So, I had a look around for alternatives to Songkick and Bandsintown popped up. Here's my experience so far:

Firstly, Songkick doesn't have an export, and Bandsintown has import from various services that I don't use. By hacking around I mostly automated my following list (details coming in another post).

I found setting the location is worse. Songkick lets you choose locations to track, whereas BiT has location + radius, which doesn't take into account transport links.

#Songkick #BandsInTown

Nyt kun ei enää näe facen kautta ilmoituksia kiinnostavista keikoista, niin täytyy etsiä vaihtoehtoja.

'Bands in town' -sivu/sovellus löytyi jo, mutta harmittavasti sieltä puuttuu olennaisia keikkapaikkoja.

Jotain keikkasivustoja selaisin, mutta kaipaisin jotain lähdettä, josta voisi uutiskirjemäisesti tilata tiettyjen keikkapaikkojen keikkailmoituksia tai jotain. Aika työmaa käydä erikseen läpitte vähän väliä..

#keikat #musiikki #bandsintown

Received a pre-sale notification (and code) from #BandsInTown for Echo & The Bunnymen. Last time I'd looked, their show at our local venue had long been sold out. I figured, "maybe they added a second night". My wife likes them, so I clicked on the link. Nope. Same show. Also: still sold out. So, "WTF?"
Kennt jemand eine coole (am liebsten FLOSS) Alternative zu #BandsInTown? #konzertbubble

🎵 New Blog Post: Bandsintown Verification Bypass (Fixed, $200 + Swag)

Found a way to claim any unclaimed artist page on Bandsintown without verification:

  • Discovered API endpoint from requesting to join Bieber's team
  • Used same endpoint on Rick Astley (unclaimed) - bypassed all OAuth/social verification
  • Got full access to 191k followers, their emails, names, locations
  • Could send push notifications and post as any unclaimed artist (including diddy xd)

I could have rickrolled 191k people for real. I did not.

Bandsintown handled it well - fast fix, honest about bounty limitations, shipped me swag.

Also found a new bypass while writing this - currently disclosing responsibly.

Full writeup: https://bobdahacker.com/blog/bandsintown

#InfoSec #BugBounty #ResponsibleDisclosure #Bandsintown #Security #Privacy #CyberSecurity #RickAstley #APISecuity #Music

Bandsintown: How I Almost Rickrolled 191k People

How I found a verification bypass in Bandsintown that let anyone claim unclaimed artist pages with a single API call - including Rick Astley's 191k followers, their emails, and the ability to send push notifications as any artist.

#BandsInTown, #SongKick, #Spotify, etc. all need some kind of "don't tell me about performances at " (or better ) option.

Even if I liked a given act, telling me about a performance in some random city (that I haven't previously expressed a desire or willingness to travel to) is the opposite of helpful.

Is there a privacy-preserving, maybe FOSS, maybe self-hostable equivalent to bandsintown?

Even one of those three would be lovely to know.

#foss #privacy #BandsInTown #help

Ok. Looks like I need to clean up my #BandsInTown profile: I'm getting event-notifications for Bassnectar.
The Fall of the Bassnectar Empire

According to women and former collaborators who spoke to VICE, and a new lawsuit, the EDM star abused his fame and power to build a complex web of secret and manipulative relationships.

VICE