Live data from Hacker News

Reverse engineering Ticketmaster's rotating barcodes

conduition.io

161–170 of 737 posts

Re: Reverse engineering Ticketmaster's rotating barcodes

#161
post #23

How about the “Add to Apple Wallet” option? He did not talk about that at all , but AFAIK the ticket would be fully available offline and not in Ticketmaster app, no? It’s actually an elegant solution IMHO.

The barcode in apple wallet also auto-updates.

Re: Reverse engineering Ticketmaster's rotating barcodes

#162
post #53

I agree with the bad implement but the opening complaining that "old way of printable tickets was great why change it" have so many problems. Scalpers are the problem that you have to accept. At the time of purchase, there's no way to tell the difference between a legit purchaser and a scalper or even someone who bought it and simply can't go and needs to resell. IDs, ticket limiters, CCs, etc, etc. All methods can b…

Buying something at a low price and selling it at a high price is arbitrage 101 and is free money. The "true solution" is to sell tickets at their actual market price instead of pretending that the face value of concert tickets isn't increasing due to a larger population and greater demand.

The reason they don't do that is to have an organic fan base of poor people who drive up the prices for the rich people. If you eliminate the poor people, the rich people aren't going to take the band forward. They'll move on to whatever the next shiny thing is. You need a hardcore fan base of poor people to support and grow your valuation.

Re: Reverse engineering Ticketmaster's rotating barcodes

#163
One things this articles kind of misses: You need that unique token... Ok, you can get it in some way.. But ticketmaster should keep it private, then, even if you know the algorithm. You still cant do a lot without the token......

So he reversed engineered it, but its still secure: You need the token.

Re: Reverse engineering Ticketmaster's rotating barcodes

#164
> They can’t have robust DRM on their tickets if those tickets can still be viewed offline.

Of course they can. All they need is a secret key embedded somewhere that the app can access but you can't. It's just a happy circumstance that they used a simple protocol in which the key is easily extracted. But they could have used a proper PKI protocol instead, which would have made it much harder, if not impossible, to hack.

Re: Reverse engineering Ticketmaster's rotating barcodes

#165
post #63

>Software developers are the wizards and shamans of the modern age. We ought to use our powers with the austerity and integrity such power implies. You’re using them to exclude people from entertainment events. I can definitely think of worse things programmers are doing aside from making it mildly difficult to see Taylor Swift . I have personal qualms with working in certain industries because of this, but Ticketmas…

> Ticketmaster ultimately provides a luxury. You don't need to see a concert I don't agree. Entertainment/recreation is a need. Music is an important part of the human experience, and seeing it live, with other fans, is really valuable to some people. And the fact is, the value a person places on the experience is totally orthogonal to their ability to use/afford Ticketmaster. And it's not just about Taylor Swift - e…

You can find a bar with a band playing. I suggest Kingston Mines if you're in the Chicago area.

Ticketmaster doesn't own have a monopoly on music. You can vote with your wallet.

Re: Reverse engineering Ticketmaster's rotating barcodes

#166

Earlier quoted context omitted.

Huh, weird, a turns out an old, low-tech solution is much more secure than Ticketmaster's roll-your-own weird TOT-QR "security" (even considering the magic animation that that makes it "in a sense, alive") (Not that requiring ID doesn't raise the same and also other consumer rights issues)

The thing is, unlike most of Europe, the US doesn't have a legal mandate for anyone to possess an ID card, and so in practice you got 50 states worth of driver's licenses, library cards, military or government employment IDs that can be used (or faked)... so you can't really use these for legitimately verifying anything unless you want to spend a lot of time and money to train your staff to spot fakes. Banks can do t…

How hard is it to get access to a database to confirm that a scanned ID is valid, and corresponds to the name written on it?

Re: Reverse engineering Ticketmaster's rotating barcodes

#167
post #30

Earlier quoted context omitted.

The public prosecutor does not pursue cases where responsible aka coordinated vulnerability disclosure was applied. I'd say that's a legal shield of some kind at least, and it is generally also considered best practice in the industry. There's exceptions to everything but, in the general case, I'm not sure where you're getting these viewpoints from

"The public prosecutor does not pursue cases where responsible aka coordinated vulnerability disclosure was applied." That seems like a pretty substantial claim to make without any sort of "in [country/state/province/etc.]" qualification, let alone a reference.

https://www.om.nl/onderwerpen/cybercrime/coordinated-vulnera...

Re: Reverse engineering Ticketmaster's rotating barcodes

#168

It's baffling that you have to carry a mobile phone to access a show. What if you run out of battery? Or if you accidentally break the screen just before entering the venue? The more the technology evolves the more we find horrible uses for it. People should fight back by refraining from purchasing tickets from them, I know is not easy for people to miss their favorite artist but until a monopoly is broken there is n…

You can still print the ticket on paper. Tho nowadays that means a trip to a FedEx store for me, since I refuse to keep buying inkjets I only use a couple times a year.

Laser printers have solved this - I don’t expect to change the toner for a decade.

Re: Reverse engineering Ticketmaster's rotating barcodes

#169

Earlier quoted context omitted.

One small example: In 2012 Facebook emotionally manipulated people in the name of science without anybody's consent by controlling positive / negative posts on their news feed. Right? Wrong? Discuss.

I can't put any facebook developer in the same bucket as a guard at a concentration camp.

Because a concentration camp guard would be jailed or killed for refusing service, but a FB dev would lose a few $thousand in opportunity?

Re: Reverse engineering Ticketmaster's rotating barcodes

#170
post #133

Earlier quoted context omitted.

https://xkcd.com/1390/ I don't see the issue. Every social media site does this, FB was just naive enough to share their research

And this just proved my point. During the Nazi regime, everyone was hating the jews. And everyone was doing fascism. Now to bring this to a close, people like you, who will jump companies for 20_000 and have lost the ability to see a clear ethical violation will be holding the guns and guarding the gas chambers when the next Hitler comes along. Meditate on this. Also this XKCD is dumb. Previously the feed was chronol…

One thing I have learned from the internet is that if you mention the Nazis or the Jews, you lose, good day sir, even if you are right.

People are illogical.

Post reply on HN