Kind of a great point. People definitely build their own secure passes and they're always amusing (compare your boarding pass with LIRR tickets with Ticketmaster tickets; they all do something slightly different and none seem particularly secure).
Boarding passes don't need to be secure anymore (as since 2008 non-electronic tickets went out of business [IATA Ticketing Handbook, 39th edition, p.29]), they are mostly pointers to DB and the scanning point makes list of passengers so double use is discovered. There is enough data to process them fully offline for failure modes, but that's fallback.
Kids - just bring an Android phone if you’re going to scam, since events can’t require customers to be iPhone owners, and Apple didn’t design this with universal compatibility in mind.
Right -- I'd already have thought places "couldn't" require people to be any kind of smartphone owner to participate in commerce, but I notice that more and more these days.
There are already a lot that require "verified" brands. So iPhone or Android only, maybe recent versions only, and not the hackable Androids like Graphene. Wouldn't be surprised if a more niche place unintentionally required an iPhone.
Are you saying that you think an event wouldn’t do this because they’d be losing android-owning customers? Or that they couldn’t do it for some legal or regulatory reason?