Boarding passes don't need to be secure anymore (as since 2008 non-electronic tickets went out of business [IATA Ticketing Handbook, 39th edition, p.29]), they are mostly pointers to DB and the scanning point makes list of passengers so double use is discovered. There is enough data to process them fully offline for failure modes, but that's fallback.