What's the deal with PDF417? Why did they choose it over QR?
Perhaps a better question is: Why not PDF417? What functional improvement would be had by using a 2D QR code?
Reverse engineering Ticketmaster's rotating barcodes
241–250 of 737 posts
Re: Reverse engineering Ticketmaster's rotating barcodes
#242How about the “Add to Apple Wallet” option? He did not talk about that at all , but AFAIK the ticket would be fully available offline and not in Ticketmaster app, no? It’s actually an elegant solution IMHO.
I just added a ticket to my Google Wallet for a concert last night and it was very similar to the Ticketmaster/LiveNation app. The PDF417 barcode changed and had an animation around it. My guess is that it is the same or very similar on Apple devices.
Re: Reverse engineering Ticketmaster's rotating barcodes
#243Earlier quoted context omitted.
There's no way that I trust the developers of a company like Ticketmaster to install their app on my device.
What is the worst that can happen? I have it installed on my iPhone and deny whatever permissions it asks for. I have enough confidence in the sandbox that "installing an app" is basically never an issue (though I don't out of the principle that most things companies have apps for just shouldn't be apps).
I don't know the worst, but juice is not worth the squeeze in my opinion. If you recall, Ticketmaster was just recently hacked, so the worst pretty much happened in that any data they had collected on their users is potentially been leaked. So if they can't protect that data, then I'm not participating in giving them data.
Re: Reverse engineering Ticketmaster's rotating barcodes
#244v2 of this will require an Android/iOS app which will make use of the platforms secure storage abilities for the key. On non-rooted devices, those are pretty much impervious to the user trying to inspect their contents.
The Android docs mention a "secure timer" in the hardware security module, but I'm not sure that it can be used to prevent this.
https://developer.android.com/reference/android/security/key...
Re: Reverse engineering Ticketmaster's rotating barcodes
#245Earlier quoted context omitted.
The thing is, unlike most of Europe, the US doesn't have a legal mandate for anyone to possess an ID card, and so in practice you got 50 states worth of driver's licenses, library cards, military or government employment IDs that can be used (or faked)... so you can't really use these for legitimately verifying anything unless you want to spend a lot of time and money to train your staff to spot fakes. Banks can do t…
Sure, but realistically no one is going to get a fake ID with a certain name on it so they can go to a concert with that person's tickets.
The problem is that Americans are not required to have an ID -- at all. No federal law requires it, and there is none issued by default.
(This is not the same as saying "Americans don't have to carry an ID" even though that is also true.)
Re: Reverse engineering Ticketmaster's rotating barcodes
#246Earlier quoted context omitted.
It's piracy in a way that's analogous to ripping like Netflix content. You are breaking away from DRM which is piracy. They also cite the potential to have multiple tokens valid per one ticket which would let multiple people get in with the same ticket.
I doubt the second bit is true - they will still be marking the ticket as used in their backend. They are just trying to prevent scalpers printing off tickets 10 times and selling them outside the venues as a scam, which happened at every large concert I have ever been to until recently (so I assume this is working!).
Heard from a friend who got straight into two events in the same city recently - they presumed the show was at one outdoor venue but the scanners let them straight in at the first (wrong) venue. Went to the correct venue and got in there without any issue too (this suggests one or both venues were offline or using offline scanners).
Re: Reverse engineering Ticketmaster's rotating barcodes
#247Earlier quoted context omitted.
It's not hard if you remove the self delusion. Removing the self delusion is maybe tricky for the individual, but it's easy for people around the individual to see. Societal tools like shame are generally used to encourage people in the right direction, but we don't do a great job of this in America, because money tends to override everything else and I don't think we have good structures around expressing non-moneta…
Yup. I was just discussing this in another comment that Facebook's emotional manipulation of users without consent is ethical wrong. Some people are replying with eh, everybody does it and for 20,000 dollars people will jump to Facebook. I think the Leetcode grinding, TC optimizing crowd with no real moral judgment which is the majority in tech right now is another reason why things are falling apart. They will happi…
Re: Reverse engineering Ticketmaster's rotating barcodes
#248Earlier quoted context omitted.
People often buy tickets without knowing exactly which of their friends are going to attend with them. This is not true of airplane tickets.
One ID for the entire order would be fine. You can buy 4 tickets, and go into the concert with your 3 friends. It often works this way even with no ID involved, I buy two tickets, add them both to my wallet, scan them both when my GF and I go to the show. You COULD still scalp tickets if the person who bought them from you is going to walk in with you. But the scalper would have to eat the cost of one ticket to do it…
Re: Reverse engineering Ticketmaster's rotating barcodes
#249Earlier quoted context omitted.
...by doing what? FB is one of the largest employers of people on this site. If you ran a poll, I'd expect the majority to answer "no" to your question. Of the people who answered "yes", I bet the majority would still accept an offer from FB if it was just 20k more than the next best offer.
One small example: In 2012 Facebook emotionally manipulated people in the name of science without anybody's consent by controlling positive / negative posts on their news feed. Right? Wrong? Discuss.
Re: Reverse engineering Ticketmaster's rotating barcodes
#250This sort of ticketing thing is a trivially solvable problem. It is solved at every airport in the entire world millions of times per day. You provide the name of each concertgoer when you buy a ticket, and they show up with their ticket and ID. You often need to show your ID at these kinds of venues to prove you're old enough to drink beer anyway.
There was a recent story of someone taking pictures of other people's boarding passes, and using that to board the plane.
With this ticketmaster scheme, unless the person has access to the secret keys, the pass would only be valid for a few seconds, likely defeating this attack against boarding passes.
https://www.nbcdfw.com/news/local/texas-news/texas-man-board...