Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> for some reason, passes are cryptographically signed, and they have to be signed with a key known to one of Apple’s certificate authorities. Cryptographically signing these files makes some sense when you consider that passes were designed to get automatic updates from their vendors; for example, your boarding pass for a flight reflecting gate changes or changing your seat assignment.

How does this make sense? There’s a perfectly well supported system for doing this: HTTPS.

Maybe Apple wants passes to be verifiable by the phone offline instead of just when updated? This still seems silly — a malicious actor could replace a pass instead of updating it.



Having the initial pass specify the public key that it accepts for updates would be sufficient. Having an association with an Apple developer account doesn't help for the updates problem at all AFAICT.

The only reason I came up with for the blessed-by-Apple requirement I came up with is selling fake tickets. There is no way to tell (with or without that requirement) whether a pkpass file with a "ticket to concert X" is actually legit. So, one can try to combat the (potential?) problem by responding to complaints of fraud by revoking the corresponding developer's account. However, that doesn't seem like a solution either: developer account are probably way cheaper than how much you can gain on fraud before you get caught in that way.


Yeah, I also found the justifications for Apple requiring passes to be signed pretty vague. Locking things down is just the default for Apple; it's usually only in later iterations that they open up integrations to the broader ecosystem.

On the face of it, it's really weird to require passes to be signed: I can always just store a PNG or PDF showing the same bar code in my photo library or files app and present that. Imagine iOS only displaying signed PDFs!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: