Live data from Hacker News

Getting my library cards onto my phone the hard way

iliana.fyi

1–10 of 181 posts

Re: Getting my library cards onto my phone the hard way

#2
> for some reason, passes are cryptographically signed, and they have to be signed with a key known to one of Apple’s certificate authorities. Cryptographically signing these files makes some sense when you consider that passes were designed to get automatic updates from their vendors; for example, your boarding pass for a flight reflecting gate changes or changing your seat assignment.

How does this make sense? There’s a perfectly well supported system for doing this: HTTPS.

Maybe Apple wants passes to be verifiable by the phone offline instead of just when updated? This still seems silly — a malicious actor could replace a pass instead of updating it.

Re: Getting my library cards onto my phone the hard way

#4
Oooh, now do Orca cards next. Seattle is one of the tech capitals of the United States, and on top of the metro system just being not great, it's also technically inferior to nearly every single other major city that I've used public transit. Pick any European city, CDMX, Denver. They're all light years ahead of Seattle. Denver might have been my favorite.

Fun fact, one of the orgs that runs Orca actually wrote a blog post mentioning they were adding NFC support to their Android app (with some absurdly long timeline). That post is no longer to be found, and of course, years later, that functionality is absent.

Re: Getting my library cards onto my phone the hard way

#5
So wait: you don't want to pay Apple $99 and you don't want to pay for one of the apps that generates a pass for you, but you'll extract the cert from one of those apps thereby piggybacking on another developer's $99 payment to Apple.

That's uncool.

On a slightly related note: a site I login to regularly uses Semantic VIP Access for 2FA. You can convert these to standard TOTP codes so that you can load them into the Apple Keychain or whatever other TOTP program you prefer:

https://github.com/dlenski/python-vipaccess

Re: Getting my library cards onto my phone the hard way

#6
> But having the barcode is far more convenient, and I’d like to have it without having to keep yet another plastic card I rarely use in my wallet.

> So I put it on my phone, in my iPhone’s Wallet app

Another option would be to literally put the barcode on the phone.

Print it on a small piece of paper, about 15mm wide, and tape it to the back of the phone with some transparent tape.

Re: Getting my library cards onto my phone the hard way

#7
post #6

> But having the barcode is far more convenient, and I’d like to have it without having to keep yet another plastic card I rarely use in my wallet. > So I put it on my phone, in my iPhone’s Wallet app Another option would be to literally put the barcode on the phone. Print it on a small piece of paper, about 15mm wide, and tape it to the back of the phone with some transparent tape.

Or take a picture of card and store it in a note. I do this for things like my insurance cards, driver license, etc.

Re: Getting my library cards onto my phone the hard way

#9
post #3

So.. I just added my card to Stocard and used it a King County. Took 2 minutes, on my phone, synced across devices. Or yeah, you could do it that way I guess.

This eliminates the need for multiple wallets. Plus it's a fun hack.

Stocard addresses a different point in the design space.

Re: Getting my library cards onto my phone the hard way

#10
post #5

So wait: you don't want to pay Apple $99 and you don't want to pay for one of the apps that generates a pass for you, but you'll extract the cert from one of those apps thereby piggybacking on another developer's $99 payment to Apple. That's uncool. On a slightly related note: a site I login to regularly uses Semantic VIP Access for 2FA. You can convert these to standard TOTP codes so that you can load them into the…

I think if you are locked out from doing what you want on your phone that you bought through arbitrary software locks then you should have the right to bypass that. This isn’t costing the app developer anything, nor were they even using the app to generate the pass, so I don’t really see any issue here
Post reply on HN