-
Notifications
You must be signed in to change notification settings - Fork 3
Description
Issue
The Internet-facing database for validating QR tickets should be able to distinguish once a QR code has been scanned at an event to prevent reuse abuse.
User Story
I go the event ticketing website and download my QR code. I have a friend who wants to go to the event and so I send them a copy of the QR code.
Discussion
This one is a tricky issue, IMO.
On the one hand it might be simple enough to say that the QR is a one-time use.
However, this probably wouldn't really work well, since there are a lot of events that have a reentry practice.
- At a movie theater I can come and go just showing my ticket.
- At a theme park I can leave the park and then return later showing the same ticket.
- At a conference I might leave and return.
- etc...
So, what mechanism can ensure that a QR code is reasonably only permitting one entry at a time, while respecting and permitting re-entrance policies?
I suppose that this one might need a little more of a process mapping done to imagine where controls could be implemented.
I'll also spend a little time thinking about this, if desired.