Live data from Hacker News

Reverse engineering Ticketmaster's rotating barcodes

conduition.io

531–540 of 737 posts

Re: Reverse engineering Ticketmaster's rotating barcodes

#531
post #219

Earlier quoted context omitted.

They needed reliable connectivity in the previous scenario (checking barcodes against a central db) - they just setup a local private wifi network for the handsets and all the venue devices. Otherwise I can't see how you would avoid replay attacks.

You can do time-based binding. Many TLS/Quic 0RTT take this approach; where the signature is only valid for a second or so. It's not as good as a real strike register, but probably ok for this kind of environment. Of course the barcodes would need to be more dynamic, but that's doable.

[deleted]

Re: Reverse engineering Ticketmaster's rotating barcodes

#533
post #156

Earlier quoted context omitted.

I'd argue that a few extra people sneaking in on the same ticket (assuming this is even possible) is more like sharing your Netflix credentials than ripping Netflix content and having it be shareable with the entire world. You're also walking into a stadium/concert in plain view of security cameras, so the stakes and deniability are different as well.

Not a lawyer, but "subverting DRM" (even if it's trivial or really stupidly designed) can be a crime in and of itself in the US under the DMCA. There are a bunch of exceptions to this, so I have no idea if OP's work is actually illegal.

Now this is f*cked up, isn't it?

Re: Reverse engineering Ticketmaster's rotating barcodes

#534

Earlier quoted context omitted.

> Asking if a person or a company is good or bad isn't a question that can ever have a well-defined answer: the answers we give are rounded according to our own values. Counterexample: Was Hitler bad?

Due to chaotic effects of causality, most of us would not exist if any significant event from that long ago had happened differently.

How is that related? Other people would exist then. So what?

Re: Reverse engineering Ticketmaster's rotating barcodes

#535

This sort of ticketing thing is a trivially solvable problem. It is solved at every airport in the entire world millions of times per day. You provide the name of each concertgoer when you buy a ticket, and they show up with their ticket and ID. You often need to show your ID at these kinds of venues to prove you're old enough to drink beer anyway.

Ticketmaster says: NIH

Re: Reverse engineering Ticketmaster's rotating barcodes

#537
post #207

Earlier quoted context omitted.

Maybe you are using a fully open phone, but mine has an OS made by Google and almost every app tracks my location without my consent.

I'm an app dev. How exactly would I track your location without your consent?

For example, based on my IP address, nearby wifi networks, and camera footage.

Re: Reverse engineering Ticketmaster's rotating barcodes

#538

Earlier quoted context omitted.

> Asking if a person or a company is good or bad isn't a question that can ever have a well-defined answer: the answers we give are rounded according to our own values. Counterexample: Was Hitler bad?

Good/Bad are consensus votes. Its hard to escape their use just because of how deeply ingrained the programming is. We just think it makes "sense" and is "obvious" because its a meme that is already in our head. There is nothing inherently evil or good about any past/present/future animal on this planet.

So, was Hitler evil?

Re: Reverse engineering Ticketmaster's rotating barcodes

#539
post #434

Earlier quoted context omitted.

Just vote with your pocket and don’t buy tickets from them. I do that - yes I don’t get to go to major concerts but there are still so much more that is not on ticket master. I found a lot of new entertainment and was happy to pay $4 fee instead of whatever TM charges nowadays.

They have an effective monopoly.

Not just on tickets, but on venues, catering, security, logistics. It's pretty bad.

Re: Reverse engineering Ticketmaster's rotating barcodes

#540

"besides the fact that I don’t want to install their spyware on my phone." There's no other mention of spyware in the article - does anyone know what this is referring to?

I think it's just usually any 3rd party app is to be considered spyware nowadays.

OK - just general tin-foil hattery.
Post reply on HN