Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.
Reverse engineering Ticketmaster's rotating barcodes
21–30 of 737 posts
Re: Reverse engineering Ticketmaster's rotating barcodes
#22> This is a contradiction in TicketMaster’s marketing. They can’t have robust DRM on their tickets if those tickets can still be viewed offline. The "robust DRM" is called "ID cards". Here in Europe, it's become commonplace to tie soccer tickets to ID cards that are verified at the gates to keep hooligans (or those suspected of being hooligans, which is a status that is way WAY easier obtainable than one might reason…
(Not that requiring ID doesn't raise the same and also other consumer rights issues)
Re: Reverse engineering Ticketmaster's rotating barcodes
#23Re: Reverse engineering Ticketmaster's rotating barcodes
#24Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.
Re: Reverse engineering Ticketmaster's rotating barcodes
#25Re: Reverse engineering Ticketmaster's rotating barcodes
#26> This is a contradiction in TicketMaster’s marketing. They can’t have robust DRM on their tickets if those tickets can still be viewed offline. The "robust DRM" is called "ID cards". Here in Europe, it's become commonplace to tie soccer tickets to ID cards that are verified at the gates to keep hooligans (or those suspected of being hooligans, which is a status that is way WAY easier obtainable than one might reason…
Huh, weird, a turns out an old, low-tech solution is much more secure than Ticketmaster's roll-your-own weird TOT-QR "security" (even considering the magic animation that that makes it "in a sense, alive") (Not that requiring ID doesn't raise the same and also other consumer rights issues)
Re: Reverse engineering Ticketmaster's rotating barcodes
#27Re: Reverse engineering Ticketmaster's rotating barcodes
#28Earlier quoted context omitted.
Huh, weird, a turns out an old, low-tech solution is much more secure than Ticketmaster's roll-your-own weird TOT-QR "security" (even considering the magic animation that that makes it "in a sense, alive") (Not that requiring ID doesn't raise the same and also other consumer rights issues)
The thing is, unlike most of Europe, the US doesn't have a legal mandate for anyone to possess an ID card, and so in practice you got 50 states worth of driver's licenses, library cards, military or government employment IDs that can be used (or faked)... so you can't really use these for legitimately verifying anything unless you want to spend a lot of time and money to train your staff to spot fakes. Banks can do t…
Re: Reverse engineering Ticketmaster's rotating barcodes
#29How about the “Add to Apple Wallet” option? He did not talk about that at all , but AFAIK the ticket would be fully available offline and not in Ticketmaster app, no? It’s actually an elegant solution IMHO.
Re: Reverse engineering Ticketmaster's rotating barcodes
#30Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.
"Responsible disclosure" is poorly defined corporate wishcasting, and certainly not any sort of best practice or legal shield.