokens
Maybe they are just being cautious?

Would it be better if they had waited for a hacker or disgruntled employee before instituting a more secure system?

Honestly, this has to be one of the biggest non-issues turned into big issue on this site.
 

sd2

New member
Joined
Sep 21, 2004
Messages
1,928
Tokens
Well, it may not be a major issue, but when I got popups the last few weeks telling me that the Pin security certificate is not to be trusted, and then this, it is at least something of an issue. Pinnacle could have made it a non-issue by being forthright, and by informing people that the pws would soon be requiring changing.

A bit high-handed, don't you think?
 

Member
Joined
Sep 20, 2004
Messages
1,450
Tokens
Sounds like rubbish to me. Something is up for sure. Now way they jsut decided to fuck around with this crap a week before their biggest weekend of the year. They must of had some security breach, maybe a threat from an ex-employee who had access to players un's and passwords or something.
 

New member
Joined
Jul 20, 2002
Messages
6,480
Tokens
sd2 said:
I think it quite likely that Pinnacle did have a security issue, either via hackers,a disgruntled ex-employee with some client data, or whatnot.

I'm inclined to agree as did Labeda. It is also standard security to make no comment, as has occurred on the two occasions when my bank had to change my credit card number. The information in their email is correct and valuable.

My first concern when seeing the notice of password change was to make sure that I had not been diverted to a dummy site that was trying to get access to my account. After I was assured I changed from 6 to 8 alphanumerics.
 

New member
Joined
Oct 16, 2005
Messages
528
Tokens
Ladeda said:
Sounds like rubbish to me. Something is up for sure. Now way they jsut decided to fuck around with this crap a week before their biggest weekend of the year. They must of had some security breach, maybe a threat from an ex-employee who had access to players un's and passwords or something.

Definitely the most on target statement I've seen. Our IDs are somewhat randomly generated, so someone would have to try 10,000 logins before standing a somewhat reasonable chance of coming up with a success if they had someone's name and password from another site. And that could be handled on a case by case basis. I see no reason for them to do this unless someone stole user ID info.
 

New member
Joined
Feb 4, 2003
Messages
3,271
Tokens
nimue77 said:
It has been that way for a long time. If you didn't have a 6+ digit password before than you have been there for a few years at least. Not sure about it being an industry standard...I know of at books where you can do 3 letters as a password.


I had a 3-letter password up unitl this morning
 

New member
Joined
Feb 1, 2005
Messages
7,373
Tokens
You had a nice advantage, sucks to be you. This levels the playing field.

drunkguy said:
I had a 3-letter password up unitl this morning
 

New member
Joined
Jul 20, 2002
Messages
6,480
Tokens
All my passwords are Control-V. In fact I never even look at them normally, since they are held in an encrypted database used solely for that purpose. Now all I need to remember is the password for the database.
 

Back from the Ban
Joined
Oct 13, 2004
Messages
3,606
Tokens
woody, would be interested in knowing how to put multiple pass's on control v.

I give the mods permission to release my email to woody0
 

W-R-X Champion
Joined
Dec 21, 2004
Messages
17,101
Tokens
Yea my password was the standard 2 letter initials and yes I was concerned here and there but how would anyone know my account number. Then it hit me!
 
Joined
Sep 21, 2004
Messages
28,775
Tokens
Anything under 8 characters isn't that tough to break. I have a couple friends that I don't even want to ask because I know the answer will be "Well, duh".

3 digits is insane
 

New member
Joined
Feb 1, 2005
Messages
7,373
Tokens
How do you set it so you can control v with multiple books? Ths is the first i've heard of this..

Budworth22 said:
Only a moron would type their password. Control +V anyone?
 

New member
Joined
Sep 21, 2004
Messages
818
Tokens
I probably needed to change it anyway. No big deal. What is 'Control V'? A password manager?
 

Forum statistics

Threads
1,108,708
Messages
13,453,699
Members
99,429
Latest member
AnthonyPoi
The RX is the sports betting industry's leading information portal for bonuses, picks, and sportsbook reviews. Find the best deals offered by a sportsbook in your state and browse our free picks section.FacebookTwitterInstagramContact Usforum@therx.com