4 ms·
I believe I may accidentally be one of these "hackers." For those of you who don't know how the line worked, TicketFly sent registered users a link to a page t
by fWnApHU2PY6CPA 12y ago
I believe I may accidentally be one of these "hackers."
For those of you who don't know how the line worked, TicketFly sent registered users a link to a page that would allow them to purchase tickets at 12:00pm PST. Like most people, I clicked the link just before noon and ended up in a waiting room with a countdown clock and a note explaining that a continue button would appear at exactly 12:00.
My coworkers and I were curious if the button was simply hidden from view using JavaScript, so we did what any hackers (in the Hacker News sense) would do – we viewed the page's source. There it was! In the middle of the page sat a small javascript function with a link to reveal the button. Curious again, we clicked it. I believe the waiting room page just refreshed at that point, and we though nothing of it. A few minutes later, the queue began, and after sitting in it for about 40 seconds, I was shown the purchasing screen. I assumed I got lucky and left happy.
When I read this blog post on Saturday evening, I realized what had happened and freaked out a bit. It appears that clicking that link placed us at the top of the queue, even though we couldn't actually start the purchasing process until noon. Because of this, I am probably going to lose my tickets. Yet the fact that we could cut in line never even occurred to us, because we assumed that any queuing logic would have happened on the server side to prevent exactly this kind of exploit.
I feel bad for the users that I apparently cut in front of. I feel equally crappy, though, because I'm certain that other "hackers" are in similar situations to me. From what I've read in subsequent reports, using NoScript or otherwise browsing with Javascript disabled would have revealed the button before noon. That means that those people, too, will be labeled as hackers and have their tickets revoked. I'm relatively certain that even having a system clock running a few minutes early would mark you as a line cutter.
Not sure what to do next. I suppose all I can do is wait. This sucks.
- lawlessone 12y agoThats not accidental.
- fWnApHU2PY6CPA 12y agoWe had no desire to gain any advantage in the line or 'game the system' in any way. We were simply curious how the line worked.
- toomuchtodo 12y ago> We were simply curious how the line worked. I don't mean to be rude, but curiosity would've been viewing the source. Dropping into the queue early is when it got shady. Apologies if you lose your tickets, but it seems the fair way to handle the situation.
- kordless 12y ago> Dropping into the queue early is when it got shady My suggestion? Don't put your queue in my computer.
- toomuchtodo 12y agoIt doesn't matter if their technical solution wasn't perfect. It was good enough, and those who bypassed it (whatever their motives) showed up in the logs. Seems like it worked just fine. That's the problem with the HN bubble. We seem to think everyone should come up with the perfect solution, when good enough carries the day.
- fWnApHU2PY6CPA 12y agoTaking myself out of the equation then, since I understand that my actions may be construed as a gray area. If it turns out to be true that users with incorrectly set system clocks and users with javascript disabled accidentally cut the line, are they hackers? Should they have their tickets revoked?
- toomuchtodo 12y agoAs someone who has been in your shoes, I'm saying you're very much not a "hacker". You found a front-end weakness, exploited it, but the repercussions (if any) should be minor (ie tickets being kicked into the next sale for those who jumped the line). In the grand scheme of things, this is as minor of an issue as it comes.
- dpark 12y ago
- frogpelt 12y agoIt's also not hacking. Viewing page source and navigating to a URL which is clearly visible is not subversive in any way.
- toomuchtodo 12y agoBurning Man and TicketFly disagree, hence why they're revoking tickets.
- Shivetya 12y agoBy whose definition? So if a site has elements on a page they do not want to be immediately seen their only choice is to not distribute the content? So if your circumventing a script that is not the same as circumventing a program? I look at this way, if it does not occur to the common user to do so then it is "hacking". Not in any nefarious/sinister sense but the term still should apply.
- edwintorok 12y agoIf it is true that people visiting with Noscript or javascript disabled would see the button immediately then it is a design flaw of the ticketing system, not hacking. At least they should've used javascript to generate the link and show it as opposed to hiding it on page load.
- fWnApHU2PY6CPA 12y agoFull disclosure, I don't mean to present the Noscript/Disabled Javascript comment as fact – I read that here: https://www.reddit.com/r/BurningMan/comments/2wieta/did_you_cheat_the_system_with_the_hidden_link/corv4g9 https://www.reddit.com/r/BurningMan/comments/2wieta/did_you_... EDIT: Typo
- blueskin_ 12y agoNever trust the client or the data they send. Talk about a rookie mistake.
- mindslight 12y ago
- userbinator 12y agoReminds me of a few free file hosts (probably now long dead) that would do the countdown thing client-side, with the direct link to download the file right there in the source code.
- codyb 12y agoThat sucks. In my eyes that's more on Ticketfly than on you. They have an event with ~400 dollar tickets that far more people want to pay for and attend than tickets are available. They should have made sure there system wasn't exploitable in this way. Of course hindsight is always 20/20. It just doesn't seem fair that for clicking a link they served to your computer a few minutes early you'd get totally #$&$ed out of a ticket. It doesn't seem fair you got to click the link a little early by peeking at the source but that shouldn't have been doable in the first place and they literally served you the key for access.