Live data from Hacker News

Reverse engineering Ticketmaster's rotating barcodes

conduition.io

131–140 of 737 posts

Re: Reverse engineering Ticketmaster's rotating barcodes

#131
post #2

Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.

If it runs on my CPU and shows up on my screen after I paid for it, it's mine and I can do whatever I want. Anybody who thinks otherwise can fuck off outright.

That's exactly the same policy I apply to AGPL software. I paid for it ($0, as mandated by the developer) and it runs on my CPU.

Re: Reverse engineering Ticketmaster's rotating barcodes

#132

I hate TM and ridiculous fees as much as anyone, but this article is overly hyperbolic. There's a section named "Pirating Tickets", that just explains how to re-create a barcode that you already paid for. You're not using this to rob anyone of anything. And at the end, "Have fun refactoring your ticket verification system". Why? There are no vulnerabilities here. A rotating barcode (even if following a known pattern)…

This way you can sell and have the ticket completely off of ticketmaster. That is a vulnerability. It lets users do something they explicitly don't want to allow.

Re: Reverse engineering Ticketmaster's rotating barcodes

#133
post #117

Earlier quoted context omitted.

...by doing what? FB is one of the largest employers of people on this site. If you ran a poll, I'd expect the majority to answer "no" to your question. Of the people who answered "yes", I bet the majority would still accept an offer from FB if it was just 20k more than the next best offer.

One small example: In 2012 Facebook emotionally manipulated people in the name of science without anybody's consent by controlling positive / negative posts on their news feed. Right? Wrong? Discuss.

https://xkcd.com/1390/

I don't see the issue. Every social media site does this, FB was just naive enough to share their research

Re: Reverse engineering Ticketmaster's rotating barcodes

#134
post #73

A few months ago I went to Las Vegas to watch U2 at the Sphere. When I learned that I needed to open the app or website in order to get in I panicked in fear of the shitty internet that is common in massive events, so I opened my tickets since I left the hotel. Unless this stuff works completely offline, it is a terrible idea.

There's no way that I trust the developers of a company like Ticketmaster to install their app on my device.

What is the worst that can happen? I have it installed on my iPhone and deny whatever permissions it asks for.

I have enough confidence in the sandbox that "installing an app" is basically never an issue (though I don't out of the principle that most things companies have apps for just shouldn't be apps).

Re: Reverse engineering Ticketmaster's rotating barcodes

#135
post #112

I hate TM and ridiculous fees as much as anyone, but this article is overly hyperbolic. There's a section named "Pirating Tickets", that just explains how to re-create a barcode that you already paid for. You're not using this to rob anyone of anything. And at the end, "Have fun refactoring your ticket verification system". Why? There are no vulnerabilities here. A rotating barcode (even if following a known pattern)…

It's piracy in a way that's analogous to ripping like Netflix content. You are breaking away from DRM which is piracy. They also cite the potential to have multiple tokens valid per one ticket which would let multiple people get in with the same ticket.

I'd argue that a few extra people sneaking in on the same ticket (assuming this is even possible) is more like sharing your Netflix credentials than ripping Netflix content and having it be shareable with the entire world.

You're also walking into a stadium/concert in plain view of security cameras, so the stakes and deniability are different as well.

Re: Reverse engineering Ticketmaster's rotating barcodes

#136

> There’s no risk that your ticket won’t get you in Isn’t this not true? The risk with printable tickets is that a seller could sell it to multiple people, who all print it out, but then only the first person who uses it can get in? Even if the venue doesn’t check to see if a ticket has already been used, only one person can sit in the actual seat.

Ticketmaster has a system for transferring tickets, if you want to buy or sell tickets. There could very well be a reason for someone to only sell a physical ticket, or not transfer it through ticketmaster, but I have yet to find anyone but scammers that want to do that. The reason is, just as you mention, that scammers will try to sell multiple tickets. Then one (or many) sucker turns up to the avenue, only to disco…

>Ticketmaster has a system for transferring tickets, if you want to buy or sell tickets

Sure, and it is terrible.

They can block you from transferring the ticket you bought, and can set a minimum resale price (effectively ensuring you cannot recoup anything)

You should to own what you purchase, simple as.

Re: Reverse engineering Ticketmaster's rotating barcodes

#137
post #53

I agree with the bad implement but the opening complaining that "old way of printable tickets was great why change it" have so many problems. Scalpers are the problem that you have to accept. At the time of purchase, there's no way to tell the difference between a legit purchaser and a scalper or even someone who bought it and simply can't go and needs to resell. IDs, ticket limiters, CCs, etc, etc. All methods can b…

Buying something at a low price and selling it at a high price is arbitrage 101 and is free money. The "true solution" is to sell tickets at their actual market price instead of pretending that the face value of concert tickets isn't increasing due to a larger population and greater demand.

People will scream (including in this thread) that it’s “unfair” that ‘only the wealthy can afford them then’ but their beef is with scarcity and thus with reality. It’s always “unfair” to the 10,001st person who wants to attend the concert with 10,000 capacity. Today it’s a weird lottery with 6 different fan and credit-cardmember presales, which each sell out immediately, and the “backstop” at the end which is the ability to buy expensive scalped tickets.

There are finite tickets but unbounded demand. A lottery means you can slightly adjust the distribution of poor vs rich, but in practice today it still advantages those comfortable enough to sit around refreshing their computers at the right moment, instead of working. And lots of opportunists will snap up those tickets you are hoping poor people will get, to sell them to the wealthy.

In my opinion for in-demand shows it should just be a Dutch auction (all of the highest 10,000 bids win, awarded at some fixed cutoff date before the event). If not enough bids are received, the concert isn’t sold out, so then the rest go on sale for the lowest bid.

Re: Reverse engineering Ticketmaster's rotating barcodes

#138

I hate TM and ridiculous fees as much as anyone, but this article is overly hyperbolic. There's a section named "Pirating Tickets", that just explains how to re-create a barcode that you already paid for. You're not using this to rob anyone of anything. And at the end, "Have fun refactoring your ticket verification system". Why? There are no vulnerabilities here. A rotating barcode (even if following a known pattern)…

This way you can sell and have the ticket completely off of ticketmaster. That is a vulnerability. It lets users do something they explicitly don't want to allow.

Assuming that you can actually do that.

If the seller re-opens the TM app and it generates a new token and invalidates the old one, then that's not the case.

Re: Reverse engineering Ticketmaster's rotating barcodes

#140
post #117

Earlier quoted context omitted.

...by doing what? FB is one of the largest employers of people on this site. If you ran a poll, I'd expect the majority to answer "no" to your question. Of the people who answered "yes", I bet the majority would still accept an offer from FB if it was just 20k more than the next best offer.

One small example: In 2012 Facebook emotionally manipulated people in the name of science without anybody's consent by controlling positive / negative posts on their news feed. Right? Wrong? Discuss.

I can't put any facebook developer in the same bucket as a guard at a concentration camp.
Post reply on HN