Hacker News new | past | comments | ask | show | jobs | submit login

I feel like I often have to login again with ticketmaster and I'm never sure of they can't figure out token refresh logic or if it's some kind of anti theft measure or what.



Happens all the time:

I need the wretched app to go to a QR code-only concert. Would love to take up a stallman-esque stand against this, but the bands I love aren't getting any younger and neither am I.

Need to show my digital ticket to the steward. Only to find the app has again signed out, spend ages fumbling with my phone and password manager to sign in, while standing in the rain outside of the venue.

Not the seamless experience they promise!


Idk if you could take a screenshot of the QR code for offline use? I always do this when buying public transport tickets in Europe.


The last half-dozen concerts I've been to have some sort of live code or something where screenshots don't work. I haven't spent enough time trying to deduce if the code itself changes or if the scanner just reads animation over the code, but at least for the moment you do need the live app to get into most concerts if they're using the Ticketmaster or Live Nation apps.


It's almost certainly the code that changes.

That's easy to program and is very common in apps that produce scannable QR codes that they don't want duplicated, that will only work for the next e.g. 60 seconds.

Any animation that could reliably be picked up by a scanning camera would necessarily be quite visible to the user. Just think of how QR codes often don't even work until you increase your phone's brightness, and they're as high-contrast as you can get...


If you have refresh tokens in your first-party authentication flow you are already a good way down complexity lane - best to avoid IMO.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: