Live data from Hacker News

Reverse engineering Ticketmaster's rotating barcodes

conduition.io

181–190 of 737 posts

Re: Reverse engineering Ticketmaster's rotating barcodes

#181

This sort of ticketing thing is a trivially solvable problem. It is solved at every airport in the entire world millions of times per day. You provide the name of each concertgoer when you buy a ticket, and they show up with their ticket and ID. You often need to show your ID at these kinds of venues to prove you're old enough to drink beer anyway.

That requires a single source of truth for which names go with which tickets. Which is going to be a problem if tickets need to be transferred in contexts where users don't have internet access (but they do have local connectivity between devices) or in contexts where the venue doesn't have internet access. Or in cases where the single source of truth might be vulnerable to attack or doesn't have the resources to han…

> Which is going to be a problem if tickets need to be transferred in contexts where users don't have internet access (but they do have local connectivity between devices) or in contexts where the venue doesn't have internet access.

You know as well as I do that TicketMaster won't allow any of that, because it means they miss out on selling another ticket.

Re: Reverse engineering Ticketmaster's rotating barcodes

#182

With regards to the end of the article. > Can I work for a bad company and still be a good person? > No. https://apenwarr.ca/log/20201121

I think we should make an exception for saboteurs.

And whistle blowers. And double agents.

Re: Reverse engineering Ticketmaster's rotating barcodes

#183
post #128

> Software developers are the wizards and shamans of the modern age. We ought to use our powers with the austerity and integrity such power implies. This is one of the most powerful truths underlying the world we currently inhabit. The sooner we can agree to behave accordingly, the better our prospects for ripping the reigns of society from the hands of those whose only animating principles are avarice and exploitati…

Programmers being analogous to wizards or martial artists made more sense back when one used to need to train years or decades to become one. With age comes wisdom. There has been a lot of good that came from making coding more accessible; I'm not trying to gatekeep. But I do think that this is one instance where the outcome is worse. The martial arts masters still unquestionably exist among us. It's just that they'r…

Yes I think there is truth to this. Something I have seen lately with Rust for example, is because the language is harder to learn, the discourse, tutorials, libraries are all much higher quality.

Re: Reverse engineering Ticketmaster's rotating barcodes

#184
post #127

Earlier quoted context omitted.

There's no way that I trust the developers of a company like Ticketmaster to install their app on my device.

You don't trust your OS to sandbox it? With a threat model like that, I wouldn't use any apps other than the browser

Maybe you are using a fully open phone, but mine has an OS made by Google and almost every app tracks my location without my consent.

Re: Reverse engineering Ticketmaster's rotating barcodes

#185
It's one thing for customers phones' wifi issues to be a problem, but it's an even worse problem if the scanner itself needs reliable connectivity. That makes me wonder if there is some kind of delegated deterministic derivation step in the secrets too (which wouldn't be obvious in this kind of analysis), so that the handheld scanners can avoid an on-line dependency.

Re: Reverse engineering Ticketmaster's rotating barcodes

#186

Earlier quoted context omitted.

This way you can sell and have the ticket completely off of ticketmaster. That is a vulnerability. It lets users do something they explicitly don't want to allow.

Assuming that you can actually do that. If the seller re-opens the TM app and it generates a new token and invalidates the old one, then that's not the case.

Vulnerability to LN business practices. Not a system vulnerability.

Re: Reverse engineering Ticketmaster's rotating barcodes

#187

Earlier quoted context omitted.

Yup exactly. Some events are pretty bad at opening the doors early. The Brooklyn Nets seem to open 30 minutes before the game, so they need to get 20,000 people through 20 metal detectors in 30 minutes. Every second extra they add to the process is a second you don't have to buy a $25 drink, and that's how they make their money. We check IDs for flights because airline yield management demands that there be no resale…

>We check IDs for flights because airline yield management demands that there be no resale, or business travelers would be traveling on leisure fares. Sorry, what? Surely business travelers pay more just by virtue of traveling by business class? Or, if travel through business portals was consistently significantly more expensive than just buying the ticket directly on the airline's website, businesses would just star…

Last minute / next day fares have traditionally been far more expensive than 3 week advance, and that was intended to impact business travel more than leisure. If there was a 3rd party marketplace for airline tickets, last minute tickets would not be nearly as expensive and the airlines would make far less money.

Consider an example where we have a business traveler "Bob" and a leisure traveler "Larry". Bob needs to get to LAX tomorrow to put out a fire at a client site. Larry has a trip booked to LAX tomorrow, but can't go because he's sick. Larry has paid $500 for the trip 3 weeks ago.

Today: Larry cancels his trip, and maybe, if he's lucky, gets an airline credit for the original price of the trip that expires in a year and which may be hard to use for his next trip. When he cancels, a seat opens up on the plane, and the airline sells it to Bob for $1200.

If resale was permitted: Larry auctions off his ticket at an airline ticket reseller. He gets $700 from Bob. So if resale was permitted, Bob's business saves $500, and Larry makes $200, and the airline looses $1200-$1700. You can see why they hate resale.

Re: Reverse engineering Ticketmaster's rotating barcodes

#188
post #20

Another case of abusing ToTK, an excellent technology that promised convenience, security, and offline access. Similarly, Duo builds their stuff off ToTK and then fending off (or makes it very, very hard) you from using a third-party ToTK authenticator with their sites. This company just jettisons the fine promise of available offline that was made by ToTK.

Tears of the Kingdom?

Re: Reverse engineering Ticketmaster's rotating barcodes

#189
post #120

Earlier quoted context omitted.

I'm glad we cleared that up. Now all that remains is a good, measurable definition of what a bad company is.

It's not hard if you remove the self delusion. Removing the self delusion is maybe tricky for the individual, but it's easy for people around the individual to see. Societal tools like shame are generally used to encourage people in the right direction, but we don't do a great job of this in America, because money tends to override everything else and I don't think we have good structures around expressing non-moneta…

Yup. I was just discussing this in another comment that Facebook's emotional manipulation of users without consent is ethical wrong. Some people are replying with eh, everybody does it and for 20,000 dollars people will jump to Facebook.

I think the Leetcode grinding, TC optimizing crowd with no real moral judgment which is the majority in tech right now is another reason why things are falling apart. They will happily work for the KKK if they get a larger RSU package.

Your point about them being at least "sad" about it, is a start I guess.

Re: Reverse engineering Ticketmaster's rotating barcodes

#190

This sort of ticketing thing is a trivially solvable problem. It is solved at every airport in the entire world millions of times per day. You provide the name of each concertgoer when you buy a ticket, and they show up with their ticket and ID. You often need to show your ID at these kinds of venues to prove you're old enough to drink beer anyway.

Flying requires an ID. Attending a concert should not. Any solution that is solved by "simple, just require an ID" is not a solution.

> Flying requires an ID. Attending a concert should not.

Why though? Not disagreeing per say because I'd have thought so too, but upon reflection...

I assume the main reason airlines require an ID is safety and security. We maintain a denied parties list and use identity verification to make it as difficult as possible to fly a plane into a crowded venue. Border control is another issue, but there's plenty of intra-country or intra-state flights where this isn't an issue.

Ticketmaster sells unverified access to crowded venues.

Post reply on HN