Live data from Hacker News

Reverse engineering Ticketmaster's rotating barcodes

conduition.io

701–710 of 737 posts

Re: Reverse engineering Ticketmaster's rotating barcodes

#701

I'd also like to highlight another bad practice by Ticketmaster. When you purchase a ticket from them and resell it on their marketplace, once someone purchases it, they(Ticketmaster) hold your funds and only give you the money ~7-14 business days after the event is over. They say this is to verify the validity of the ticket. On the buyer side, you purchase the ticket from the marketplace and it gets added to your ac…

I really, really, really hope Ticketmaster gets broken up. Their shittiness seemingly knows no bounds.

Re: Reverse engineering Ticketmaster's rotating barcodes

#702

Earlier quoted context omitted.

> If you are first to market and still can't make money off your amazing invention, that might be a skill issue. Sounds like something a VC would say. Have you considered that inventing things and selling them are two different skill sets? The patent system needs reform, not elimination.

Why would you artificially encumber a significant invention from benefitting the world just because you don't have the wherewithal to sell it? Seems awfully self-centered.

The patent system certainly needs reform, but I think more along the lines of what gets accepted as a patent. Discovering what I would describe as a 'natural law' should not be patentable (but I think happens everyday), and those ideas should not be kept from human progress, imho. There's a line between research paper and patent, that I believe is blurred for profit.

But a true invention, a novel use of those laws, should be patentable. Are you saying that if you discover a novel use of natural laws, a product that could be capitalized, your own unique idea, that you should not be able to capitalize on it? Maybe this would work in a trek economy, but not with capitalism.

If your worried about innovation, how innovative could we be if discoveries/inventions were squandered because there are no protections if you happen to even mention your idea to someone?

Re: Reverse engineering Ticketmaster's rotating barcodes

#703
post #700
post #52

Earlier quoted context omitted.

I have to presume that the driving impetus of all of this is that they're trying to avoid the actual requirement of checking the ID. Like, they want to improve the flow of traffic through admissions. But I mean, obviously, any kind of system like this strikes me as the same sort of thing as DRM. That you can somehow protect the message from the person you're sharing the message to. How can you avoid reselling if you…

> Like, they want to improve the flow of traffic through admissions. But they in turn greatly degraded the flow of traffic by forcing the use of a proprietary always-online app which fails to load when your cellular connection is less-than-ideal. Verifying a photo ID would probably be faster.

True, but when you point out practical realities like this to monopolistic institutions, they don't have to care.

They will instead ask "well why isn't the connection good at the concert? What can we do to fix that?" (ie. "we don't have to change when we can make you change")

It IS true that if you don't have to verify the ID of the ticket holder then admissions will go much faster. So long as they can make that plausible sales pitch, they can use it as justification for whatever byzantine DRM system they can dream up.

Re: Reverse engineering Ticketmaster's rotating barcodes

#704
Reading this reminded me when last year I found a few old venue printed ticket stubs to concerts I went to the in the late 90's and 00's. I almost threw them out when I realized they weren't really taking up space and could be maybe put into a collage or photo/scrap book. I just suppose I find it laughibly absurd that something as mundane as a ticket stub was replaced by an energy wasting Rube Goldberg contraption that doesn't do anything for the person who wants to go to the concert.

Re: Reverse engineering Ticketmaster's rotating barcodes

#705
post #14

Really good post! I also found this quote which distilled their position in the 404media coverage of the situation. > “What I can say for sure is that TicketMaster and AXS have had every opportunity to support scam-free third party ticket resale and delivery platforms if they wished: By documenting their ticket QR code cryptography, and by exposing apps and APIs which would allow verification and rotation of ticket s…

I dug up the court docs referenced in that article, it's pretty interesting- AXS Group LLC v. Internet Referral Services LLC (2:24-cv-00377) District Court, C.D. California Amended complaint: https://storage.courtlistener.com/recap/gov.uscourts.cacd.91... Docket: https://www.courtlistener.com/docket/68163191/axs-group-llc-... One item of the complaint is regarding the "secure.tickets" site, which I wrote about in an…

The underlying issue is that those tickets have a "no resale" provision that doesn't apply when the original seller acts as a broker.

Do other brokers, when they go and work around that limitation break the sales contact? Maybe. The legal system would churn an answer in a few years.

Do AXS et al with their "only we are allowed to engage in a secondary policy" are abusing their monopoly on original sales? The legal system would churn an answer about the legality of this in few years, but I think it's obvious they at least break rules in the spirit.

Re: Reverse engineering Ticketmaster's rotating barcodes

#706
post #670
post #667

Earlier quoted context omitted.

If you're an app dev you're more qualified than me to answer that question. Perhaps you'd like to re-frame your comment or ask a different question?

My point is that you and the other guy are just making stuff up and spreading misinformation. At the API level, an app that doesn't have the user's explicit permission to get location, camera, run in the background, etc is not that different from a web app. My question was obviously rhetorical.

There you go, getting to the meat of it..

So your position is that an app installed on my phone is not able to track or collect any more data, and does not have access to any other information, than a website that I load in my device browser (assuming I log into that website with the same credentials I use in the native app)?

I agree that this might be true in some cases. Note that I never said or implied that an app could do things without permission - but my fault if that wasn't clear.

Now, that said, would it perhaps be fair to say that the average user is much more likely to grant additional permissions to a native app on their phone than they would to a website?

If a website asks for your location, or access to the camera or to your contacts or whatever, I think many people would refuse. There's still a sense that a website is "out there" on the Internet, and you shouldn't necessarily trust it.

But when an app you've installed on your device asks for these things, in order to "operate properly" or provide functionality, then I think people are much more likely to grant it.

After all they've installed the app on their device, they've already trusted the vendor that much, it's only an incremental step at this point.

And once the device does have this elevated access, and access to more data, then there are absolutely more opportunities to collect data on users without their understanding.

I say "understanding" here rather than "consent" because typically consent is given via some long and complicated T&Cs that no one reads. Which is of course on the user, but again if you don't grant permission in the first place (because you're on a website not an app), it's not a problem.

And we have historically seen that some companies (not all companies of course) take advantage of this app access to collect data for themselves without your knowledge. I hope that part isn't up for debate here..

Re: Reverse engineering Ticketmaster's rotating barcodes

#707
post #560

Earlier quoted context omitted.

There's another good point in here. Why do they hold the ticket until just before the event? I bought tickets to a concert for my wife's favorite band. Then, my wife's work scheduled an event for that same week and she had to leave town. So, what I really wanted was a refund so someone else could buy the tickets. They don't do that of course. So, then I wanted to sell the tickets for face value... but ticketmaster di…

I’ve never dealt much with TicketMaster, despite them being a monopoly. So my questions here may just be out of naiveté: 1) Why would TicketMaster pay event organizers ahead of time, if the event might be shit and attendees may demand their money back? Rather than having to deal with a lot of chargebacks and making it their own problem with the banks, they might prefer to make sure the event goes off without a hitch…

#1 and #3 are related. They make scalping easy so they get all of their money immediately and can pay event organizers ahead of time. I personally think scalping should be straight-up illegal but business schools loove it and consider it an excellent example of helping with liquidity in a system and finding the true "willingness to pay" price of something.

Re: Reverse engineering Ticketmaster's rotating barcodes

#708

Earlier quoted context omitted.

Well this just sounds like more reason to use a point scale rather than calling the entire idea a waste of time. In particular 'slightly less evil' is not the goal.

> Well this just sounds like more reason to use a point scale rather than calling the entire idea a waste of time. Again, I think we're kind of on the same page, but our solutions are different. The original question refused any kind of nuance, and we both seem to agree it's not a question that should ignore nuance. You choose to answer a binary question with a grading system, I choose to substitute a different quest…

Well, I think the binary version still works, even if I see possible improvement. While you think the binary version doesn't work. So sort of the same page, sort of not. Shrug.

Re: Reverse engineering Ticketmaster's rotating barcodes

#709
post #93
post #73

A few months ago I went to Las Vegas to watch U2 at the Sphere. When I learned that I needed to open the app or website in order to get in I panicked in fear of the shitty internet that is common in massive events, so I opened my tickets since I left the hotel. Unless this stuff works completely offline, it is a terrible idea.

I used to work or a mobile event app company that made a lot of the big festival/conference apps. Everything was built to function locally from a sqlite file on your phone that was constantly updated when you did have coverage. It was 100% expected that you would have no cell signal the entire event and we built in as many mitigations as we could think of. This was 2013ish, I think there are a lot more mesh network d…

...or just let us print g*d@mn paper tickets.

Re: Reverse engineering Ticketmaster's rotating barcodes

#710
post #560

Earlier quoted context omitted.

I’ve never dealt much with TicketMaster, despite them being a monopoly. So my questions here may just be out of naiveté: 1) Why would TicketMaster pay event organizers ahead of time, if the event might be shit and attendees may demand their money back? Rather than having to deal with a lot of chargebacks and making it their own problem with the banks, they might prefer to make sure the event goes off without a hitch…

#1 and #3 are related. They make scalping easy so they get all of their money immediately and can pay event organizers ahead of time. I personally think scalping should be straight-up illegal but business schools loove it and consider it an excellent example of helping with liquidity in a system and finding the true "willingness to pay" price of something.

willingness to get ripped off LOL

I built a blockchain-based solution.

It features a price discovery mechanism: you auction off M tickets to M people, the price goes up every time after M people buy and the oldest buyer is booted when the others buy, but can buy back in again. Buyers can set a “reserve price” to automatically bid up to that price.

No scalping, because tickets aren’t transferrable.

Similarly, you can disallow transfering of bearer token X but let the user sell it back to the central market maker and someone else buys it. Enforcing commissions on sales.

Blockchain makes all this work, decentralized.

Post reply on HN