Live data from Hacker News

Reverse engineering Ticketmaster's rotating barcodes

conduition.io

561–570 of 737 posts

Re: Reverse engineering Ticketmaster's rotating barcodes

#561
post #52

Earlier quoted context omitted.

Yup. I have to believe the reason the likes of ticket master isn't fixing this is because they are selling/auctioning/reserving some percentage of tickets to scalpers or "3rd party sellers". Requiring ID is such an obvious solution that I have to believe these convoluted approaches are only there so the secondary market can exist and so ticket master can wash their hands when prices get out of control on that market.

I have to presume that the driving impetus of all of this is that they're trying to avoid the actual requirement of checking the ID. Like, they want to improve the flow of traffic through admissions. But I mean, obviously, any kind of system like this strikes me as the same sort of thing as DRM. That you can somehow protect the message from the person you're sharing the message to. How can you avoid reselling if you…

> How can you avoid reselling if you don't verify the original purchaser?

A ticket scalper cannot know the names of the people that will later purchase his tickets. So connecting each ticket to a name prevents scalpers.

Re: Reverse engineering Ticketmaster's rotating barcodes

#562

I'd also like to highlight another bad practice by Ticketmaster. When you purchase a ticket from them and resell it on their marketplace, once someone purchases it, they(Ticketmaster) hold your funds and only give you the money ~7-14 business days after the event is over. They say this is to verify the validity of the ticket. On the buyer side, you purchase the ticket from the marketplace and it gets added to your ac…

There's another good point in here. Why do they hold the ticket until just before the event? I bought tickets to a concert for my wife's favorite band. Then, my wife's work scheduled an event for that same week and she had to leave town. So, what I really wanted was a refund so someone else could buy the tickets. They don't do that of course. So, then I wanted to sell the tickets for face value... but ticketmaster di…

Tbf, this does sound like a fairly efficient anti-scalper strategy, so I guess there's at least some upside to this mess.

Re: Reverse engineering Ticketmaster's rotating barcodes

#563

I hate TM and ridiculous fees as much as anyone, but this article is overly hyperbolic. There's a section named "Pirating Tickets", that just explains how to re-create a barcode that you already paid for. You're not using this to rob anyone of anything. And at the end, "Have fun refactoring your ticket verification system". Why? There are no vulnerabilities here. A rotating barcode (even if following a known pattern)…

The way this is already being exploited in the wild is that a scalper/scammer buys 1 ticket, then resells the same ticket multiple times. Multiple people believe they have a valid ticket, show up at the event, but only the 1st ticket works. The other people who try to use the ticket are turned away saying that their ticket has already been used.

Do you have a source for this? What platform are they selling multiple copies of the ticket through, and what app are the buyers using that allows multiple buyers to receive and show the same animated barcode?

Re: Reverse engineering Ticketmaster's rotating barcodes

#564
post #515

I hate TM and ridiculous fees as much as anyone, but this article is overly hyperbolic. There's a section named "Pirating Tickets", that just explains how to re-create a barcode that you already paid for. You're not using this to rob anyone of anything. And at the end, "Have fun refactoring your ticket verification system". Why? There are no vulnerabilities here. A rotating barcode (even if following a known pattern)…

Are you sure you understood the article? The token is supposed to be a secret and the TOTP generation should happen remotely. This is not the case and this suggest a fundamental lack of security practices at the company.

"Should happen remotely" – according to who? What is the security risk for the end-user?

"this suggest a fundamental lack of security practices at the company" – that's a stretch of a conclusion to make. You're being as hyperbolic as the original post.

What didn't I understand about the article? This still offers a slight increase in security over static barcodes, without introducing any new vulnerabilities.

Re: Reverse engineering Ticketmaster's rotating barcodes

#565

Earlier quoted context omitted.

... for a completely optional form of entertainment. At the very least you have the choice not to go to any concerts until there are better options. You can also make that clear to your favorite bands.

lol, people and bands have been complaining about it for 30 years and it’s only gotten worse. Yes, you could skip concerts for the rest of your life, I suppose, to make a point. But it’s not going to fix anything.

Complaining yes, but how many people are actually putting their foot down? As for bands, they may actually be profiting from this scheme where ticketmaster ensures higher prices while taking the blame. If they really cared enough they could chose not to deal with Ticketmaster. Sure, that would limit their choices in venues which could mean lower potential for profit. Probably not going to be a real issue for the the more popular groups.

And yes, if there are no concerts with acceptable terms (and that's really a hypothetical if) then don't go to any for the rest of your life. You make it sound like this is some kind of required part of the human experience when it is just one of many possible ways to spend your time. Even if you are really into music, concerts are just one way to experience it - and when it comes to audio quality, a fairly crappy one.

Re: Reverse engineering Ticketmaster's rotating barcodes

#566

I'd also like to highlight another bad practice by Ticketmaster. When you purchase a ticket from them and resell it on their marketplace, once someone purchases it, they(Ticketmaster) hold your funds and only give you the money ~7-14 business days after the event is over. They say this is to verify the validity of the ticket. On the buyer side, you purchase the ticket from the marketplace and it gets added to your ac…

>When you purchase a ticket from them and resell it on their marketplace, once someone purchases it, they(Ticketmaster) hold your funds and only give you the money ~7-14 business days after the event is over. They say this is to verify the validity of the ticket.

I imagine it's more about discouraging scalping, regardless of what they may say about it.

Re: Reverse engineering Ticketmaster's rotating barcodes

#567

Earlier quoted context omitted.

Flying requires an ID. Attending a concert should not. Any solution that is solved by "simple, just require an ID" is not a solution.

Depends a lot on the country you live in. In most European countries "carrying an ID" is legally required if the police stops you anyway (they do need a reason to see it though), so "show an ID at the entrance" is no big deal. It's to my understanding mainly the US where ID requirements are often side eyed because many people don't have them and there's no national standard (and due to a variety of political reasons…

What the hell kind of draconian country forces you to always have an id on you? What if I go running with only my watch on (I’ve regularly done this with no malicious intent)

Re: Reverse engineering Ticketmaster's rotating barcodes

#568
This is Gold - but also Ticketmaster is a evil monopoly

Disclaimer: This isn’t from a real SafeTix barcode. I don’t want TicketMaster to be able to identify and harass me.

Bullshit, TicketMaster. It’s a CSS animation. Get over yourself.

I think we can all agree: Fuck TicketMaster

Re: Reverse engineering Ticketmaster's rotating barcodes

#569

Earlier quoted context omitted.

Flying requires an ID. Attending a concert should not. Any solution that is solved by "simple, just require an ID" is not a solution.

> Flying requires an ID. Attending a concert should not. Why though? Not disagreeing per say because I'd have thought so too, but upon reflection... I assume the main reason airlines require an ID is safety and security. We maintain a denied parties list and use identity verification to make it as difficult as possible to fly a plane into a crowded venue. Border control is another issue, but there's plenty of intra-c…

Because we ought to do everything in our power to stop the aggressive onslaught of the surveillance state. We already know TSA is security theatre at best, and the time they’ve wasted already justifies more lives lost to terrorism instead.

Practically, I don’t want Ticketmaster having access to the information on my ID, they already leaked lot of my other PII.

Re: Reverse engineering Ticketmaster's rotating barcodes

#570

This sort of ticketing thing is a trivially solvable problem. It is solved at every airport in the entire world millions of times per day. You provide the name of each concertgoer when you buy a ticket, and they show up with their ticket and ID. You often need to show your ID at these kinds of venues to prove you're old enough to drink beer anyway.

Italy solved this. Five years ago, a new law enforced ID-checking when you enter any big events (like concerts with an audience larger than 5000 people). Tickets have your name on it, and you can only change the name or resell them through the official seller (so, third party resellers are out of the game). Also, every reselling transaction is registered and can be inspected by the Italian Rightsholder Agency (SIAE).

I’d rather not solve it than let the state have more information about my transactions
Post reply on HN