Live data from Hacker News

Reverse engineering Ticketmaster's rotating barcodes

conduition.io

41–50 of 737 posts

Re: Reverse engineering Ticketmaster's rotating barcodes

#41
post #23

How about the “Add to Apple Wallet” option? He did not talk about that at all , but AFAIK the ticket would be fully available offline and not in Ticketmaster app, no? It’s actually an elegant solution IMHO.

I just added a ticket to my Google Wallet for a concert last night and it was very similar to the Ticketmaster/LiveNation app. The PDF417 barcode changed and had an animation around it. My guess is that it is the same or very similar on Apple devices.

Re: Reverse engineering Ticketmaster's rotating barcodes

#42

This sort of ticketing thing is a trivially solvable problem. It is solved at every airport in the entire world millions of times per day. You provide the name of each concertgoer when you buy a ticket, and they show up with their ticket and ID. You often need to show your ID at these kinds of venues to prove you're old enough to drink beer anyway.

[flagged]

Buying and using a scalped ticket isn't a crime for the concert-goer, using a fake ID (in most states) is meaning it puts significantly more pressure the consumer to not buy. Also, most people in the US over the age of 21 don't have fake ID's, so it's a reasonable detriment.

Re: Reverse engineering Ticketmaster's rotating barcodes

#43
post #41
post #23

How about the “Add to Apple Wallet” option? He did not talk about that at all , but AFAIK the ticket would be fully available offline and not in Ticketmaster app, no? It’s actually an elegant solution IMHO.

I just added a ticket to my Google Wallet for a concert last night and it was very similar to the Ticketmaster/LiveNation app. The PDF417 barcode changed and had an animation around it. My guess is that it is the same or very similar on Apple devices.

So items inside google/apple wallet don't need to be 'static'?

Re: Reverse engineering Ticketmaster's rotating barcodes

#45

I agree with the bad implement but the opening complaining that "old way of printable tickets was great why change it" have so many problems. Scalpers are the problem that you have to accept. At the time of purchase, there's no way to tell the difference between a legit purchaser and a scalper or even someone who bought it and simply can't go and needs to resell. IDs, ticket limiters, CCs, etc, etc. All methods can b…

That's because there isn't a difference between a "legit purchaser" and a scalper except their intentions, which you can't get from amy kind of barcode.

Re: Reverse engineering Ticketmaster's rotating barcodes

#46
post #41

Earlier quoted context omitted.

I just added a ticket to my Google Wallet for a concert last night and it was very similar to the Ticketmaster/LiveNation app. The PDF417 barcode changed and had an animation around it. My guess is that it is the same or very similar on Apple devices.

So items inside google/apple wallet don't need to be 'static'?

No, I have flight tickets autoupdate when there is a delay.

Re: Reverse engineering Ticketmaster's rotating barcodes

#47
post #41

Earlier quoted context omitted.

I just added a ticket to my Google Wallet for a concert last night and it was very similar to the Ticketmaster/LiveNation app. The PDF417 barcode changed and had an animation around it. My guess is that it is the same or very similar on Apple devices.

So items inside google/apple wallet don't need to be 'static'?

With Google Wallet (the only one I have at the moment), it is not static for the ticket. It has a NFC and barcode option. The barcode changes every 15 seconds for me.

Re: Reverse engineering Ticketmaster's rotating barcodes

#48

This sort of ticketing thing is a trivially solvable problem. It is solved at every airport in the entire world millions of times per day. You provide the name of each concertgoer when you buy a ticket, and they show up with their ticket and ID. You often need to show your ID at these kinds of venues to prove you're old enough to drink beer anyway.

[flagged]

The solution doesn't have to be perfect. It just has to be good. Good enough is good enough.

Re: Reverse engineering Ticketmaster's rotating barcodes

#49
post #20

Another case of abusing ToTK, an excellent technology that promised convenience, security, and offline access. Similarly, Duo builds their stuff off ToTK and then fending off (or makes it very, very hard) you from using a third-party ToTK authenticator with their sites. This company just jettisons the fine promise of available offline that was made by ToTK.

TOTP?

Re: Reverse engineering Ticketmaster's rotating barcodes

#50

Isn't this vulnerable to ticket 'selling' by simply sharing the username and password of the ticketmaster account? it's not like a ticketmaster account is 'worth' anything, so the seller can simply set up a new one for their next purchase.

Setting up separate accounts for every ticket purchase seems like a LOT of overhead (especially scalpers buying many tickets at once and piecemealing them out), and is easy to defeat, e.g. require out of band auth via the phone number associated with the account before logging in for the first time on a new device.
Post reply on HN