Reverse engineering Ticketmaster's rotating barcodes
conduition.io
conduition.io
> “What I can say for sure is that TicketMaster and AXS have had every opportunity to support scam-free third party ticket resale and delivery platforms if they wished: By documenting their ticket QR code cryptography, and by exposing apps and APIs which would allow verification and rotation of ticket secrets,” Conduition told me in an email. “But they intentionally choose not to do so, and then they act all surprised-pikachu when 3rd party resale scams proliferate. They're opting to play legal whack-a-mole with scammers instead of fixing the problem directly with better technology, because they make more money as a resale monopoly than as an open and secure ecosystem.”
from https://www.404media.co/scalpers-are-working-with-hackers-to...
AXS Group LLC v. Internet Referral Services LLC (2:24-cv-00377) District Court, C.D. California
Amended complaint: https://storage.courtlistener.com/recap/gov.uscourts.cacd.91...
Docket: https://www.courtlistener.com/docket/68163191/axs-group-llc-...
One item of the complaint is regarding the "secure.tickets" site, which I wrote about in an earlier comment below (https://news.ycombinator.com/item?id=40906148#40910690).
Basically, brokers are using the "secure.tickets" and similar websites to proxy ticket barcodes to buyers, without going through the actual ticket transfer mechanisms on the primary ticketer AXS/TM, (similar to how this blogger does). Then resellers are delivering these ticket URLs, hosted on random websites, to Seatgeek and Stubhub customers, and those platforms are supporting their delivery by telling their customers that the tickets are legit. Sounds like AXS is fighting back against this practice.
Do other brokers, when they go and work around that limitation break the sales contact? Maybe. The legal system would churn an answer in a few years.
Do AXS et al with their "only we are allowed to engage in a secondary policy" are abusing their monopoly on original sales? The legal system would churn an answer about the legality of this in few years, but I think it's obvious they at least break rules in the spirit.
Sounds like something a VC would say.
Have you considered that inventing things and selling them are two different skill sets?
The patent system needs reform, not elimination.
Seems awfully self-centered.
But a true invention, a novel use of those laws, should be patentable. Are you saying that if you discover a novel use of natural laws, a product that could be capitalized, your own unique idea, that you should not be able to capitalize on it? Maybe this would work in a trek economy, but not with capitalism.
If your worried about innovation, how innovative could we be if discoveries/inventions were squandered because there are no protections if you happen to even mention your idea to someone?
Also, I don’t think any of the issues with Ticketmaster have anything to do with patents.
Nothing seems reasonable to me on the topic unless it comes with evidence as to how it would improve a system that would appear by any objective measure to be doing incredibly well.
And what does any of it have to do with ticket master? They’re awful in a lot of ways, but I’m not aware of patent trolling to be one of them. If they even have and enforce patents, I’ve not heard of them, and I work in live events so I’m fairly well-informed on that company. Everyone in the industry hates them, it's unlikely they’re doing anything awful that isn’t routinely mentioned.
No, it wasn't. The idea behind the system was to give people a financial incentive to be _open_. Patents are a trade with the commons; you would give up your secrets for a limited time period of exclusivity. People would innovate with or without patents, but they would keep that innovation to themselves.
With software, both sides of that bargain have changed. Secrets are harder to keep, and since everything moves so much faster, any given time period is much more damaging to the commons (e.g., 20 years is forever in software).
(I also don't think Ticketmaster affairs have anything to do with patents, FWIW)
"To promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries"
This says nothing about publication, only about progress and exclusivity.
The big benefit of a functioning patent system is it allows people to make money just inventing things.
This group seems to have a “throw the baby out with the bath water” mentality when it comes to patents simply because of patent trolls, when the obvious solution is to just fix patent approval/litigation.
It was developed to spur innovation, and that is still its main function.
What about chemistry that mad everything from baking recipes, optics for physics, paint for art, forging techniques... The list goes on and on.
There are so many subtle ways of doing things that were silo'd in small communities or regions.
1. https://www.morganlewis.com/pubs/2022/04/russian-decree-unde...
When you purchase a ticket from them and resell it on their marketplace, once someone purchases it, they(Ticketmaster) hold your funds and only give you the money ~7-14 business days after the event is over. They say this is to verify the validity of the ticket.
On the buyer side, you purchase the ticket from the marketplace and it gets added to your account immediately. (I think) You get the barcode some time ~1 week before the actual event begins.
The confusion for me? Ticketmaster owned the ticket and all logic relating to the validity of it. The logic to validate this shouldn't be complex at all. They OWN the ticket. They KNOW it's legitimate because it never left their database. Yet they double dip and hold both buyer and seller funds. Events can be close to a year in the future but the seller won't see that until after that event ends.
This is cash that ticketmaster is holding
Therefore they will be earning interest on this.
[1] see interest incom on their latest 10-K https://investors.livenationentertainment.com/sec-filings/an...
2. there are a lot of customers
3. therefore ticket master holds lots of customer cash in transit (this is called the "float")
4. cash earns 5% interest so this year they will earn about 5% * avg float
I watched for a month leading up to the event as the ticket prices plummeted while the scalpers were desperate to get at least something for their tickets before my ticket was even delivered to me.
As soon as they take my money, they should update the database to show that the ticket is mine. If I want to sell it, I should be able to do that immediately too.
But, from what I've read, that instant resale ability only belongs to their "partners" who resell a lot of tickets, and you need access to their "TradeDesk" tool to do it: https://tradedesk.ticketmaster.com
If nobody used them, they would go away.
You writing your congressperson is more likely (albeit, still not at all likely) to make a difference than you not going to your annual concert.
This kind of gross exclusionary contract should be illegal (it's kinda the same BS that Google does with Android OEMs - contractually force them to [1]), but for some reason antitrust avoided acting on the matter (including allowing acquisitions in the space) for quite some time
[1] > Predicating the availability of any of Google’s apps, including the Google Play Store, on OEMs not taking advantage of the open source nature of Android on devices that will not include Google apps seems much more problematic than Google insisting its apps be distributed in a bundle. The latter is Google’s prerogative; the former is dictating OEM actions just because Google can. https://stratechery.com/2018/the-european-commission-versus-...
They now, having merged with LiveNation, have effective ownership of all major and semi-major venues around the country. They also aren't just doing concerts, they're doing sporting events and other live entertainment as well.
They aren't going anywhere. They are just too big, and too ingrained.
At the very least you have the choice not to go to any concerts until there are better options. You can also make that clear to your favorite bands.
And yes, if there are no concerts with acceptable terms (and that's really a hypothetical if) then don't go to any for the rest of your life. You make it sound like this is some kind of required part of the human experience when it is just one of many possible ways to spend your time. Even if you are really into music, concerts are just one way to experience it - and when it comes to audio quality, a fairly crappy one.
> Even if you are really into music, concerts are just one way to experience it - and when it comes to audio quality, a fairly crappy one.
This fundamentally misunderstands why people go to see live music and honestly maybe what people enjoy about music entirely.
Ticketmaster is basically “customer punching bag ad a service”.
Venue owners are profiting. LN/TM can pay them a lot for exclusive rights thanks to their monopoly-inflated profits.
Why would Ticketmaster/live nation pay them at all? They don’t have to, the bands don’t have any other places to play and they make most of their income from live shows.
Choice quote: "It is a greedy scam and all artists have the choice not to participate. If no artists participated, it would cease to exist."
Perhaps they give artists a little to encourage participation in some ancillary revenue, I don’t know. I’ve mostly worked non-TM venues. But I’m sure the promoter gets most of that too and it’s not a lot of the overall ticket sales.
I can tell you for sure, everyone but the venues feels they would get more without the monopsony. There is not a functioning market for concert promotion once you get to the 10,000+ seat level, and TM is actually even buying up the ones below that too.
Your only end run around it is the festival circuit since a lot of them are out in a field rather than a venue, but guess who is buying those up now also…
Do you have a source for that statement? The article about it linked below does not back up either assertion. I’m pretty sure they’re dynamically priced by a TM algo, and I’d bet little of it goes to the artists.
Granted, I live in NYC, which probably has one of the most vibrant local music scenes in the country. But it's not like nowhere else has local bands that play at small venues.
It feels like a lot of the people that complain about ticketmaster's monopoly have never branched out from Billboard chart artists.
Even the most 'hole in the wall' places around here have deals with LN/TM, short of a bar-band or niche-local joint.
One of the more 'fun' ways that LN/TM did shenanigans at the past I observed: Metal shows at smaller places in the Detroit area like Harpo's (famous place but known for the sketch area) or Token Lounge (literally a bar with a dance floor and stage, pretty fun tho) you'd have one of the local small/startup bands selling tickets, often -below- cost at the box office.
Why? If they sold enough tickets, they got to play as an opener. Yes some scammers would try to fake this, but I never saw anyone actually get 'taken'. And yes I'd buy them if I didn't already have them to help the locals out.
That said, the concerts at those smaller venues, despite being TM/LN, were in the 20-30 dollar range after fees. Not 'top billboard' type stuff per se but Children of Bodom, Lacuna Coil, and other 'popular but niche' bands in the 2005-2007 timeframe.
1) Why would TicketMaster pay event organizers ahead of time, if the event might be shit and attendees may demand their money back? Rather than having to deal with a lot of chargebacks and making it their own problem with the banks, they might prefer to make sure the event goes off without a hitch and refund people while they still can. Rather than subsidizing the refunds they make the event organizer have to get (and pay for) financing instead, backed by their payout. They might also offer such financing.
2) I get that they hold event organizers hostage by making contracts with the venues for years, that might be an antitrust issue but it’s separate from 1.
3) Why would TicketMaster make scalping easy? Middlemen would just buy up all the tickets and then pump and dump the price, much like early crypto investors in a meme token or altcoin do. So they don’t “deliver” the ticket to you until just before the event, exactly for that reason.
With ChatGPT it’s now easier than ever to impersonate thousands of people at scale, with credit cards and everything. But I will admit, showing up to an event at least once confirms there is a human behind the account. But a first-timer buyer? Shouldn’t be able to resell, no.
I built a blockchain-based solution.
It features a price discovery mechanism: you auction off M tickets to M people, the price goes up every time after M people buy and the oldest buyer is booted when the others buy, but can buy back in again. Buyers can set a “reserve price” to automatically bid up to that price.
No scalping, because tickets aren’t transferrable.
Similarly, you can disallow transfering of bearer token X but let the user sell it back to the central market maker and someone else buys it. Enforcing commissions on sales.
Blockchain makes all this work, decentralized.
But then they literally built a whole platform (link in my last comment) for actual scalpers to resell tickets in bulk. So, they're not trying to prevent scalping, they're just ensuring that only their "partners" can scalp.
But when everything in the world was being cancelled I assume they didn't have all the money just sitting around to reverse and it was a ton of thrash to deal with. As someone who had bought tons of tickets and sold some, it was a mess. I had a ton of credit card refunds back, the third party sites had to reverse payments, etc.
Waiting until after the event is just less overhead. Guarantees the transaction happened without a hitch.
There are some POS and broker sites that still pay on transfer, but none of the "primary" secondary market does.
(disclaimer: I'm a complete outsider, last time I bought anything from Ticketmaster was a really long time ago).
Not at all difficult - simply share screen a third device and display the rotating QR-code through e.g. zoom on individual phones. For additional trickery, try to split the group into joining multiple ticket scanning lines and timing the scan of the ticket to be as close as possible to eachother.
I imagine it's more about discouraging scalping, regardless of what they may say about it.
Anything that can be used to monetize stolen cards will tend to be used for the purpose even if it's inefficient.
There's a section named "Pirating Tickets", that just explains how to re-create a barcode that you already paid for. You're not using this to rob anyone of anything.
And at the end, "Have fun refactoring your ticket verification system". Why? There are no vulnerabilities here. A rotating barcode (even if following a known pattern) is still more secure than a static barcode on a piece of paper.
You're also walking into a stadium/concert in plain view of security cameras, so the stakes and deniability are different as well.
They are just trying to prevent scalpers printing off tickets 10 times and selling them outside the venues as a scam, which happened at every large concert I have ever been to until recently (so I assume this is working!).
I assume that's true, but it makes me wonder how their scanners are connected to the server.
I mean, if 10,000 people showing up to an event with smartphones overwhelms wireless networks, wont that also kick their scanners off the network?
They'd probably like to have a system where, if a scanner loses its connection, it can still validate tickets. It could store a copy of validated tickets locally, and upload it when the network connection is restored - that would mean a copied ticket would have to make sure they go to a different door/scanner. But it would allow copying.
It's all off-the-shelf electronics and standard protocols. Venue provides some wifi with a "Ticketbastard" SSID (or whatever) at entry points, and the COTS-built barcode-validating devices use that. Easy-peasy.
They might also provide other wireless networks for other purposes (definitely for vendors [$$$], but perhaps also for regular house staff, touring staff, and maybe even the guests who pay for it all!), but they'll all be under the venue's control and coordination: Other than the odd personal hotspot that wanders in, there's not necessarily any meaningful outside interference on 2.4/5GHz wifi bands in a big venue.
It's pretty easy to make short-range wifi work reliably in that kind of RF environment, such as the chokepoints where tickets are validated. (Modern apartment dwellers will have worse interference problems than that.)
I don't pay very much attention to the ticket-scanning devices while I'm getting into a big show (which is generally a rather unpleasant experience on my side), but:
Don't they allow usage of 5GHz bands? Unlike 2.4GHz, I've had tremendous success with 5GHz bands in all kinds of environments -- including outdoor festivals.
Even at huge venues i dont expect requests would be over 5 rps
I think maybe 4-15 seconds between scans per scanner, at best.
Even at 1 rps that's if we assume 1 meter distance that's 3.6 km/h or a normal walking pace. Do you ever see crowd at ticketing move at walking pace?
E.g. this weekend I went to a show at a 70,000 seat arena. Knowing from experience, there are 4 entrances. This time there were 10 people scanning tickets at the gates I entered. Friends reported the same at the one they came in.
5 RPS per scanner is obviously overkill, but if those 10 at one gate were linked to a hub that could issue 5 RPS I would call that adequate, if barely.
If all 4 gate areas were linked centrally to a system that could do 5 RPS, well, actually, that might explain the throughput I experienced getting through lol
Heard from a friend who got straight into two events in the same city recently - they presumed the show was at one outdoor venue but the scanners let them straight in at the first (wrong) venue. Went to the correct venue and got in there without any issue too (this suggests one or both venues were offline or using offline scanners).
i.e., theoretically duplicate tickets would be identified but not instantly but still pretty quickly
If the seller re-opens the TM app and it generates a new token and invalidates the old one, then that's not the case.
While this has the upside of breaking you free from TM's obnoxious practices, it also obviously opens up for scalpers and all.
Recording the ticket with a video is everyone's first thought at defeating their restriction, and is no doubt the first thing they thought of when designing it. Hence, the codes expiring too quickly that you'll need a new video before you get through the line at the entrance of the venue. And messing with videos in a pressured line of people in front of a bouncer, is, as others have said, simply not practical for the vast majority of cases.
So it's kind of irrelevant - practically speaking - that it is possible.
That is one of many ways this is already exploited in the wild.
"this suggest a fundamental lack of security practices at the company" – that's a stretch of a conclusion to make. You're being as hyperbolic as the original post.
What didn't I understand about the article? This still offers a slight increase in security over static barcodes, without introducing any new vulnerabilities.
It offers nothing to the user, except taking away their rights, and making it all unreliable
It says that it is available offline (if you've viewed it in the last 20 hours), so the TOTP generation can't happen remotely
It's enough to defeat screenshotting and the 20 hour bit would defeat large scale malicious use.
Not good security but probably good enough, especially in stopping the resale of stolen tickets.
I have to believe the reason the likes of ticket master isn't fixing this is because they are selling/auctioning/reserving some percentage of tickets to scalpers or "3rd party sellers".
Requiring ID is such an obvious solution that I have to believe these convoluted approaches are only there so the secondary market can exist and so ticket master can wash their hands when prices get out of control on that market.
But I mean, obviously, any kind of system like this strikes me as the same sort of thing as DRM. That you can somehow protect the message from the person you're sharing the message to. How can you avoid reselling if you don't verify the original purchaser? It just seemes ridiculous on its face.
We check IDs for flights because airline yield management demands that there be no resale, or business travelers would be traveling on leisure fares.
Sorry, what? Surely business travelers pay more just by virtue of traveling by business class? Or, if travel through business portals was consistently significantly more expensive than just buying the ticket directly on the airline's website, businesses would just start buying tickets directly from the airline's website?
Is there something about how ticket fares are calculated and paid that I don't understand?
Airlines use a fair number of techniques to price discriminate between leisure and business passengers.
Consider an example where we have a business traveler "Bob" and a leisure traveler "Larry". Bob needs to get to LAX tomorrow to put out a fire at a client site. Larry has a trip booked to LAX tomorrow, but can't go because he's sick. Larry has paid $500 for the trip 3 weeks ago.
Today: Larry cancels his trip, and maybe, if he's lucky, gets an airline credit for the original price of the trip that expires in a year and which may be hard to use for his next trip. When he cancels, a seat opens up on the plane, and the airline sells it to Bob for $1200.
If resale was permitted: Larry auctions off his ticket at an airline ticket reseller. He gets $700 from Bob. So if resale was permitted, Bob's business saves $500, and Larry makes $200, and the airline looses $1200-$1700. You can see why they hate resale.
Likewise, there are plenty of non-business flights booked last-minute like that, too - like, as a personal example, needing to book a same-night flight to help a family member drive cross-country with her kids and personal belongings so she could get out of a dangerous personal situation.
All this being to say: if price differentiation between in-advance v. last-minute bookings is actually intended to make business travel cost more than leisure travel, I'm thoroughly skeptical of that intent being fulfilled in practice. Seems more likely that it's simply a matter of things costing more when they're more scarce (as seats on an airplane would become as it gets closer and closer to the departure time), and that just so happens to impact business travelers more than leisure travelers.
Back in the old days, sales like this were common. No ID checks, non-passengers allowed through security, and the classified ads in newspapers would say “round-trip coach ticket May 8-12 JFK to SFO, male name, call 212-555-1234”. So you met them, got your paper ticket, got a boarding pass at the counter or the gate, and flew.
Don't they already do that anyway? Every time I've gotten on a plane for work purposes, there was no differentiation between "business traveler" v. "leisure traveler" as far as the ticket purchasing process was concerned. Hell, in the most recent case it was even with my own credit card (for which I submitted an expense report to be reimbursed) - so for all the airline knew, I was just taking a week-long vacation to Colorado Springs (in that case) instead of being there for work.
If you could buy someone else's ticket on the secondary market, then you could do a split ticket thing where you both stay Saturday night but neither of you actually do.
Everyone should change their name to Pat Smith and end this scam once and for all.
I recently flew from the US to Europe and returning on Thursday or Friday was twice the price of flying home on Saturday or Sunday - the weekend return options actually showed up as free during booking.
That requires the admitter device to send the challenge back to HQ, but that shouldn't really be much of a challenge. Tickets then become linked to the user's account (perhaps you allow transfer).
This is effectively what Disney does with their ticketing system, along with at the gate them taking a picture of you so they can confirm "Yes, so and so looks like the photo".
But yeah, all of this is ridiculous on its face as the cheaper and easier solution is ticket plus ID. If you are worried about flow have signs up before check in that say "be sure to have your ID ready before you get to the counter".
The ticketmaster solutions are just bad/half assed.
That is to say, if ticketmater had just done TOPS like the article points out, you'd not need the headache they've created with needing a live internet connection to load your ticket.
Any solution that increases capital or operating expenditures for them or the venues (half of whom they own, if I remember correctly?) is a non-starter if it doesn't generate some increase in revenue.
They will not do anything they don't have to do if it means any impact to their bottom line whatsoever.
We see it as "pennies per transaction."
They see it as "we sell 500M tickets per year so five cents per transaction is $25M/year in lost net."
> These rotating barcodes on the other hand are far from perfect. I experienced this first-hand last year when I attended another very popular concert where they used a similar rotating-QR-code-ticket system. Numerous people including myself and my friends were floundering at the entry gate citing a bevy of broken barcode problems. ...
> The venue was so crowded that cell-towers and WiFi were overloaded. Internet access was spottier than a Dalmatian with chickenpox.
That is impact to their bottom line. They have admittees waiting at the gate blocking other people from getting in cutting into their concession sales.
If they'd used a bog standard TOPS system (like the op suggests) that would not be an issue at all. But instead because they have the dumb system where you reach out to the ticket master servers to get your code, they've created their own nightmare.
That's a different system. The article makes it clear that the Ticketmaster system works offline if you have opened it on the mobile app. Which they don't want to install.
I never asked for this BTW, would rather have a paper ticket.
A ticket scalper cannot know the names of the people that will later purchase his tickets. So connecting each ticket to a name prevents scalpers.
But they in turn greatly degraded the flow of traffic by forcing the use of a proprietary always-online app which fails to load when your cellular connection is less-than-ideal. Verifying a photo ID would probably be faster.
They will instead ask "well why isn't the connection good at the concert? What can we do to fix that?" (ie. "we don't have to change when we can make you change")
It IS true that if you don't have to verify the ID of the ticket holder then admissions will go much faster. So long as they can make that plausible sales pitch, they can use it as justification for whatever byzantine DRM system they can dream up.
To hack around this, I've used Southwest Airlines; I can buy tickets for folks and if they can't travel, we cancel the ticket(s) and keep the travel funds banked for another time. I hope this is potentially helpful information.
https://simpleflying.com/why-airlines-dont-allow-name-change...
hopefully their new changes such as allowing their fares to be indexed will make them close to being competitive at some point. but today you really only get near-competitiveness (it's still bad) if you're going to check both pieces of luggage and have no way of getting free luggage on any other carrier.
even buying and throwing away tickets, depending on your probability of travel, might pay for itself in one trip.
https://community.southwest.com/t5/Blog/Southwest-Airlines-R...
https://www.nerdwallet.com/article/travel/is-southwest-airli...
The seats are more comfortable. Every plane has pretty good in-flight WiFi (paid) and free movies/TV you can watch on your own device. Drinks and snacks included. Two checked bags free. About the only thing I miss from the big carriers is charging/power outlets at the seats, but I hear that's coming.
You COULD still scalp tickets if the person who bought them from you is going to walk in with you. But the scalper would have to eat the cost of one ticket to do it, and it's probably onerous enough to severly reduce the impact of scalping.
Every ticket must have one name and surname on it, no matter how many passengers it covers. That person must be traveling on the ticket.
You're usually asked for some kind of photo anyway because of discounts, which a very significant percentage of train riders are entitled to.
I think this is because tickets must be both printable and verifiable offline in case the train gets into a spot with no connectivity when the inspector is inspecting tickets.
Here, train tickets need to list every passenger along with their age and gender. This also enables you to cancel for just one person on the ticket without affecting the rest.
The ticketing system basically assumes no network connectivity. Ticket inspectors usually only ask you for your name and match it to their records. And only ask for and id in rare situations (you absolutely need to have yout id with you irrespective of infrequently you actually need to show it).
As a frequent concert goer, I’d happily have to arrive with my group if it meant no Ticketmaster.
If you think scalping isn't enough of a problem to balance out the inconvenience of having to plan the ticket purchases better, well, uh, that's just like, your opinion, man. We'll agree to disagree. But it does mitigate a problem, scalpers inflating prices.
I don't have the solution explicitly, but it seems like it ought to be possible to do this such that PII need not be collected. Tickets could be cryptographic proofs that a chain of custody exists and meets certain criteria. The proofs could be constructed at transfer time and verified at admission, no servers in the loop anywhere. Yeah, we'll come up against the CAP theorem eventually, but we might find that the imposed constraints are workable.
You know as well as I do that TicketMaster won't allow any of that, because it means they miss out on selling another ticket.
Why though? Not disagreeing per say because I'd have thought so too, but upon reflection...
I assume the main reason airlines require an ID is safety and security. We maintain a denied parties list and use identity verification to make it as difficult as possible to fly a plane into a crowded venue. Border control is another issue, but there's plenty of intra-country or intra-state flights where this isn't an issue.
Ticketmaster sells unverified access to crowded venues.
I'm also probably overly discounting border control. Traceability in particular. I'm not a fan of this either.
[1] https://www.schneier.com/crypto-gram/archives/2003/0815.html...
Practically, I don’t want Ticketmaster having access to the information on my ID, they already leaked lot of my other PII.
Can no longer pay cash, have a paper ticket, be anonymous. Those are much more important to me than preventing scalping.
Scalpers out front have provided a valuable service to me a dozen times over the years, when I didn’t plan well.
Any solution (I didn’t ask for) that turns concerts in an international flight experience means they are dead to me.
Age was traditionally checked separately and manually. Not put into a database to be bought and sold and breached.
I did not have an ID, and none was required to get in.
All-ages shows are definitely things that exist.
It's to my understanding mainly the US where ID requirements are often side eyed because many people don't have them and there's no national standard (and due to a variety of political reasons there probably won't ever be any.)
In the US, permanent residents are required to carry their green card at all times.
Here's a description of the law for the Netherlands, where I live: https://www.government.nl/topics/identification-documents/co...
I just went to a MLB game yesterday, and the digital process was:
- Open ticket app
- scan ticket 1
- scan ticket 2
I imagine this could have been: - Open ticket app
- scan PDF417
- scan ticket 1
- scan ticket 2No more opening app, and showing different tickets and IDs.
That would clear that argument.
But for another, not everyone has a state ID card. In particular the 7.1% of the population that does not have U.S. citizenship will have varying amounts of US documentation, depending on how long they're in the US for and whether they're there legally.
And you really want to be able to sell tickets to tourists.
people complain at ticketmaster yet seem to bend over backwards to justify the state of affairs
If/when https://nfc-forum.org/news/2024-07-nfc-forum-defines-next-ge... gets implemented by Apple/Google then we could one phone tap, get the ID, the ticket and verify that they match.
But I have no idea when Apple or Google would implement those ?
Tickets have your name on it, and you can only change the name or resell them through the official seller (so, third party resellers are out of the game). Also, every reselling transaction is registered and can be inspected by the Italian Rightsholder Agency (SIAE).
- not allowed to change to time or name of the event after the 1st ticket is sold
- only allowed section names in halls from a know list
- free tickets on events... can only do this under strange conditions
- smart card application, for encryption, must run on a physical server in Italy. You should not be able to log into the ticketing box office if that smart card application is not running.
There was a recent story of someone taking pictures of other people's boarding passes, and using that to board the plane.
With this ticketmaster scheme, unless the person has access to the secret keys, the pass would only be valid for a few seconds, likely defeating this attack against boarding passes.
https://www.nbcdfw.com/news/local/texas-news/texas-man-board...
This is security FUD. Stop solving problems that do not exist to the point where it makes the news when they do happen, once a century.
This DRM scheme concretely creates millions of small annoyances to millions of people and wasting our time as a society.
Sure, it won't happen to you or me, because we know it is a risk to expose these documents, but that is not true of most people.
Maybe the DRM is not worth it. I actually think it's obnoxious for concert tickets (I recently had to deal with this system, and I was not thrilled about installing an app from a company that I think is using unfair business practices).
The security theater of checking ID does nothing to stop this. What's your point?
I only use paper boarding passes if they insist on giving them to me when I check my bags or if I’m flying internationally and am worried about connectivity in one of the transfer airports. They go straight into my travel wallet (full-length, large enough for letter or A4 paper folded, with enough space for two passports, several credit cards, a pen, and plenty of cash or other documents). The company that made mine is unfortunately out of business, but https://www.leatherology.com/zip-around-travel-wallet is similar.
In a perfect world, the digitization of these IDs would come with modern digital privacy and security. Scanning your ID number would only provide a recipient-specific ID that couldn't be matched with other vendors. Age eligibility and driver's licensing status would be presented as separate signed attestations that share no other data.
We aren't even heading in that direction yet.
But none of us have any intention of lining up with the others to get in. We want to go with our partners, our own friends etc.
I want Bob, Terry or Bazzy to by able to buy tickets for me (or me for Bob, Terry or Bazza) but I do not want to have to meet up with Bob, Terry and Bazza and stand in line with them all to get in.
So yea, it's not trivial. I wish it was, I farkin' hate scalpers.
The interesting mechanism there is that you can buy a lot of seats at once, but you don’t get to choose where they are exactly, only the section. So in every case you’re going to have people buying big lots of tickets and distributing them to friends and family after the fact.
A lot of people think live event ticketing is the same problem as airplane tickets, but they really aren't. As an example, there are rules about requiring identification for commercial flight. There are rules against requiring identification for live events.
I’m not making the argument but it’s an argument I’ve heard.
Said festival does their own ticket re-sale to avoid scalping but mainly to avoid shady sites that are known to allow the selling of counterfeits. You can only cede your ticket, not sell it. It is not perfect (e.g. if you don't find a buyer for the same price, you can't sell it at a lost to recoup some money. You get your ticket back) but at least is not as bad as the one from Ticketmaster.
A music festival I went to recently charged 30 euro to change the name on a ticket.
It'd then be impossible to buy a few tickets to an event with the intention of finding people to come after the fact.
> Can I work for a bad company and still be a good person?
> No.
OP wasn't the one trying to define it.
No matter which company you choose, someone somewhere will find a justification for why they are actually not bad. Weapons dealer? Protecting your nation. Destroying local businesses? "They are just adding efficiency to the market". Kill someone with bad practices? "Still safer than the alternative". Ticketmaster? "The scalpers are giving a subvention for those who cannot afford the real price".
Setting up a straw "bad company" and knocking it down doesn't help anyone on the real problem of people working for unethical companies.
Especially on the west coast, we're so passive in our shaming of people that it probably doesn't translate to action. There are people who work at Evil companies like Facebook, etc, who are otherwise nice, but I find myself not including them or turned off to them as friends because this sort of contradiction is hard to square in my brain. Of course I wouldn't communicate to this, being a passive PNW raised wimp, and it's not even super explicit in my mind, it's really more of a bad vibe than anything else. I imagine over time if enough people act like I do, it doesn't actually translate to different decisions from the individual in question, but instead translates to them waking up one day feeling distant and unfulfilled, which is probably the worst of all outcomes. They still work for Bad Company, but are also sad about it, and there's a general sense of malaise pervading life that's hard to pinpoint.
*Obviously this all ignores the people who don't have a choice of employment. But here I'm generally referring to software people who have high pay and career mobility. Things get murkier when the conversation is opened up to people who are just trying to survive.
I think the Leetcode grinding, TC optimizing crowd with no real moral judgment which is the majority in tech right now is another reason why things are falling apart. They will happily work for the KKK if they get a larger RSU package.
Your point about them being at least "sad" about it, is a start I guess.
If you no longer feel pride in your work, then money takes over. In my search, no employer cares about this anymore because the newer generations are only here to grind for gold.
I don't question that the problems you're describing are problematic, but what do they have to do with postmodernism? It seems like in the cases you're describing, the postmodern approach would be to call into question whether the abstractions in use ("value" in this case) are applicable, and to instead march to the beat of your own drum in some way.
When most of the relevant work around you is in some way related to ICBM's, you either sell your soul early, or you end up with habits like this. By my reckoning, about 80% of technology companies are bad.
And trying to objectify value judgements is another whole area of contention that inevitably leads to itself.
But the point of reading a blog post would be to learn something insightful, to see the reasoning or argument by which the poster came to this particular conclusion. Hopefully with some consideration that I'd not thought of before.
This boils a complicated question with nuance and problems and facets of debate into a rather vapid "I like this answer." of a post. It's not worth anything: I come away from it no richer than when I came.
Like, trivially, someone could write the opposite answer on another blog. And whose answer is right? (They of course need not even bother actually writing it out. A "right" answer is created by argument, not spilled ink.)
Lets re-invent religion.
The answer to "What happens when you move faster than light" is not "nothing", it is undefined because the question is invalid. Asking if a person or a company is good or bad isn't a question that can ever have a well-defined answer: the answers we give are rounded according to our own values. To get more specific, not all of us have a huge amount of choice in who we work for.
If apenwarr believes I want to be a good person they should hire me at Tailscale. What's that, they won't? They don't have openings, or I'm not qualified? I guess they're the bad person because now I have to work for a bad company or lose my income. And if I lose my income, my co-habitants lose their housing, and my donations to good causes dry up. Do I just not do enough good for apenwarr? They must be a paragon of virtue. Surely they don't eat meat, or even associate with meat-eaters. Surely they don't fly in airplanes.
Counterexample:
Was Hitler bad?
I don't think it's useful to say "Hitler was bad." Hitler did a lot of specific evil acts that are more useful to analyze. If anything, it's counterproductive to say "Hitler was bad," because lots of people do bad things and then say "well, at least I'm not Hitler."
It's still useful to point out that IF you think your company is bad THEN you should do something about that. It establishes that "I was just following orders that I know are wrong" isn't a valid excuse (e.g. like if you end up in court for something you did on the job).
Well, I'm responding to someone else providing their scheme for everyone else to use.
I agree with this entirely.
And rounding does not change the answer in most situations.
Something that isn't well-defined can still be mostly-defined.
I have no idea what the point of that strawman is in your last paragraph. It doesn't make sense with or without rounding. Maybe if you round every single value to infinity, but that's not what "rounding" normally means...
You said when people look at moral situations, they use their own values to round their measurement. And I thought that was a good way to describe things.
Then for some reason you acted like "rounding" turns things into strawman-level black and white. The slightest blemish (not hiring a specific good person) qualifying as evil.
Let's say a scale of 0 to 10. If people disagree whether some issue is a 3 or 4, and a few people say 5, and that's 95% of responses, then that disagreement isn't a big deal. It doesn't matter that it's not well-defined, it's sufficiently-defined.
That would be rounding. Showing that the question is not nonsense.
If they disagree whether it's a 0 or a 10 that's a totally different thing that is not rounding.
> Then for some reason you acted like "rounding" turns things into strawman-level black and white. The slightest blemish (not hiring a specific good person) qualifying as evil.
This was in direct response to the top-level comment making that very assertion (via a blog post). If I'm understanding you correctly, I think we're actually agreeing that it's absurd. The CEO of a "good" company indirectly, but unambiguously, called me a bad person for not leaving my job. I say, if it's so cut-and-dry, and I want to be a "good" person, why aren't they helping me get a better job? Of course, it's an absurd ask.
Somebody isn't only allowed to be "good" if they do every good thing possible to them. And I am sure said CEO does many acts others would consider "bad", such as eating industrial meat or flying, both of which participate in the generation of immeasurable harm.
---
Also, with regard to your scale - you've given the question too much credit. The question doesn't ask "how much are you good or bad?", it asks and receives a binary answer. And the vast, vast majority of people can't be assigned one of those binary categories of "good" and "bad".
"A good person is obligated to quit a bad company." is a far more reasonable statement than "A good company is obligated to hire every good person."
> Also, with regard to your scale - you've given the question too much credit. The question doesn't ask "how much are you good or bad?", it asks and receives a binary answer. And the vast, vast majority of people can't be assigned one of those binary categories of "good" and "bad".
You can pick a threshold. Your strawman would categorize 99.9% of things as bad, which is obviously the wrong threshold, and very obviously not what the OP meant. The failure of that method doesn't make the entire idea of judging companies invalid.
I'm not giving it "too much credit" to take a sane and quite obvious interpretation.
Yes, the bar is higher (higher means it's harder to qualify as bad, right?) when talking about needing to quit.
> I already asserted at the very beginning of the comment chain, almost every company is bad. That went unchallenged
Because you went on to say it didn't matter anyway, so I focused on the latter part of your post.
Though I'm confused. You showed an argument that sorting companies into good and bad results in absurdity, but it only results in absurdity when the bar is super low. Why is your conclusion that sorting is impossible, rather than "the bar is too low", if you were already seriously considering that the bar needs to be higher?
I also thinks it's misleading and not very useful to call people good or bad, in general. I'm more comfortable with calling capitalist corporations "bad" as a blanket statements; resource-hoarding is their utmost priority, and I consider that an evil motivation.
My conclusion isn't that sorting is impossible, it's that people are too complex to be sorted into "good" and "bad", in general... and that it's shitty and incorrect to call ordinary people bad if they aren't willing to risk everything to work for a slightly less evil company in a world made of evil companies.
In particular 'slightly less evil' is not the goal.
Again, I think we're kind of on the same page, but our solutions are different. The original question refused any kind of nuance, and we both seem to agree it's not a question that should ignore nuance. You choose to answer a binary question with a grading system, I choose to substitute a different question.
> No.
Laser printers are the solution, and Brother laser printers seem to remain the most highly-regarded.
A brother laser can often be had for $100 these days.
I actually recommend HP but Brother is great too. My current HP is at least 10 years old, and it's the second I've owned. My first was a 2000 vintage which I used from 2005-2017. (Its rubber rollers eventually got dried out and I wasn't as skilled a refurbisher as I fancied myself)
I've really appreciated my local library for allowing 20ish pages of printing per day, which has allowed me to limp through the no-printer lifestyle. Plus I usually grab a DVD movie while I'm there.
Life's good in the mid-2000s.
The WiFi in the O2 was woeful, and even on "The best network" EE the app wasn't loading.
Eventually after stepping aside and letting a load of people go in front of us I managed to get it to load, but it was a dreadful experience.
Contrast that with seeing the Pet Shop Boys last month in Birmingham where the ticket was on my phone in Apple Wallet was night and day (and you could print the ticket if you didn't have an iPhone, or wanted a physical version).
Source: I am an engineer within TM that has worked on integration between various booking products in the UK market.
> I think we can all agree: Fuck TicketMaster. I hope their sleazy product managers and business majors read this and throw a tantrum. I hope their devs read this and feel embarrassed. It’s rare that I feel genuine malice towards other developers, but to those who designed this system, I say: Shame.
> Shame on you for abusing your talent to exclude the technologically-disadvantaged.
> Shame on you for letting the marketing team dress this dark-pattern as a safety measure.
> Shame on you for supporting a company with such cruel business practices.
> Software developers are the wizards and shamans of the modern age. We ought to use our powers with the austerity and integrity such power implies. You’re using them to exclude people from entertainment events.
> Have fun refactoring your ticket verification system.
I don't know how many times I've reasonably pointed out why our product is extremely user-unfriendly - backed by evidence from user feedback and endless reddit complaints - but I still get shot down, badly. "Disagree and commit" they say, which is just short for "do what we tell you and shut the fuck up". If you bring up issues too many times, you end being treated like an agitator and they make your life hell. This has remained true for the many different industries I've worked in over the last 17+ years. Software developers are effectively powerless in many organizations.
Helping a company use some sleazy dark patterns to make some extra money off of Taylor Swift tickets is honestly pretty mild on the scale of evil software engineering jobs, so I imagine their answer is "I built a system to sell entertainment, now my kids get to go to private school, and I sleep great at night."
Ticketmaster sucks, but it's not like he's working for Palantir, Lockheed Martin, or TikTok.
I have been to Ticketmaster events that use reasonably priced, printable tickets, you could even buy a printed ticket with cash. In fact, even though there are so many Ticketmaster events, they are not all working the same way. And Ticketmaster doesn't have the monopoly on shitty practices, the article gives a good example in the beginning.
What I suspect is that Ticketmaster is nothing more than a service provider. The venue/event organizer/... looks at the Ticketmaster catalogue and pick the product they want. There are "evil" products in that catalogue, and they are probably the ones with the best returns, but I am sure people have a choice.
I'd even go as far as calling Ticketmaster "Evil as a Service". So people can say "fuck Ticketmaster" instead of saying "fuck Taylor Swift". I would be very surprised if artists (and their agents) at the level of Taylor Swift didn't have a say regarding ticket sale practices, even with Ticketmaster.
Of course, the monopolistic practices of Ticketmaster are a problem, people are most likely paying more than they should because of it, but all the crap with apps, resale platforms, etc... I am pretty sure the event organizers, maybe the artists themselves are as much to blame.
Correct, except rather than "evil" it's "market-clearing pricing". Of course many people see no distinction there.
Often, they do not. The DOJ is currently suing TicketMaster because they have exclusive agreements with nearly all of the large venues and that prevents those venues from using other ticket providers. To be fair to TicketMaster, they argue they are not a monopoly because there are many smaller venues that they are not exclusive with.
But, TicketMaster even requires that artists use TicketMaster's promotional agency if they want access to these large venues.
And more evil stuff! Details here...
https://www.justice.gov/opa/pr/justice-department-sues-live-...
I was talking about using Ticketmaster (for the lack of other choice) but using one of the more consumer friendly services Ticketmaster appear to provide. I am sure Ticketmaster won't mind, they get their share anyways.
What I wanted to say is that Ticketmaster may be responsible for your ticket costing $70 and not $60, but for all the other bullshit, they just do what is asked of them (by the artists, venue, event organizers, etc... maybe even the fans themselves). Or at least, that's how I think it is.
For the most part, no. I'm actually shocked by how much understanding you are demonstrating in this post. I did not expect to find that on Hacker News.
The venue "choosing" the Ticketmaster product is owned by Live Nation.
Some tiny stragglers perhaps. Went to a tiny venue recently but was goldenvoice.
This part made me want to throw up, preferably a couple of buckets full, right onto the heads of the marketing team who came up with it.
Kudos to the author of the article. Great work and a great read to go with it.
The ticket in Apple Wallet is still revocable if you transfer the ticket to someone else using Ticketmaster’s website, probably through an update that Ticketmaster pushes to the wallet [1].
[1]: https://developer.apple.com/library/archive/documentation/Us...
But it does solve the offline issue that the blog author was experiencing.
Great. So an app can plug my IP address into a geolocation query, and might ultimately determine that I'm somewhere in $city. Or maybe the next city over. Or maybe half a continent away.
But sure, this "works" without consent, since there is no extra step to enable networking for an app.
> nearby wifi networks
This doesn't work without consent.
> camera footage
This doesn't work without consent.
Web apps can also get the rest if you click accept when it asks for camera access. What exactly do you lose by installing an app?
Data Linked To You:
Purchases, Location, Search History, Usage Data, Financial Info, Contact Info, Identifiers, Sensitive Info.
Nope Nope Nope.
The same applies if you use their website. It'll still ask for that info with a web form.
...is not installed on any of my devices
Insular is an app that lets you create and manage one of these profiles on the device itself: https://gitlab.com/secure-system/Insular
https://www.nytimes.com/2024/05/31/business/ticketmaster-hac...
You do know that apps can record data in the background, right?
A website is also sandboxed by your browser in a much stricter manner than an app is on your phone, at least by default.
I don't have specific information on the Ticketmaster app here, but to say that an app is the same as website from a tracking perspective on a phone is absurd.
Perhaps you'd like to re-frame your comment or ask a different question?
So your position is that an app installed on my phone is not able to track or collect any more data, and does not have access to any other information, than a website that I load in my device browser (assuming I log into that website with the same credentials I use in the native app)?
I agree that this might be true in some cases. Note that I never said or implied that an app could do things without permission - but my fault if that wasn't clear.
Now, that said, would it perhaps be fair to say that the average user is much more likely to grant additional permissions to a native app on their phone than they would to a website?
If a website asks for your location, or access to the camera or to your contacts or whatever, I think many people would refuse. There's still a sense that a website is "out there" on the Internet, and you shouldn't necessarily trust it.
But when an app you've installed on your device asks for these things, in order to "operate properly" or provide functionality, then I think people are much more likely to grant it.
After all they've installed the app on their device, they've already trusted the vendor that much, it's only an incremental step at this point.
And once the device does have this elevated access, and access to more data, then there are absolutely more opportunities to collect data on users without their understanding.
I say "understanding" here rather than "consent" because typically consent is given via some long and complicated T&Cs that no one reads. Which is of course on the user, but again if you don't grant permission in the first place (because you're on a website not an app), it's not a problem.
And we have historically seen that some companies (not all companies of course) take advantage of this app access to collect data for themselves without your knowledge. I hope that part isn't up for debate here..
I have enough confidence in the sandbox that "installing an app" is basically never an issue (though I don't out of the principle that most things companies have apps for just shouldn't be apps).
I don't know the worst, but juice is not worth the squeeze in my opinion. If you recall, Ticketmaster was just recently hacked, so the worst pretty much happened in that any data they had collected on their users is potentially been leaked. So if they can't protect that data, then I'm not participating in giving them data.
It was 100% expected that you would have no cell signal the entire event and we built in as many mitigations as we could think of.
This was 2013ish, I think there are a lot more mesh network devices that can relay signal nowadays but I'm not involved anymore in that stuff.
It was the best on-call I've ever had because.. nobody had cell signal while the event was on to complain about something.
This person complains that people didn't have network access on their phones when they were at the gate. I can only assume that they waited till they were at the gate to install/use the app so it never got its offline data.
Always open your event apps before getting to the event. Sometimes they're completely bare bones and have to reach out and pull that apps specific database so its sure you have the latest. Most of the event apps are a template that is modified for each event and just has different assets/sqlite.
There's also the chance the ticketmaster app won't work properly later even if you did do it. I've had other apps shit the bed for no apparent reason in offline mode before. I add them to my wallet now just in case.
To be fair though I always get at least somewhat reasonable concert prices by doing presale. Sign up for the artist’s “presale club” and/or get the credit cards that have presale as a perk. Get in queue ahead of time. You won’t have to deal with the dynamic pricing/public sale shenanigans that we hear about. On Reddit I often see people complaining about paying at least 2x what I paid for similar tickets.
I've been a couple times, and what I've learned that was still not common knowledge to faire vendors as recently as last year is that T-Mobile brings out a mobile cell tower to support the faire, and no other cellular network does.
So if you're trying to accept electronic payments, the whole thing tends to fall over and you only get to sell to people who brought loads of cash and prioritized hitting your booth first. Only the vendors on T-Mobile are able to take purchases for a big part of the day, and a few other people who use the rare billing system that is fine queuing up Visa transactions until after the bulk of people leave. The line for the cash machine sucks up a substantial part of your time budget for the faire, meaning you probably miss out on some things altogether.
Then there are microcells, which can be privately owned. I worked at a place that had one when I was in mobile. There was a period of time when one of the carriers would sell you one if you were having connectivity issues. It’s possible for instance, living on a hill, to have a cell signal on your roof but not in the rest of the house and they can work as a repeater.
The idea of cellular networks is simple: Put the "source" of the bandwidth near where the people need it.
The idea of CoWs is also simple: It's the same thing, but it's dynamic and flexible.
---
There was a time in my life when I was using AT&T as an all-you-can-eat LTE provider through a third party as my home Internet access, because reasons (and hear you me, if DOCSIS had been an option then none of this would have happened).
Armed with a hotspot device that had external antenna connectors, band selection, and a Yagi antenna, I found a cell tower that I thought to be about 14 miles away that had consistently good Internet bandwidth. It was a ton better than several other much-closer towers (some only 1 or two miles away), presumably because it had better backhaul(s).
I made quite a study of things to get that dialed in and working reliably. And it was reliable for months. But then: One day, the signal had turned to shit.
So I did the right thing and I drove over to where I thought that tower was, 14 miles out, to have a peek. And the tower was right where I expected it to be.
But there were men actively working on the tower (with ropes and stuff), and a CoW of much-smaller stature was parked there and providing (rather lesser) backup service.
Which, you know: That explained that.
---
They additionally get used some for natural disasters if a tower fails, and also sometimes for other dynamic events like festivals and concerts and such. They're pretty useful when they work, in that a tiny sliver of bandwidth is superior to zero bandwidth. When properly-managed they can reduce contention on neighboring towers so that regular people doing their regular things are less-affected by whatever dynamic event is happening nearby.
I don't know about the specific site you mentioned, however the large broker platform Automatiq runs a number of domains like this, where they effectively proxy the original ticket token, recreate it with TOTP just as in this article, and display it to any user who has the right link in a similar format to how TM displays it. They advertise this service as "Transferless Delivery" to their ticket reseller customers. The main Automatiq one is called "secure.tickets".
It reduces work for sellers, because they never even have to transfer the tickets out of their Ticketmaster account anymore. Of course, it's horrible for buyers because they have no idea whether the random website link they were sent is actually going to serve them a barcode corresponding to a real ticket or not, or whether the site will be up, and they have no rights to the ticket as far as the primary ticket issuer (TM) is concerned, buyers don't even know the name on their own tickets.
Seatgeek and StubHub seem to be aware of these systems because of how closely they work with ticket brokers, and just coach customers to accept them if they are from any of the domains known to them. See https://support.seatgeek.com/hc/en-us/articles/2074030716443... the Automatiq site is called out specifically on that page.
Who thought it was a good idea to require an internet connection at an event. For anything, not just ticketing. It is as if the people who designed these apps never went to a large event.
No internet is the rule, not the exception. Sometimes, you can't even send a SMS. Apps designed for use in events should always work offline, and if internet use is justified, take into account latencies in minutes and use bandwith sparingly. Failing to do that will make the experience terrible for everyone, as bandwidth will be saturated by thousands of phones trying to do something with that damn app.
At least Ticketmaster does it somewhat right here. The app is supposed to refresh the ticket 20 hours before the event, to account for the fact that the internet may be unavailable at the gate.
Isn’t this not true? The risk with printable tickets is that a seller could sell it to multiple people, who all print it out, but then only the first person who uses it can get in?
Even if the venue doesn’t check to see if a ticket has already been used, only one person can sit in the actual seat.
They can't "print it out" because it's a rotating code.
> If you bought the ticket off the event’s official ticketing agency (not a sketchy reseller)
There could very well be a reason for someone to only sell a physical ticket, or not transfer it through ticketmaster, but I have yet to find anyone but scammers that want to do that.
The reason is, just as you mention, that scammers will try to sell multiple tickets. Then one (or many) sucker turns up to the avenue, only to discover that the ticket has already been validated.
Sure, and it is terrible.
They can block you from transferring the ticket you bought, and can set a minimum resale price (effectively ensuring you cannot recoup anything)
You should to own what you purchase, simple as.
Note that the portion of that you're quoting that you didn't quote is "If you bought the ticket off the event’s official ticketing agency (not a sketchy reseller)"
I.e., we're specifically talking about someone holding a ticket that they purchased from Ticketmaster. If there are multiple copies floating about, presumably at some point the artist (/the actual event) is going to be unhappy that Ticketmaster is screwing their fans/attendees over.
Of course we all like to dream up all sorts of technical crypto solutions to this, preferably decentralized to remove evil Ticketmaster from the equation. But I don't think the ticket scalping problem is a technical problem per se. I believe it is because tickets are currently sold under the wrong terms, which encourages scalping.
A possible solution could be to make tickets non-transferable, but always refundable. So only you (the buyer of the ticket) can use it, but you can't resell it. But if you decide not to go, you should be able to refund the ticket to the ticket office for full price. The ticket can then be sold again to someone else, for the same price.
Now, of course this is a naive idea. There are many practical and technical challenges to it, not to mention the politics of the entertainment industry. I'm not too familiar with the event industry, so I'm not sure if this would even align all the incentives, but it would benefit the fans and the performers who care about their fans.
Unfortunately, this "solution" is Ticketmaster cementing their control of the ticket marketplace and spying on their users.
Isn't that the market sorting itself out? What do you want, planned economy? How is fixing the price on a ticket different than the soviet union stamping prices directly onto manufactured items. I meant this to be sarcastic, but it's only half so, since I find the comparison appropriate, you know free market and all.
Every world economy is a mix of a market system and a planned economy. No economy is a pure market or a pure planned economy.
The incentive to scalp arises from the likelihood that a ticket will be worth more in the future (buy low, sell high) and that future worth is established by scarcity (sold out shows). To help eliminate this likelihood, the original price (face value) needs to decrease over time, ideally in such a way that the final original ticket sale occurs right when doors open, because the sooner that occurs, the bigger the opportunity for scalping. "Dutch auction" [0] is one implementation of this concept, though it's typically to find the most money a single buyer will pay, whereas in this case we have thousands of buyers. Perhaps the rate at which the price declines could be dynamically adjusted to aim for N% sold when N% of the on-sale timeline has elapsed, for any N.
The problem is convincing promoters/etc. that this would be as profitable for them as the status quo. But it might be!
Auction models are good for price discovery but this isn’t a price discovery problem, it is a supply problem. Believe it or not, artists don’t always want to maximize revenue from a ticket, they want fans from lower income brackets to be able to attend as well.
If face value is constant over time (i.e., the current model), scalpers can buy at any time that original tickets remain available. If they predict huge scalping margins, they'll buy up tickets ASAP, competing with the 17yo buying ASAP. And scalpers are more likely to have bots/scripts to help get in the moment tickets go on sale, putting them at an advantage over the 17yo. The 17yo probably ends up finding that the show has sold out to scalpers, so now tickets are too expensive. If the scalpers overbought, they'll eventually let the tickets go at reasonable prices (maybe even below face value) as the event nears, so maybe the 17yo has a chance that way, and many seats will be empty. If the scalpers underbought, great.
If face value decreases over time (i.e., my proposed model) from the original seller, then you've sort of got the exact same thing going on in terms of the rich buying early and the 17yo buying late, except the 17yo has one less middleman to contend with. Less chaos. Authoritative information about how many seats are yet to be filled. Bots that simply react to slow price changes like a human could, instead of bots that rush the release of tickets faster than humans.
In either model, the rich get their way and the 17yo gets whatever is left. But when well-controlled, this gap can be filled through need-based programs, student programs, etc. -- Broadway has some examples. These programs can be layered on top of, as they are orthogonal to, eliminating the incentive to use bad bots for scalping.
I don't have all the answers, but as someone who has been a musician for 30 years, programmer for 24, FoH audio engineer for 21, stock trader for 15, booked several shows, and buys tickets to shows every month or two, this is something I truly think could benefit the ticket-buying experience without excessive downside. The prices don't need to be astronomical (i.e., for the richest of the rich) when they first go on sale. They just need to be set, and reset continuously over time, so as to have N% be sold equal to N% of sale window elapsed, with the window ending at doors; sales would be almost exclusively to genuine show-goers because scalpers would almost exclusively be bag-holders.
If the concert is priced at $120 there are 200 people completely priced out, but there are 800 people who will pay. The tickets are released, they all scramble for the tickets, some from each of the 8 cohorts willing to pay the price are able to attend.
If the concert is priced the way you described it, all 100 tickets would be bought before the price ever goes below $200.
There is simply more demand than supply. The only way to fairly distribute that, if that is what you want to do, is by the lottery-esque system we have now.
No, the problem is artists wanting to falsely advertise low prices, and using gimmicks like first-come-first-served ticket sales and "scalpers" (usually fake, sometimes hired by the artists themselves) to do it, and the "fans" buying into this whole false narrative. If artists would honestly sell, and fans would honestly buy, at the actual prices, then the whole kabuki play of "evil scalpers" could be avoided.
This reverse-engineering also breaks if ticketmaster forces venue staff to only scan if the barcode is in the ticketmaster app. Unless you create a lookalike app to trick the staffers.
I once paid at Starbucks with the Apple Wallet barcode appearing in a photo of my phone displayed on the back of a DSLR. Plopped my not-remotely-iPhone-like Nikon D800 on the counter lens-down, LCD-up, barista scanned it without a second thought.
Phone number? The friction/expense of a scalper getting a new one for every sale would seem sufficient. Although I guess the scalper could reclaim (via password reset or whatever) accounts after the show to some extent.
$ date=$(python3 -c 'import datetime; print(datetime.datetime.fromtimestamp(1707074879).isoformat())')
Consider reaching for `date` from GNU coreutils instead: $ date -Is -d @1707074879
Fewer keystrokes, faster execution, and the output includes the TZ offset.It's a good reminder though. We are all smart individuals with wealth of knowledge, but we never know everything.
Otherwise I can't see how you would avoid replay attacks.
Once I buy a ticket, it's my property. I should be able to sell it, by any means I want, to any person I want, at any price we agree upon.
So I haven't read their fine print lately---is Ticketmaster is not selling you a ticket, but a non-transferrable license to attend the event?
They want to monopolise scalping
On non-rooted devices, those are pretty much impervious to the user trying to inspect their contents.
The Android docs mention a "secure timer" in the hardware security module, but I'm not sure that it can be used to prevent this.
https://developer.android.com/reference/android/security/key...
I can definitely think of worse things programmers are doing aside from making it mildly difficult to see Taylor Swift .
I have personal qualms with working in certain industries because of this, but Ticketmaster ultimately provides a luxury. You don't need to see a concert, and if you have such an issue with their business practices you can do something else with your Friday night .
I've actually never had an issue with Ticketmaster. At a point a certain other ticket provider just blocked me without any explanation, and I had to go down to the box office to buy tickets. That sucked, but compare to airlines who do weird things like print off tickets without the actual seat number, Ticketmaster doesn't bother me too much.
I don't agree. Entertainment/recreation is a need. Music is an important part of the human experience, and seeing it live, with other fans, is really valuable to some people. And the fact is, the value a person places on the experience is totally orthogonal to their ability to use/afford Ticketmaster. And it's not just about Taylor Swift - even local shows can be difficult to access without quarrelsome online portals. (But also, someone being obsessed with Taylor Swift isn't a personality flaw.)
Ticketmaster doesn't own have a monopoly on music. You can vote with your wallet.
"Clearly, the best answer to this is to forget about all of the music you think you like. Just forget all about it."
"Instead, go to the bar and see a band. It doesn't matter if you like the music or not; after all, we know that every live music performance is exactly the same as any other!"
https://help.ticketmaster.com/hc/en-us/articles/978498452737....
I go to a lot of concerts. Ticketmaster covers half of the shows I go to. They're not that much worse than others who also tack on fees amounting to 20% of the purchase price.
I'm not opposed to basic regulation, but let's not act like Ticketmaster is some uniquely evil company.
I'm going to keep going to see Big Rock Shows because that's what I enjoy the most. And I'm going to keep getting GA tickets (what seats?), because I am nowhere near old enough to stay out of the pit once my pant legs start flapping from a grotesquely overbuilt PA.
And in my neck of the woods, bands at bars can't scratch that itch.
So that means paying (and complaining about) Ticketmaster.
Not all of them, but online ticket is a convenience and then a trap. It isn't going to be outcompeted by me "voting with my wallet." That just betrays an ignorance of situation.
Oh okay, nevermind then. Heck, I just found some under my couch. How does Ticketmaster even make any money?!
Well, F.U. $COACH_COMPANY. I don't want to have to install your app for that, but I guess I won't have any other option if I need to get to the airport.
I'd say this highly depends on the fastidiousness of the ticket taker and the rules of the venue. I purchased Major League Baseball tix recently through my employer which uses a 3rd-party seller site that has restrictions like this (a moving graphic behind the barcode with the admonishment not to take a screenshot because it won't work).
I was unable to attend the event that night so I sent my wife a screenshot of the ticket. Two tickets, in fact. They were taken with zero issue.
That's a good incentive for companies to keep up with the "high-tech experience".
No they are not. The big difference is that wizards and shamans closely guarded their secrets to keep their position secure, while software developers will happily give them away to as many people as possible.
This means that software developers as such have close to zero leverage.
I saw the New York Red Bulls play not long ago and had to use Ticketmaster's system for the first time. I travel with a tablet, not a smartphone, and I was expecting trouble. Turns out the only trouble I had was that they didn't want to let me in with a tablet but they did when I explained my ticket was on my tablet. It did require an internet connection but Red Bull Arena has great WiFi so that was no problem.
Bet your bottom dollar it’s good for 24h and they added 4h of buffer in their API guidance to handle admissions after the start of the show “for free.”
Not that this really gets you anything, just made me chuckle.
So he reversed engineered it, but its still secure: You need the token.
But if each ticket is for a particular seat, would ticketmaster notice if too people came with tickets for the same seat? I bet not. I bet they just trust their ticketing system to be foolproof. If anything they might just reject the second ticket without any way to know which was authentic.
Scalpers are the problem that you have to accept. At the time of purchase, there's no way to tell the difference between a legit purchaser and a scalper or even someone who bought it and simply can't go and needs to resell.
IDs, ticket limiters, CCs, etc, etc. All methods can be circumvented by someone dedicated enough. You can only make it "not scalable" but the tickets still need to be transferable, securely.
Unless we're willing to go ID checking at the gate, there's not going to be a true solution.
The "true solution" is to sell tickets at their actual market price instead of pretending that the face value of concert tickets isn't increasing due to a larger population and greater demand.
That is *a* solution but it isn't *the* solution. The fact that many smart people are not choosing that solution is an indicator that there are some factors to the problem that you aren't considering.
The "real" solution here would be for Ticketmaster (or whoever) to actually make a ticket non-transferrable somehow, and then allow for tickets to be transferred directly through the original website for at most the original ticket price, and refund me the money.
For example, if I have a $200 ticket and I can't make it and want to sell it, I can post up a link to the original ticket seller's website (in this case Ticketmaster) where someone else can go buy it, and, if they do, I get a refund of the amount they paid. I can say how much I'm willing to accept (full price, $150, whatever) and someone can go buy "my" ticket, potentially at a loss if I'm willing to accept it. Ticketmaster can make money on these tickets by charging a non-refundable processing fee or whatever to everyone (the original buyer and any subsequent re-buyers). They make a tidy profit, everyone gets what they want.
The only complications are
1. making the tickets non-transferrable but also work offline is a difficult technology problem 2. Ticketmaster is an unregulated monopoly and thus has no incentive to behave in the best interests of the market or its customers when they could rake in millions more by screwing everyone except the scalpers
Not if they index the resales on their website and make them searchable.
People could still perform arbitrage by snapping up any resales significantly under the original price and reselling them at the original price, but at that point they're not making that much money and people are paying less than the original price, so the impact is just that you can't get a discounted resale. Which still sucks, but it sucks a lot less.
A bit of a nit pick, but this isn't "free money" unless you have a guarantee that someone will actually buy at the higher price. You could buy low, be unable to sell, and end up eating the "buy low" cost.
> sell tickets at their actual market price
How do you know what their actual market price is? You have to open it up to a market, where supply/demand get to play out.
IIRC some ticketing company tried doing something to this effect by scaling prices in realtime based on how many people were also trying to buy. I believe it was widely criticized as unfair/exploitive.
So you're back to square one then, where you have to set some price.
To be honest, it seems overall a better solution.
There are finite tickets but unbounded demand. A lottery means you can slightly adjust the distribution of poor vs rich, but in practice today it still advantages those comfortable enough to sit around refreshing their computers at the right moment, instead of working. And lots of opportunists will snap up those tickets you are hoping poor people will get, to sell them to the wealthy.
In my opinion for in-demand shows it should just be a Dutch auction (all of the highest 10,000 bids win, awarded at some fixed cutoff date before the event). If not enough bids are received, the concert isn’t sold out, so then the rest go on sale for the lowest bid.
A better idea is an airline-style dynamic pricing system that considers different variables, current demand, projected demand, type of seat etc. If it looks like the show is about to begin and there are still lots of tickets left unsold, be like Ryanair and sell them at a massive discount. If there are more people on your page than there are seats available, make the price go up until that changes.
Fiddling with the prices does absolutely nothing to fix that problem, because it isn’t a problem with price, but a problem with developing an unduplicatable token.
Ticketmaster is evil, and most resellers are fine, but some are evil and that’s a problem this at least attempts to solve.
The problem is maintaining a mutually-beneficial but economically suboptimal equilibria.
"evil scalpers are exploiting this poor artist by charging outrageous prices and preventing many fans from going" is a far better look than "evil artist is exploiting their poor fans by charging outrageous prices and preventing many fans from going."
To prevent scalping, you'd need a massive price increase, and very few artists are willing to be the first to do this.
I think this is a fascinating feature, a lot of artists would be more than happy to make $X for a show so that their fans can come see them. The problem ends up that a free market has no mechanism for that, the artist can sell the tickets such that they end up with $X but then you get things like scalpers who don't want to see the show but do want money and act like artificial demand. They know that regardless of what the seller wants there are buyers that will pay $X+N and want to capture that $N.
The scalper provides no value to the market, but they get $N, which seems like a market failure to me. The fans lose $N, the artist still only gets $X and they also get reputation damage because fans are upset that things cost $X+N.
And that's just the end of it. The artist literally can not perform for their fans at a venue for $X even if that's what they want, there's just no mechanism in the free market to make that function correctly. I find market failures like this fascinating because it really shows the limits of how "free" markets operate. The only person that isn't free to do what they'd like is the producer of the good being sold, they literally can't sell it for less than the market will bear.
And I suppose this plays out for every part of the market, if I can produce apples and make a profit for $1 a bushel and that's plenty of money for me, I don't want any more, tough shit. Arbitrage will make sure that people pay more for those apples. If people are willing to pay $5 a bushel then someone will snap up my cheap apples, mark them up and make a bunch of money for doing nothing. Even if I were willing to do all the distribution myself, if the person conducting arbitrage adds no value to the system (the common argument being that they deserve the money for finding cheap apples and connecting people that demand apples with a supply of apples), it just can't happen. The incentive to make that free money means everyone loses, I don't get to give people cheap apples, people don't get to enjoy cheap apples, everyone is worse off except for the person doing arbitrage.
The scalper allows the devoted fan who is gladly willing to pay $X+N to actually get a ticket rather than having to wake up at 6am and repeatedly refresh the site and probably still not get one.
I find market failures like this fascinating because it really shows the limits of how "free" markets operate.
How would central planning handle this better? There are more people who want to buy a ticket at $X than there are seats available; lots of people are going to be unhappy regardless of how they get distributed.
If we agree that scalpers are a problem, we can make it illegal to resell ticket over the original price. Enforcement is always a problem, so to help with that it could be required to have an ID matching the ticket name and resell can only be performed on official platform.
To grantee having a ticket with this system, a wealthy or connected devoted fan can have private arrangement with the artist manager or event organizer to get tickets.
This is the system we have right now. Ticketmaster is the event organizer.
Oh really? What if they are at work at 6am? So take a day off work? You just greatly increased the dollar cost of the ticket, which is exactly the thing you are trying not to do. And even if they take the day off to click at 6am they aren't guaranteed to get a ticket because of everyone else clicking at 6am. There's always a cost
You can be interested in market failures without proposing an alternative. Complex systems are fascinating and their boundaries and failure conditions are fascinating. That’s all I’m talking about.
Our economic system (arbitrage!) increases the price of the apple by $N until only one person is willing to buy that apple at $X+N.
If you make arbitrage illegal and implement a price ceiling at $X, one of two things will happen. If $N is greater than the cost of breaking the rules, people will start a black market to sell at $X+N (like in many communist countries). As mentioned in the article, this is already occurring with Ticketmaster because they take such a large tax on tickets; arbitrageurs are realizing they can avoid Ticketmaster's system by just sending around PDFs.
If $N is less than the cost of breaking the rules (Ticketmaster benefits from $N>$X), there will be shortages of seats because not everyone willing to pay $X for a seat can get one.
The market system works great when people who derive the most value from tickets are the ones who pay the most money. This works even better with arbitrage because people can just pay what they value the ticket at.
The market failure here is caused by wealth inequality, because there are people with unfathomable amounts of money who will pay tens of thousands of dollars to see a musician they sort of like.
Personally, I like how box seats deal with the problem. They have a high level of luxury that costs little to implement compared to price + is very scalable (you can stack boxes directly on top of each other and you're paying more to sit farther away!), and that's helping soak up a lot of demand.
Sorry I saw your comment after I wrote this reply to someone else, I’d be interested to hear your take on this hypothetical situation too if you don’t mind. https://news.ycombinator.com/item?id=40911779
I agree with you though about the idea that the market works well when those that receive the most value spend the most money. While we have very high rates of wealth inequality, which also seems to be something of an emergent property of this system, once you have even medium amounts of inequality the system becomes interesting. I think expanding on your thoughts it comes down to the relative value of money being different for different people. If I have $100 then $10 is a LOT of money, it’s 10% of all my money. If I have $1000 then $10 is probably not a lot of money to me, not trivial but it’s only 1%.
Now this is an order of magnitude but if you asked someone if a system where the wealthy had 10x as much money as the poor they’d probably say that the inequality wasn’t so bad. But even in that case the guy with $1000 would probably be willing to spend $11 on some good that the other guy wants maybe infinitely more, just because that guy can’t really afford it.
It’s a fascinating way of looking at things I hadn’t quite ever thought about in terms of relative value of money itself. I don’t have any real point I’m making here, just thanks for contributing I found your reply interesting and it made me think.
I want to sell those apples for $1 each. There’s plenty of apples to satisfy the demand. But let’s say that the market would bear a higher price, people would love to buy apples for $1 but due to a love of apples would be willing to pay up to $5.
In that scenario, the arbitrage opportunity still exists. Apple scalpers knowing that people would be willing to pay up to $5 would want to buy up lots of cheap apples and make the $4 profit that I’m leaving on the table for themselves.
And there’s just nothing we can do about it. I think we’d say that when the equilibrium price of $5 is met that the market is efficient but it’s a market where the producer of the good can fully satisfy the demand of the market for $X and yet the consumers have to pay $5X and this arbitragers get $4X.
It’s just interesting is all.
Several European countries ban reselling tickets for more than the original cost.
Scammers - yes; but how scalpers? Does this mean there is no way to resell or give the ticket to another person?
Edit: The answer was couple of sentences later; looks like yes, unless via an official marketplace. I like this even less than scalpers.
"SafeTix makes it harder for people to resell tickets outside of TicketMaster’s closed, high-margin ticket-resale marketplace, where they make a boatload of money by buying low and selling high to customers with no alternative."
Very minor nitpick: I don't like the term "technologically disadvantaged" here. While it is undoubtedly true that there are many people who are without smart phones due to economic reasons, or because their battery died or their phone was just stolen ... there are also lots of people, myself included, who would CHOOSE to forgo a smart phone when attending a concert / event.
My wife and I live in a city with a Caesar's hotel and casino within walking distance. When there are shows and concerts we are interested in, we don't hesitate to buy tickets. When we go to such a show for a date night, we would like to leave our phones at home. Some of this might be due to our being middle aged, and so we're not glued to our phones 24/7, but it's also just a hassle to bring them through security, and to often have to put them in those lock bags because they don't want people recording etc.
So to us, e-tickets are evil for no other reason than the fact that it assumes that we want to have a phone on us and to use it as a ticket. I will happily pay the fee for a physical ticket whenever available.
This is horrible. Please stop.
But then ticket resale online marketplaces aren't a thing around here either. When people resell event tickets, it's usually an entirely DIY affair.
Of course they can. All they need is a secret key embedded somewhere that the app can access but you can't. It's just a happy circumstance that they used a simple protocol in which the key is easily extracted. But they could have used a proper PKI protocol instead, which would have made it much harder, if not impossible, to hack.
I bought a ticket that someone had double sold, and by the time I got to the door, they turned me away and said the ticket had already been used. So their system has good intentions, they just need to make it work offline.
Is this still true in the age of locked-down bootloaders, secure enclaves, TPMs etc?
Side note: this is actually a great advertisement for server side rendering! If they didn't do all this client side rendering, exposing data in JSON APIs, then I doubt this reverse engineering would have been possible.
It seems like that didn't matter at the venue though? The spotty internet connection not allowing the code to load was the first part of the article wasn't it?
it's not like a ticketmaster account is 'worth' anything, so the seller can simply set up a new one for their next purchase.
Or you can transfer it to another name and print it out - just the name on Ticketmaster's system has to match some ID you have in the print scenario.
I feel like I am in a Disney movie.
What functional improvement would be had by using a 2D QR code?
My phone's default camera app can recognize QR and UPC (and certainly other things; but I have other tools that I usually use when actually-using barcodes so I'm not that familiar with this part of the camera app), but it doesn't seem willing to do anything with PDF417.
Oh, and quoting Wikipedia:
In practice, a PDF417 symbol takes about four times the area of a DataMatrix or QR Code.
Which of these aspects offers a functional improvement in this application?
("Feels janky" doesn't quite cut the mustard, I don't think.)
The "robust DRM" is called "ID cards". Here in Europe, it's become commonplace to tie soccer tickets to ID cards that are verified at the gates to keep hooligans (or those suspected of being hooligans, which is a status that is way WAY easier obtainable than one might reasonably assume) out, and high-class events that attract scalpers like a pile of dungs attracts flies have been doing that for even longer.
(Not that requiring ID doesn't raise the same and also other consumer rights issues)
The problem is that Americans are not required to have an ID -- at all. No federal law requires it, and there is none issued by default.
(This is not the same as saying "Americans don't have to carry an ID" even though that is also true.)
But none of that somehow makes this side of the pond the same as the other side of the pond.
An idea that works in one place doesn't necessarily work in the other.
I guess you could abuse that to turn partial IDs into more realistic ones? But that feels like a stretch. I can't see it being that useful for much more than confirming that an ID isn't a fake, which seems hard to abuse.
The exception is anything that is accepted by airports for international travel aka, for you Americans, only a passport - ICAO 9303 is very detailed on how you can access the data stored on them. The specs and a basic understanding on how to communicate with smartcards are decent enough to get you to a readout in maybe a weekend worth of work. The authentication is either via a code derived from the MRZ or a dedicated access code printed on the document.
Can we also please acknowledge that if people stop going to the things Ticketmaster sells tickets to, they will stop these practices? No one is forcing people to participate in these things; I don’t.
Lastly, it even calls itself Tomicketmaster. And you didn’t realize you are a Ticketslave? It is right there, in the name! Right in front of your eyes!
It always amazes me what they can get away with and people just behave like buffalo on the Serengeti, stampeding through the crock infested river … “those crocks are the worst! Ok, Karl, we are up next”
Instead of chiding your TicketMASTER devs and alpha slave MBAs, maybe stop being a TicketSLAVE altogether. Has that dawned on any buffalo?
Fun fact, to drive the point home. Guess how the predators of the Serengeti are treated when they want to go to an event. You think they deal with Ticketslavery even though the Ticketslaves is how the cabal makes its money?
There's no other mention of spyware in the article - does anyone know what this is referring to?
But yes, its disgusting that i've needed a phone for events...
How hard is that really?
Until they change their encoding.
Requiring the installation of a proprietary app to do anything should be forbidden.
Uhm, you can save the tickets to Google Wallet.
Disclaimer: This isn’t from a real SafeTix barcode. I don’t want TicketMaster to be able to identify and harass me.
Bullshit, TicketMaster. It’s a CSS animation. Get over yourself.
I think we can all agree: Fuck TicketMaster
For a billion dollar corp that is some atrociously poor security
Taylor Swift is a nice-ish person and wants her fans to think they can buy tickets for her shows at about 25 bucks because that’s a lot of money for a 12 year old and she does not want to alienate her fans.
Her manager is an evil cackling bastard and wants to get as much as he can.
He knows if he sells all the tickets for 25 bucks he will lose money in the tour and the people who resell the tickets for 2000 will make 1975 dollars profit.
So he does a deal with ticketmaster.
They will sell 100 seats at 25 bucks, then announce “wow that sold out quickly” and then pretend that the other 5000 tickets they have are sold, and then resell them on secondary sites (ie ticket master is actually selling you orignal tickets through secondary markets).
Then they give the cash to the evil manager who twirls his moustache.
All the rest, the adding extra charges at end of sales process, the ridiculous rush to buy at a given moment in time instead of some auction or lottery, the whole thing of backhanders to venues, all that is secondary to enabling Taylor swift to take a huge cut without seeming like a evil moustache twirling money grabbing manager.
[0] https://www.npr.org/transcripts/154299904
[1] https://www.vox.com/the-goods/2019/7/22/20703858/live-nation...
This is all open and documented in the upcoming prosecution by US attorney - also cannot find atm
Source: https://www.cbc.ca/news/business/ticketmaster-resellers-las-...
Scalping aside, TicketMaster is taking massive fees each time the same ticket is sold. For example, I went to an event last year and the fee was $50 on each ticket, and these were reseller tickets so TicketMaster had already taken a fee on each of those tickets at least once already (perhaps more than once).
TicketMaster also owns many venues or has exclusive deals with most large venues that prevent those venues from using any other ticket selling platform. The DOJ is currently investigating this monopoly. TicketMaster alleges it is not a monopoly since there are many smaller venues that they are not involved with.
So your evidence is that you were charged a $50 fee on a separate transaction that didn't involve TicketMaster?
This is not the compelling evidence that you think it is.
I know that you already know this, based on your other posts on this thread.
The technology referenced in the post above is, at least in part, to prevent you from reselling the ticket without involving TicketMaster. That may be justified as a way to prevent selling the same ticket more than once, but it’s certainly the case that this is one of many possible approaches, and it’s the one that most favors this business.
It would probably be criminal for the company to act any other way, so I’m not claiming any evil doing here.
Yup. I misread the comment.
I'll lay it out in detail so it's more clear: TicketMaster sold the original ticket to the scalper. Then the scalper listed the ticket on TicketMaster's secondary market. Then I bought the ticket on TicketMaster's secondary market and TicketMaster collected a $50/ticket fee from me. TicketMaster also collected a fee on each ticket the first time TicketMaster sold those tickets to the scalper.
TicketMaster also charges the scalper a fee to list the ticket, so TicketMaster actually made more than the $50/ticket fee that they collected from me.
It's also possible that the ticket was sold on TicketMaster's secondary market several times before I bought it on TicketMaster's secondary market, which would allow TicketMaster to collect many fees on the same ticket.
There are plenty of scalpers who sell tickets outside of TicketMaster, despite their best efforts. Do you think the $50/ticket fee that you paid would have been lower if you'd done your transaction outside of TicketMaster's platform?
I'm slightly less concerned with the actual amount of the fee and more concerned with the fact that ticket scalping has apparently become legal and that the original ticket seller is not only in on it, but getting even higher fees on the scalped tickets than the original tickets.
It's disturbing that it's illegal to scalp a single ticket in person outside an event, but if someone does it online with hundreds of tickets then they're a "ticket broker" and that's legal (in California at least).
Legal space around ticketing is... insane. The laws protecting "ticker brokers" are cloaked as consumer friendly regulations, and ironically TicketMaster actively lobbies against online "ticket brokers".
> I have purchased secondary tickets outside of TicketMaster many times and the fee has always been lower. But, that's anecdotal of course... there's no reason why they couldn't be higher.
In general, TM's share of resell is much smaller, and the resell market is heavily fee sensitive, as the brokers like to keep as much of the money as they can, so the fees tend to be set by the market (and they didn't go up when TM got in to the business).
> Conspiracy
> a secret plan by a group to do something unlawful or harmful.
It could be true but Ticketmaster is explainable by the purely mundane evil of a monopoly. I could be convinced but I too would want evidence.
Of course, their insane monopoly means they also get to take advantage of smaller artists, venues etc. None of this is good.
It's, in effect, a shell operating as a scalper and a customer service disruptor. This has very little to do with the artist beyond selecting venues.
Fundamentally, if there's someone out there willing to pay up to $x for a space-limited event, they will find someone to give that $x to. I'd rather that person be the artist.
And because of Taylor Swift there is now a DOJ investigation of ticketmaster. Taylor Swift is not on the side of ticketmaster like you are conspiracizing.
Face value on tickets for her last tour started at 75.
All that money went to Taylor. ALL OF IT.
How do you pay for support staff, trucking how do you pay to move t-shrits from one venue to the next.
This is where all those fees come in... It's not the manager grabbing the money (that bit is later), it's the promoter covering the cost of the tour. Paying for staff to haul and set up a stage at every venue, paying for band members, dancers, people to run lights...
The Management (and the artist) will then "hold back" tickets. Most of the best seats are sold one of two ways. Fan club packages, where you pay 3000 bucks to meet the artist, get a photo and get a good seat. - OR - they go directly to the secondary market. This used to be scalpers (who "worked" for management) but now is secondary sales sites.
There are still two more bits: Consessions. Most artist get a pretty hefty kick back after covering venue staffing. These contracts can be weird, but artists, managers and promoters LIKE Ticketmaster being a one stop shop. It lets them negotiate a single deal (and one that is better for the artist) for the whole tour. Then there is merch, this is a gold mine for the artst and management too. Again there is a staffing component but that is covered by the concessions (mostly).
IN a lot of cases a venue will not sell out, and that is FINE. What happens is that the "fans" ran to the front of the line and paid too much for tickets, bought on the secondary market to get good seats. IN many cases there was so much money made at this stage that the monetary value of the rest of the tickets drops to zero....
At that point no one wants an half empty venue... So it gets papered over. They give away tons of free tickets, they "leak" a late box office hold being released... but it's now a fire sale. The nose bleed seats are selling for 5-10 bucks (even in today's market). Because assess in seats sells beer, t-shirts, and a full venue makes it an "experience"
This is the model that Bill Graham built and the vision of the industry he was going towards. TM is still, at its core, Bill Graham Presents.
I used to work in the industry, it's a hot mess and every one is greedy.
This is one of the most powerful truths underlying the world we currently inhabit. The sooner we can agree to behave accordingly, the better our prospects for ripping the reigns of society from the hands of those whose only animating principles are avarice and exploitation.
I agree power and greed go hand in hand - absolute power corrupts, absolutely - but this bit? This is new.
https://web.archive.org/web/20200915000000*/https://try.newr... [pdf]
In fact, society would likely be better off if e brought back more public shaming
Also, my impression is that there is already copious amounts of public shaming. Some social media sites seem largely devoted to that. And unfortunately, I don't think most people fully deserve the verdict that they get in the court of public opinion.
My outrage is directed entirely at the government agencies whose job it was to stop this, not the developers making a ticketing app.
There's a lot of blame to be spread around though. The developers themselves, their management chain all the way up to the decision makers, shareholders that demand ever increasing profits, governments who provide the legal framework and allow these huge, destructive companies. Everyone should get their share of the blame.
Developed countries long ago came to the conclusion that companies should not be allowed to have monopolies because it is bad for society as a whole, and it's hard to think of a current monopoly as egregious as this one. There is absolutely no reason one company should have exclusive rights to 85% of large venues, also be an evebt promoter, and also be the ticket seller.
Anything their developers do is not the real issue, a society that allows this to happen in the first place is.
Right? Wrong? Discuss.
I don't see the issue. Every social media site does this, FB was just naive enough to share their research
Now to bring this to a close, people like you, who will jump companies for 20_000 and have lost the ability to see a clear ethical violation will be holding the guns and guarding the gas chambers when the next Hitler comes along. Meditate on this.
Also this XKCD is dumb. Previously the feed was chronological post of friends which was definitely more ethical. But of course that didn't make people addicted enough.
I’m all for moral relativism, but there’s no future in which Facebook’s current actions aren’t at least reasonably debatable, and no past in which Auschwitz was.
If you wanted an example of where the line gets blurry (it does sometimes, just not in either of these) I’d go with pharmaceuticals.
People are illogical.
They seem very different to me and anymore, I almost think that’s a valid test of the reasonable person standard.
???
I said I don't find A/B tests unethical. Literally every tech company runs A/B tests just like that one. Why would I ask for 20k more?
> Previously the feed was chronological post of friends
Yeah, before they measured the impact of a good recommendation algorithm.
The APA put out a press release about this study violated their code of ethics.
https://www.apa.org/news/press/releases/2014/06/informed-con...
Yes, but I think they still have some responsibility, even if they say "I was just following orders!" [1]
It's like there's no way to make the software human and humans in the loop have a crutch to lean on to not behave as a human. When I contacted the dev team directly, they shrugged too. No refund.
To me it feels like software is the place where society can just exercise its cruelty and indifference, or maybe it is a reflection of society, it's probably just like humans are. What we think software should behave like is not human.
I had more pleasant experiences with London/UK train ticket edge cases and felt like the system is built to deal with user/server errors.
Now living in NZ I get tons of slack for something like “verify youre local for free museum entry” or “get your passport by post”. Life is so much easier when societal trust is high.
I see a worthwhile product as a stool with at least three legs: Technical feasibility, business viability, and ethical acceptability. Take one leg away and the stool should fail. Yet, HN commenters endlessly discuss/debate the first two and largely ignore the third. I think we all have a duty to work on projects that are ethically sound (defining that is a whole other discussion). There are plenty of companies out there and plenty of products to work on--it's not like we have to pick an evil one in order to survive and "feed our families."
I'll accept a share of developer blame in places with strong unions and the ability for workers to strike.
The market isn’t what it once was and while overall still good, we do all have bills to pay.
Take away their exclusive rights (on both sides of the business) to 80+% of large live music venues and they’re just another ticket platform.
I believe that professions should have codes of ethics, and people should be expected to adhere to those codes of ethics. Right now there is no licensing or apprenticeship or registration associated with the profession of "software developer". There are some organizations that issue professional certifications in adjacent areas (MCSE, CISSP, etc.) that have codes of ethics associated with them, but I rarely see disciplinary action associated with them, and in any case employability is not linked to these certifications.
Conversely, lawyers have bar associations that evaluate complaints and can withdraw permission to practice.
Doctors have the Hippocratic Oath, but I'm not sure that it's enforced for medical licensure. However doctors do have medical licensing boards and licenses can be revoked.
Pilots have revocable licenses but I'm not sure they have a code of ethics.
Civil engineers have codes of ethics and licensure, but licensure revocation appears associated with legal malpractice, not ethical malpractice.
In any case, there are societal mechanisms that could be used to associate codes of ethics with software developers, if we as a profession and a society chose to, which I'm not optimistic will happen.
Shamans and wizards (never heard this used to describe anyone in history but let’s assume it’s just any kind of supposed magic user) were people at the top tier of their societies in terms of political power. Not kings or chieftains, but above everyone else.
Programmers are just making a living selling their labor power like every other office drone in the world. We’re one of the most common lines of work out there.
If you want the mysticism angle, we are like those kids they used to catch “witches”.
But generally speaking Druids had an oral tradition of maintaining knowledge in Celtic society. They had inter-tribe gatherings and went through long and difficult training.
Specifically also law. So they had at least the power of judges and to some degree law makers.
Perhaps you can find out more with some of these keywords.
I don't know where you came by such a notion; Shamans, "Wizards", witches, "wise women/men", are usually shunned from society such that they tend to live near the outskirts of towns or cities, nobody really wants to live close to them; and when "bad things happen" tend to be the first ones to get blamed for it; then they also are commonly used as scapegoats for whatever political, economic or religious effort some corrupt officials try to push.
That doesn't sound very societal top-tier to me.
We're definitely not witches or wizards, at most we are scholars or [specialized] craftsmen. "Knowledge workers" if you will. Not as unlikable as the wise folk that live towards the edge of town, and not as at risk of getting tied to a post and lit on fire because the bishop believes we commune with unclean spirits.
We're on our way to get there, though, with that "can't solve social problems with technology" infectious meme, and the other one that makes the public blame programmers for socially-problematic tech, while ignoring or praising the business people who imagined, commissioned, and decided to deploy those technologies.
t. Introduction of SICP
The suits at TM couldn't build the app+backend, even if they could hire someone to maintain and replace parts of it.
With age comes wisdom.
There has been a lot of good that came from making coding more accessible; I'm not trying to gatekeep. But I do think that this is one instance where the outcome is worse. The martial arts masters still unquestionably exist among us. It's just that they're now surrounded by younger, less-wise people with guns. Both types can fight an army, but only one has the wisdom to know when it's better not to.
You can be a shitty wizard with only one year of training, same goes for programmers.
That might be true 3 or 4 years ago, but I find that difficult to believe in the current job market. All the programming jobs that have come across my screen lately require a 4-year CS degree. Companies aren't hiring noobs lately. They're laying off more than hiring.
People don't code out of a sense of duty, they do so to earn money, so there is no mechanism to enforce "behavior."
> our prospects for ripping the reigns of society
There are too many industries that take the mantle of improving society on their back. This is a mistake. There is no natural representative mechanism that ensures your actions are aligned to required outcomes.
This should probably be left to congress. If you're concerned that they won't do it then that should immediately suggest the appropriate course of action to you.
> of those whose only animating principles are avarice and exploitation.
Short term thinking cannot lead to long term rewards without abject manipulation of the marketplace.
If software engineers united behind true ideals of freedom, we could automate the entire stack of "leadership" and raise the floor of society.
Open source implementations of:
Universal cryptographic identification
Decentralized voluntary anonymous voting, verifiable by every voter
Sovereign algorithmic monetary policy
Liquid representation
Complete digitization of all necessary information to audit any authorities, at any time
Full release of privacy for any "public official" -- service to society should be a burden, not a privilege
This, and much, much more can ALL be done with software. An entirely new paradigm of society, with freedom unalienably encoded into the fabric of the social machine.
Our rights digitized, our privacy, speech, and pursuit of happiness made into software.
I would say software may have an impact, and the thinking of this impact extends far beyond the next quarter of profits. This mindset can extend into a multi-planetary society and beyond. A continuously evolving, open source mechanism of human governance.
You'd have better luck trying to remove jealousy from the human heart. If you can suggest a mechanism for actually making this happen, enforcing it in the face of economic incentives, and measuring it's actual impact then I'll take the ride with you. Until then it is an absolute fools errand.
> we could automate the entire stack of "leadership" and raise the floor of society.
Autonomous societies have been tried before. They have no mechanism to correctly align their long term objectives so none of them have ever lasted. Planning to build another one based on nothing other than assumption is flawed.
> with freedom unalienably encoded into the fabric of the social machine.
Guns exist. The social machine is secondary to force. You have no plan for this.
> This mindset can extend into a multi-planetary society and beyond.
Older people sell younger people pure unadulterated fantasies in order to extract cheap labor from them.
:)
It's worth remembering that folks who can be bought, can be bought off and spend a lot of time enjoying their riches while true believers are somewhat more difficult to convince and don't take any time off.
That's important because all of the big evils have been perpetrated by true believers in pursuit of their "one true way." (Yes, some large evils have been perpetrated by folks chasing money. I'm talking about things like wholesale slaughter of as many people as they could lay their hands on.)
I sincerely hope all tech companies can take a page from old Google and truly instill an innate rejection of evil among all software engineers.
You want truth?
The Golden Rule: "He who has the gold, makes the rules."
Truth is that money is all that matters. Nothing else in the world of business matters not relationships, not customers, not Boards of Directors or CEOs. Money.
Until a person realizes this, they will be forever caught in a cycle of thought that is not truth.
"Follow the money!" is the best way to see how society works, and is why every government wants their hands in our money. Meaningful change in this world requires money. No amount of idealism or 'using our powers' can change that.
Do the wizards have 'F-Off' money? No. Will they ever? No.
I go to 1-2 concerts a month so I'm well aware of how scummy TM is, but the problem with PDF tickets is that people sell fakes or sell the same ticket multiple times. I know multiple people who've been scammed this way. I get not wanting to use your phone for everything, but the changing barcode isn't just technology for the sake of technology, it's actually there to solve a problem.
> PDF tickets work even if your phone loses internet connection
So do the digital barcodes if you add them to your phones wallet.
TM even sends you an email before every event that says:
>> If you haven't already, download the Ticketmaster app or sign into your Ticketmaster account via mobile web. From My Events, tap view then add tickets to your phone's wallet for easy access at entry.
TM's help page for the Mobile Entry tickets also says (https://help.ticketmaster.com/hc/en-us/articles/978659778561...)
>> We encourage you to download your tickets to your digital wallet before you leave for your event. This ensures that you can always access your tickets.
> If you bought the ticket off the event’s official ticketing agency (not a sketchy reseller), you know for sure that they’re real.
The problem is that that isn't how the real world works. Ignoring the massive scalping problem currently happening (that TM is complicit in) sometimes plans change or people learn about events after the initial sale. Personally, any time I have to buy or sell through a reseller, I use StubHub, but I know plenty of people who don't want to use them as they charge high fees and they aren't much better than TM from a moral stand point.
Also, I get the impression that if TM locked all tickets so that they could only be resold on TM, the author of this article would have a problem with that.
I found the article really interesting from a tech perspective.
And I have no love for TicketMaster, but the migration from paper/PDF tickets to scannable changing QR codes is inevitable, precisely to combat scammers.
TicketMaster does a lot of bad things, but this doesn't seem to be one of them. And learning to download the digital tickets in advance -- either to the app or your Apple wallet -- is just a thing you learn to do, the same way you learn to download a bunch of podcasts before your airline flight that charges for (or doesn't have) WiFi. (And if your ticket was a PDF, you'd similarly be stuck if you couldn't get internet at the venue and hadn't downloaded it in advance.)
??? Last I heard the adding the barcode to the phone's wallet did not work, or at least not reliably. Some older folks I know struggled with it, and I specifically help setup the ticket master app and download the barcode. They mentioned that the app eventually logged them off when they got on site and had to struggle with poor wifi. Eventually got it to work but IIRC it took several minutes before they had a stable enough connection for it.
Does it need an actually Google/Apple wallet or something setup?
Stuff I add there works for me instantly every time, even with crowded venues and zero connectivity -- as long as I get it ready in advance.
(Not that I am defending this. I'd rather carry a paper ticket, since paper is more durable and far less complex than a phone is.)
Up to $1M per week.
Additionally, what is irresponsible here? Its not like this gives you the capability to clone tickets without first having a ticket in the first place.
I would consider it unethical to publish details of an unpatched vulnerability that allowed ticket forgery, but I don’t think it’s unethical to bypass DRM-like controls for personal convenience rather than commercial purposes.
Of course opinions may differ on this.
The only thing it allows you to do is sell your ticket, which is legal to do.
Might just be the musicians I like, or the fact that negativity is better for clicks, but I've never seen an artist saying they get any benefit from ticketmaster's fees and other such shenanigans; I've only seen artists and venues saying that they don't get any money or benefits at all from ticketmaster's racketeering.
> ticket fees (which can include a service fee, order processing fee, and the occasional delivery fee) are determined by and shared between the parties who have a hand in making live events happen including venues, Ticketmaster, sports teams, leagues and promoters
When the artist doesn't want their fans to be charged big fees - they have some say in it. Robert Smith of The Cure made a stand on this last year and got Ticketmaster to refund a bunch of money.
That's a very carefully crafted sentence. How much, exactly, do artists have a say? Do artists equally have the same amount of "say"?
And why are we even discussing all these nonsense in the first place?
That seems like a pretty substantial claim to make without any sort of "in [country/state/province/etc.]" qualification, let alone a reference.