Stories
Slash Boxes
Comments
typodupeerror delete not in

Comments: 1 +-   Lax TSA Website Exposes Traveller's Information-> on Saturday January 12 2008, @07:38PM sjbe

Submitted by sjbe on Saturday January 12 2008, @07:38PM
security
sjbe writes "According to a January 2008 report from the US House of Representatives Committee on Oversight and Government Reform, from October 2006 through February 2007 traveller's who utilized the TSA website to attempt to remove their name from the No-Fly list risked having sensitive data, including social security numbers, exposed due to poor security practices. The contractor responsible, Desyne Web Services was awarded a no-bid contract to design the website. The TSA's technical lead on the project reportedly had a conflict of interest having been a former employee of Desyne. The security vulnerabilities were pointed out by Chris Soghoian, a Ph.D. student at the University of Indiana's School of Informatics. The TSA has since taken action to remedy the vulnerabilities but no action was taken to sanction the responsible parties for the vulnerabilities."
Link to Original Source
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
The more things change, the more they stay insane.