How not to run a ticketing website
36 points| mydigitalself | 13 years ago | reply
The ticket vendor, ironically named CrowdSurge, are wiping their hands clean of the incident:
"Upon release of any further information from Baselogic, in particular the refund process for which they are solely responsible, we will contact you again."
The really interesting bit for me is that there were obvious problems with the ticketing system with the barcodes not being scanned correctly, I saw numerous people experiencing this.
I had 3 tickets, each sent to me via email. The ticket contains a barcode, which was scanned at the door. Allow me to present the HTML from the ticket below, in all it's secure glory:
http://crowdsurge.com/et-TicketBarcodeBig.php?code=862484 http://crowdsurge.com/et-TicketBarcodeBig.php?code=862483 http://crowdsurge.com/et-TicketBarcodeBig.php?code=862482
Now I'm not saying that CrowdSurge are solely responsible for what happened at the event, but as you can plainly see above, it's not very difficult at all to fake a ticket. Buy one, you'll have the numeric sequence, print numerous, arrive early, you're in.
Obviously the barcode image URLs need to be protected by unguessable ids with some sort of brute-force velocity checking, not just a URL that you can pass any number into and get a valid barcode in return.
The really unfortunate thing here is that CrowdSurge are a startup trying to disrupt the industry, but surely they have to get their technology a whole lot smarter than this if they want any skin in the game.
[+] [-] forgingahead|13 years ago|reply
It's bloody hard to run an event. I've done it for hundreds, and it isn't pretty. 15,000 is a lot, and if you don't have operational experience or a great ops plan, things get very bad very quickly.
So again, while the ticketing is a problem, the other issues would still be present had they used EventBrite or Ticketfly for their ticketing solution.
[+] [-] dazzawazza|13 years ago|reply
[+] [-] oraj|13 years ago|reply
http://www.crowdsurge.com/et-TicketBarcodeBig.php?code=wowth...
[+] [-] brittohalloran|13 years ago|reply
[+] [-] joshaidan|13 years ago|reply
[+] [-] brohee|13 years ago|reply
[+] [-] Pheter|13 years ago|reply
[+] [-] facorreia|13 years ago|reply
[+] [-] waldr|13 years ago|reply
[+] [-] jahewson|13 years ago|reply
[+] [-] beeepbop|13 years ago|reply
And how do you know any barcode you get from that website is a valid barcode? It's just a barcode, you can make one in Word if you have the right font..
Edit: Of course, having the ticket codes after eachother like that without any form of security check makes it a bad ticket system, but it doesn't necessarily lead to an overcrowded concert, just a lot of unhappy customers.
[+] [-] jgroome|13 years ago|reply
Another nail in the coffin for British festivals. Sad.
[+] [-] smackfu|13 years ago|reply
[+] [-] antihero|13 years ago|reply
[+] [-] stuaxo|13 years ago|reply
[+] [-] joshaidan|13 years ago|reply
If you tell them, then they'll probably come up with a solution, and in the process you would be helping a startup.
[+] [-] unknown|13 years ago|reply
[deleted]