|
Zacarías Leone, Director of the firm ZL -Security Senior Consultant “A good security and control casino system is based in the continuous assessment on the new ways of attack and prevention”
Argentina | 07/02/2009 (Argentina).- With more than five years of experience in the gaming industry, the specialist in security and control of the information, Zacarías Leone, talked in exclusive with Yogonet.com on the different modalities of attack to slots and electronic roulettes in a casino, and the best strategies to reduce the risk in a gambling hall. How did you start working with information security applied to the gaming industry? In recent years, he was appointed by several judges and attorneys of the City of Buenos Aires as Technical Adviser and Official Expert in cases of illegal and clandestine gaming in Internet, cases with no precedents in Argentina so far. Importante National and International gaming companies chose our services in Assessment in Security and Computing Expertise. The experiences acquired all these years and the merits achieved led me to create the Consultant of Security Information ZL -Security Senior Consultant (ZL-SSC), positioned as one of the main companies from Argentina and Latin America in offering Gambling Security and Gambling Forensics services, among other services allocated to fraud prevention, detection and investigation, cheats, tricks, frauds, incidents, etc., which involves totally or partially the use of technologies in gambling venues and companies related to the gaming industry. In your view, how important is the security issue for casino operators? For example, the increment of internal robberies due to a lack of security procedures and secure and effective internal controls are growing considerably in the industry, as “Orleáns” case, where casino employees took advantage on the lack of controls on them and with regards to the maintenance and manipulation of their activities in slots and device, achieved, for a long time, to rob thousands of dollars passing totally unnoticed to casino controls. I am convinced that, nowadays, a good Security and Control system is based in the continuous assessment on the new forms of attack and prevention to managers of security in casinos and the implementation of new and improved internal security controls, both of software applications and policies and procedures acordes to the new ways of cheats, tricks, frauds, robberies, etc. How complex are the technologies that operators face when being attacked? Nowadays, our ZL-24/7 base registers in an online form, 24-7, incidents from all parts of the world, from different private agencies of investigations, mainly from Las Vegas, where operators and investigators are interested not only in capture those who use these technologies in their gambling venues, but also they want to know how are they utilized or which is the vulnerability that the modern systems have so that “bad guys” achieve their aims and they may defend from this type of attacks, so there is where our consulting firm, ZL – Security Senior Consultant, starts operating. Do you consider that techniques to vulnerate systems used in Latin America are as complex as the ones from other markets? Incidents such as the manipulation of true tickets mixed with false ones introduced in bill acceptors of slots, for example, is a technique applied to the control of special acceptors that are vulnerable to those attacks, or, for example, attacks to traditional or online roulettes through a technique called “ballistics measurements”, achieved through the hiding of a determined computing device in a simple cell phone, capable of predicting numbers or zones, sending previous results by Bluetooth technology to another participant of the band of cheaters in the same betting table. But not always there are swindlers, cheaters, thieves, etc.that do not belong to the company. Incidents that involve the bingo or casino team are not new and each time this type of incident is increasing. For example, the so-called Orleans case, in which the manipulation of a special application (firmware) and the lack of efficient controls from technicians of mantainance of gaming machines, achieved to obtain several thousands of dollars before being discovered through the use of TITO technology; or the case of the manipulation of “Counters” of the device and their adulteration in both a physical and logical level. Which is the basic investment that an operator should perform in order to have a secure business? Which are the new security trends in information for casinos and gambling venues? On the other hand, operating companies they are implementing controls on Information Security and Transparency, some of them based, for example, in international norms such as ISO/IEC 27001. Once this norm is implemented and certified in the company, it allows a better information control and security with regards to cases of adulteration or manipulation of internal information that may cause several incidents, the loss of credibility of the company, among others. Enclusive interview Yogonet.com |
