TicketMaster's SafeTix, a system that uses rotating barcodes for mobile entry, is marketed as a security measure against fraud and scalping, but it can be easily reverse-engineered. The barcodes contain time-based one-time passwords (TOTPs) and a bearer token, which can be extracted and used to generate valid barcodes offline. Despite claims of preventing offline saving and transfer, the system's vulnerabilities allow for ticket duplication and potential resale outside of TicketMaster's platform.
Tuesday, July 9, 2024