Hackers Cut in Line at the Burning Man Ticket Sale–And Get Caught
wired.com
wired.com
For those of you who don't know how the line worked, TicketFly sent registered users a link to a page that would allow them to purchase tickets at 12:00pm PST. Like most people, I clicked the link just before noon and ended up in a waiting room with a countdown clock and a note explaining that a continue button would appear at exactly 12:00.
My coworkers and I were curious if the button was simply hidden from view using JavaScript, so we did what any hackers (in the Hacker News sense) would do – we viewed the page's source. There it was! In the middle of the page sat a small javascript function with a link to reveal the button. Curious again, we clicked it. I believe the waiting room page just refreshed at that point, and we though nothing of it. A few minutes later, the queue began, and after sitting in it for about 40 seconds, I was shown the purchasing screen. I assumed I got lucky and left happy.
When I read this blog post on Saturday evening, I realized what had happened and freaked out a bit. It appears that clicking that link placed us at the top of the queue, even though we couldn't actually start the purchasing process until noon. Because of this, I am probably going to lose my tickets. Yet the fact that we could cut in line never even occurred to us, because we assumed that any queuing logic would have happened on the server side to prevent exactly this kind of exploit.
I feel bad for the users that I apparently cut in front of. I feel equally crappy, though, because I'm certain that other "hackers" are in similar situations to me. From what I've read in subsequent reports, using NoScript or otherwise browsing with Javascript disabled would have revealed the button before noon. That means that those people, too, will be labeled as hackers and have their tickets revoked. I'm relatively certain that even having a system clock running a few minutes early would mark you as a line cutter.
Not sure what to do next. I suppose all I can do is wait. This sucks.
I don't mean to be rude, but curiosity would've been viewing the source. Dropping into the queue early is when it got shady. Apologies if you lose your tickets, but it seems the fair way to handle the situation.
My suggestion? Don't put your queue in my computer.
That's the problem with the HN bubble. We seem to think everyone should come up with the perfect solution, when good enough carries the day.
In the grand scheme of things, this is as minor of an issue as it comes.
Obviously not.
Viewing page source and navigating to a URL which is clearly visible is not subversive in any way.
I look at this way, if it does not occur to the common user to do so then it is "hacking". Not in any nefarious/sinister sense but the term still should apply.
https://www.reddit.com/r/BurningMan/comments/2wieta/did_you_...
EDIT: Typo
This is the path to madness (and it's the one the "justice" system is on). Adblock? Hacking. Network connection blipped? Hacking. Using a new browser that better protects your privacy? Hacking. Changing number in URL? Hacking. Using a VPN? Hacking. Leaving page open for months in a forgotten tab? Hacking. Running any program that isn't a web browser? Hacking.
If our society is to have a digital future, the only sane definition is congruent to ownership and control - your computer functions wholly as your agent, and their server functions as theirs. Servers must be properly configured to enforce the desired business rules, and not doing so means different business rules are in effect.
Would you run a race where every runner gets to choose when to begin?
Because that's what this is: A race without a central time authority. A race where each racer begins when his personal clock strikes "go".
Spirit of competition requires a fair playing field as a foundation, so there was no spirit of competition possible.
(NoScript also isn't against the 'spirit of competition'. If you want to ban a faster less-friction-causing swim suit, you have to ban it. You can't retroactively define the rules of competing!)
(Edit: Also, inventing rules of competition that aren't official rules to limit yourself to what you may consider 'honor' is called scrub logic. Play the game-- not your game, but rather the game as it exists with rules that are defined. If the rules aren't good enough, it's not the players fault).
Of course hindsight is always 20/20. It just doesn't seem fair that for clicking a link they served to your computer a few minutes early you'd get totally #$&$ed out of a ticket.
It doesn't seem fair you got to click the link a little early by peeking at the source but that shouldn't have been doable in the first place and they literally served you the key for access.
Um, Larry and Sergey have been going to Burning Man since at least 1998:
http://www.theatlantic.com/technology/archive/2013/09/the-fi...
I wonder what kinds of goodies all these front end frameworks will lead to, when they eventually fall into the hands of people who don't understand that the final arbiter of some things must be on the back end.
Because someone only has a superficial understanding of how things work.
The system is very simple: you open up the ticket purchase page a few minutes before registration opens. The page reloads at randomish 30-second intervals. Once registration opens, the backend sets a queue number linked to a unique ID, and sets a cookie in your browser with that ID. You wait for the page to finally reload and say "it's your turn to purchase tickets!" And so, through a delayed system of individual registrations, everyone gets their ticket if they showed up at the appropriate time.
The 'queue' is a server-side aspect of this system, and it all happens on servers that have their clocks synchronized. Before accepting anyone into the queue, the server software needs to check if it's 12:00 yet (or whatever time registration opens).
Their software did not check the time before populating the queue. Bottom line: this was a bug in TicketFly's software, not "hacking".
That's an order of magnitude difference.
I've worked on websites that return hundreds of thousands of dynamic content pages per second, and you don't even need to do that here: all you need is a landing page that sets cookies, and then you can take all day to actually allow people to purchase with the reservation number they've got.
The bug has nothing to do with any of that, though...
If you want to do something fun in the wilderness with your friends, you don't need anyone's permission for that.
> you don't need anyone's permission for that.
Except in this case the Bureau of Land Management's (BLM) permission. I spent a lot of time in Las Vegas and for the most part you just drove out into BLM land and it was fine. But if you have a group greater than a certain size it requires permits. The tickets process is a way for them to not exceed their permit limit of 50,000 people. Doing so would get them banned from getting permitted in the future.That said, I'm rather surprised at this point that some tech billionaire hasn't bought a couple of thousand of acres of desert[1] and allowed it to be run there. But at some point the 'exclusivity' becomes its own value.
[1] Land ownership debates not withstanding.
Can anyone explain to me how they could go about determining who skipped the line and who didn't? I'm curious.
Perhaps my thinking is naive here, but tickets seem to run counter to one of the main principles of Burning Man which is "Radical Self Reliance". If I'm paying you for a ticket then I must be relying on someone for security.
They publish a great breakdown of where the money goes here: http://burningman.org/event/preparation/ticket-money/