Earlier quoted context omitted.
They needed reliable connectivity in the previous scenario (checking barcodes against a central db) - they just setup a local private wifi network for the handsets and all the venue devices. Otherwise I can't see how you would avoid replay attacks.
You can do time-based binding. Many TLS/Quic 0RTT take this approach; where the signature is only valid for a second or so. It's not as good as a real strike register, but probably ok for this kind of environment. Of course the barcodes would need to be more dynamic, but that's doable.
Reverse engineering Ticketmaster's rotating barcodes
531–540 of 737 posts
Re: Reverse engineering Ticketmaster's rotating barcodes
#532How hard is that really?
Re: Reverse engineering Ticketmaster's rotating barcodes
#533Earlier quoted context omitted.
I'd argue that a few extra people sneaking in on the same ticket (assuming this is even possible) is more like sharing your Netflix credentials than ripping Netflix content and having it be shareable with the entire world. You're also walking into a stadium/concert in plain view of security cameras, so the stakes and deniability are different as well.
Not a lawyer, but "subverting DRM" (even if it's trivial or really stupidly designed) can be a crime in and of itself in the US under the DMCA. There are a bunch of exceptions to this, so I have no idea if OP's work is actually illegal.
Re: Reverse engineering Ticketmaster's rotating barcodes
#534Earlier quoted context omitted.
> Asking if a person or a company is good or bad isn't a question that can ever have a well-defined answer: the answers we give are rounded according to our own values. Counterexample: Was Hitler bad?
Due to chaotic effects of causality, most of us would not exist if any significant event from that long ago had happened differently.
Re: Reverse engineering Ticketmaster's rotating barcodes
#535This sort of ticketing thing is a trivially solvable problem. It is solved at every airport in the entire world millions of times per day. You provide the name of each concertgoer when you buy a ticket, and they show up with their ticket and ID. You often need to show your ID at these kinds of venues to prove you're old enough to drink beer anyway.
Re: Reverse engineering Ticketmaster's rotating barcodes
#536Re: Reverse engineering Ticketmaster's rotating barcodes
#537Earlier quoted context omitted.
Maybe you are using a fully open phone, but mine has an OS made by Google and almost every app tracks my location without my consent.
I'm an app dev. How exactly would I track your location without your consent?
Re: Reverse engineering Ticketmaster's rotating barcodes
#538Earlier quoted context omitted.
> Asking if a person or a company is good or bad isn't a question that can ever have a well-defined answer: the answers we give are rounded according to our own values. Counterexample: Was Hitler bad?
Good/Bad are consensus votes. Its hard to escape their use just because of how deeply ingrained the programming is. We just think it makes "sense" and is "obvious" because its a meme that is already in our head. There is nothing inherently evil or good about any past/present/future animal on this planet.
Re: Reverse engineering Ticketmaster's rotating barcodes
#539Earlier quoted context omitted.
Just vote with your pocket and don’t buy tickets from them. I do that - yes I don’t get to go to major concerts but there are still so much more that is not on ticket master. I found a lot of new entertainment and was happy to pay $4 fee instead of whatever TM charges nowadays.
They have an effective monopoly.
Re: Reverse engineering Ticketmaster's rotating barcodes
#540"besides the fact that I don’t want to install their spyware on my phone." There's no other mention of spyware in the article - does anyone know what this is referring to?
I think it's just usually any 3rd party app is to be considered spyware nowadays.