news.volyx.in

Reverse engineering Ticketmaster's rotating barcodes (conduition.io)

2305 points by miki123211 · 764 days ago · 714 comments on HN

Article summary

The article describes the author's experience with Ticketmaster's rotating barcodes, also known as SafeTix, which are used for ticket verification. The author reverse-engineered the barcode system, finding that it uses a combination of a static bearer token and two time-based one-time passwords (TOTPs) to verify tickets. The author argues that this system is not as secure as Ticketmaster claims and is primarily designed to prevent ticket resale outside of Ticketmaster's platform. The author also criticizes the system for being inconvenient and potentially problematic for users with limited internet access.

Main themes

  • Ticketmaster's rotating barcodes
  • Security and authentication
  • Ticket resale and scalping
  • User convenience and accessibility
  • DRM and control

What commenters say

  • The author's reverse-engineering of the Ticketmaster system is a form of irresponsible disclosure that could be considered a security vulnerability.
  • The system is not a security vulnerability, but rather a form of DRM that can be bypassed for personal convenience.
  • Ticketmaster's fees and business practices are unfair to artists and fans, and the rotating barcode system is just one example of this.
  • The system is designed to prevent ticket resale and scalping, but it also creates problems for legitimate ticket holders who want to transfer or sell their tickets.
  • Requiring ID verification at events could be a more effective way to prevent ticket fraud, but this approach has its own set of challenges and drawbacks.
  • The use of DRM and secure storage on mobile devices can provide an additional layer of security, but it also raises concerns about user control and access to their own data.