Lax TSA Website Exposed Travelers' Information 81
sjbe sends in an old story with a poetic justice ending. Almost a year ago Chris Soghoian blogged about multiple security holes exposing visitors to a TSA site to possible identity theft. Wired and others picked up the story and the TSA took down the insecure site and fixed the problems. On Friday the US House of Representatives Committee on Oversight and Government Reform released a report (PDF; HTML summary) finding that the TSA contractor, Desyne Web Services, had received a no-bid contract for the faulty site from a former employee who was then a TSA project manager. TSA has taken no action to sanction the responsible parties for the vulnerabilities. The poetic justice is that Soghoian had been investigated for 6 months by the FBI and TSA because he pointed out a vulnerability in the US air transport system; no charges were ever filed.
Like most security theater in this country ... (Score:3, Funny)
"Lax" describes it pretty well.
Re:Like most security theater in this country ... (Score:5, Funny)
Re:Like most security theater in this country ... (Score:5, Funny)
Well, I've been through Los Angeles Airport a couple of times recently. I'd say either appellation is apt.
Re: (Score:1)
Re: (Score:2)
Another concrete example (Score:4, Interesting)
What I want to know is ... (Score:5, Interesting)
Nobody wants their dirty laundry aired, I understand, but attacking people that expose such egregious errors does nothing to improve matters. I mean, if I say publicly that "your Web site has x security flaws in it" and it turns out I'm lying, fine, sue me for libel or slander or whatever else. Or better yet, just ignore me. But if I make you aware of a serious problem and you do nothing but try to intimidate me into silence, you're obviously trying to cover your ass, and should be fired for incompetence.
Re: (Score:3, Insightful)
Well, at least we won't have to worry about the encroaching loss of civil liberties
Of course, it would be a good idea for everyone to have a few guns and plenty of ammo: anarchy can be unpleasant.
Re: (Score:1, Insightful)
Nobody likes a snitch. Expecting anything else is willful ignorance.
Re:What I want to know is ... (Score:5, Interesting)
It's a much better move, careerwise, for a network admin to say "some guy was trying to hack our system, and being the network guru that I am I got his name and number", rather than admit that "some guy found a major hole in our security system, and kindly reported to us."
There have been numerous cases of Good Samaritan types reporting an insecurity on a Web site, and having the sysadmins call up the FBI and report a "hacking attempt." Over the past several years I've been on misconfigured Web sites and FTP servers that gave me access to things I should never have been allowed to see. My normal instinct would be to report the problem to the site's administrators
This is not the same thing as being a whistleblower, which is what you're referring to. See, someone who is truly interested in securing a system would investigate such reports, from any source internal or external, and fix them. What we've been seeing is that it's more important to simply squelch such complaints at any cost, rather take the heat for one's mistakes. Worse, given the current legal situation in the U.S. a corporation that files a false hacking report can screw somebody up for life.
That's where I draw the line.
I agree.. (Score:3, Interesting)
Re: (Score:2)
Re: (Score:2)
It's one area where you can report the problem directly to an enforcing agency and heads will roll, rather than reporting it to
Re: (Score:2)
this is nothing new, this has been going on for a loooonngg time, i suggest reporting it anonymously and publicly let everyone know including the IT responsible for locking down the system then just sit back and watch...
Re: (Score:3, Insightful)
Re:What I want to know is ... (Score:4, Insightful)
If private sector employees acted like this, they'd be fired for incompetence, the relationship with the incompetent 3rd party would be terminated fairly quickly, pressure would be put on the local district attorney to file fraud and conspiracy criminal charges if there was collusion and a whole lot less money would be spent before it all went away.
In the case of government employees, it's just status quo. Move alone, nothing to see here.
Re:What I want to know is ... (Score:4, Informative)
Re:What I want to know is ... (Score:4, Insightful)
But private companies are under no obligation to be fair in who they buy from. There are no laws that say a company must buy from the best, or cheapest, or whatever. They just pick who they feel like working with and that's it. If they want to buy work from their buddy then they do it. That's not fraud or conspiracy or collusion. It's not even secret or embarrassing. That's what business is all about, they just call it "networking" whereas in the government they call it "cronyism".
Public companies at least have some obligation to shareholders to be fiscally responsible, but for the most part dealing with this kind of issue doesn't get raised to the level of the board of directors unless it dramatically affects the quarterly results, so the management is free to do whatever it wants anyway. CEOs in the private sector are cowboys and apparently as a country we like it that way, evidenced by the fact that so many people these days balk at regulation.
So, no, this would not be better in the private sector. In fact, it is the status quo in the private sector which is why it is rarely news. It is not status quo in the government, or at least it shouldn't be, which is why we get so upset when it happens there. We expect the government to serve the people, and we want it to. We don't expect the private sector to serve the people we expect it to serve the company owners, and it does.
The real story here is that cronyism has spread like a cancer into many areas of government, and this item in particular shows how the very forces that are claiming to enhance our national security are actually sabotaging it. The answer isn't to leave it to the private sector and let the cancer win, the answer is to kill the cancer before it kills us.
Re:What I want to know is ... (Score:4, Insightful)
Re: (Score:1)
There is a huge difference between high level goals and the details of operating decisions. Companies make all kinds of decisions, some of which lose money and some of which make money. There is nothing that says a company can't spend too much on pencils, or pay too much for a web site from the CFO's cousin. In a typical company, how many purchase order decisions are made by putting out requests for bids? In most companies none. It is up to the management to decide what something is worth to the company
Re: (Score:3, Interesting)
In order to teach whistleblowers that the best way to point out security issues is to post the 'sploit anonymously and watch the enemy agency get hammered. It is obvious that these government agencies resent attempts to "help" them and will attack those who try. Stop Trying.
Re: (Score:2)
Why do you post your opinion as a question?
Re: (Score:2)
Re: (Score:3, Interesting)
Re: (Score:2)
Even as we are faced with incident after incident. (Score:5, Insightful)
Real ID is going to be a nightmare.
Re:Even as we are faced with incident after incide (Score:5, Insightful)
If that's what it takes. Remember the FBI under Hoover? Did all kinds of abusive stuff, until it finally reached the point where Congress had to rein them in and enact strict controls on their behavior, mainly because Congress itself was threatened by Hoover's activities. Hell, the bastard had dirt on all of them. However, many of those restrictions on law enforcement were undone with the Patriot Act, CALEA and other poorly-designed laws designed to strip civil liberties from us. I have the feeling that we're going to have to suffer through yet another cycle of government abuse (worse this time) until the pendulum swings back and some controls get put back in place.
If we're that lucky. I have my doubts about this go 'round
Re: (Score:2)
Re: (Score:3, Informative)
Re: (Score:2)
I'm sorry, since when did the existence of a worse system make this system okay? There is *always* a worse system. That does not justify this one. I don't want to be personal, but your statement is pitiful, apologetic garbage. I don't care who runs the US government. Republicans, Democrats, it doesn't matter. THEY ARE ALL OUT OF CONTROL.
I *do* want a revolution. It is absolutely necessary at this point. Yes, a lot of us may not live through
Re:Even as we are faced with incident after incide (Score:5, Insightful)
As an engineer, upon further reflection I think that a more apt description would be "running open loop". If you look at the U.S. Constitution, you'll realize that the so-called "checks-and-balances" put in place by the Founders, indeed the underpinnings of our entire Republic, are nothing but a series of carefully crafted negative feedback loops. The intent of those mechanisms was, of course, to prevent the government from going too far in one direction. The most basic of those is the fact that we can elect our leaders: the governments actions are processed by the population and fed back to the input as votes. Another loop was the original tariff system. It is complicated, but it worked for a long, long time, and had our elected leaders not fiddled with it continuously, would still be working now.
The problem is that Congress, with its fundamental incompetence and endless quest for votes, has opened most of those loops and the proper amount of negative feedback is no longer being applied to the system inputs. In fact, there's generally no negative feedback whatsoever: it's all going the other way. That's placed us in a swell of uncontrolled positive feedback which will eventually reach the maximum tolerance of the system.
In electronic terms, that usually means your output is locked to within a few millivolts of your positive supply voltage. In civil terms, it means a revolution is about to start.
Re: (Score:3, Insightful)
while i don't disagree that our government leadership is incompetent, i think that the blame isn't solely on politicians. we did at one point live in a free and democratic society. a large part of the blame therefor rests on the the public. we have developed a culture of apathy, and as such no revolution could ever take place.
the reason for public apathy is two folds. firstly, the bipartisan system that our democracy has evolved into is inherently broken. but more importantly the 4th estate has failed to u
Re: (Score:2)
-G
Re: (Score:2)
-G
Re: (Score:2)
The generation which experienced stuff like that is rapidly passing into senility or worse.
Re: (Score:2)
Re: (Score:2)
After all you and i don't pay the cost of re-election campaigning.
It is done by corporates, who will stand to benefit from Real ID act.
Imagine the cost of contracting out large quantities of safeboard, ink, printing presses, plastic, computer systems to maintain, training, emergency services (someone enters his hand into a press), laser printers, etc.
And now imagine how much employment is generated when these people are needed for abov
Re: (Score:2)
Indeed. Congress is "crating" all of our jobs
Re: (Score:2)
Economics is a zero sum game. For me to win, you have to lose.
Crating jobs to india does not mean if the jobs were not crated would be available in USA. It is more likely the cost of living would have increased a lot, but so too would have salaries.
Now by crating jobs, we enable the rich to earn more via LBO and IPOs.
Re: (Score:2)
this actually shows the opposite (Score:2)
I think the opposite is true. This TSA site is needed at all because right now it's hard to prove that you're not on the list of bad guys. If you carry biometrically secure identification and have a unique identifier, that becomes much easier. A lot of the intrusions into our civil liberties and the lack of privacy are a result of not having good identifiers.
In any case, the private sector is already going this route anyway with identification like the Clear card.
Re: (Score:2)
Thing is that outside of fiction such things simply do not exist. Any actual ID card scheme will at best be only as secure as current systems.
A lot of the intrusions into our civil liberties and the lack of privacy are a result of not having good identifiers.
Actu
Re: (Score:2)
Lots of countries have physical id cards that are nearly impossible to forge. Many of those have no electronic components at all, are fully human readable, and are excellent from a privacy point of view.
Actually what you need to know is intent knowing identity isn't actually of much use.
Identity tells you a great deal about intent. Countries like Israel, for example
Re: (Score:2)
In which case the other likelyhood is infiltration of wherever these are issued or bribary/blackmail of those already working there. A more likely reason for a low level of id cards being forged is that (unlike those proposed in the US and UK) they are "low value".
Identity tells you a great deal about i
Poetic justice? (Score:2, Informative)
Re: (Score:1)
Re: (Score:2)
Summary:
"The poetic justice is that Soghoian had been investigated for 6 months by the FBI and TSA because he pointed out a vulnerability in the US air transport system; no charges were ever filed."
TFA:
"I'd be lying if I said that I wasn't grinning from ear to ear with the news of this report.
It's poetic justice, if you will, for the unpleasantness that TSA put me through."
IN TFA it isn't really "poetic justice" either. It's just "justice", lacking any of the irony necessary to make it "poetic". But makes a
Summary misses the point entirely (Score:5, Informative)
Re: (Score:2)
Re: (Score:2, Interesting)
Re: (Score:2)
So first you praise him for exposing one security vulnerability, but damn him from exposing another? Why should he keep quiet when it's obvious how to create a fake boarding card?
Well. (Score:2)
..."no charges were ever filed." (Score:3, Interesting)
Nixon's the one [rvv.com].
Re: (Score:3, Funny)
Where is a good place to complain about the TSA (Score:2)
Re: (Score:2)
http://www.senate.gov/general/contact_information/senators_cfm.cfm [senate.gov]
rj
TSA = Toothpaste Security Agency (Score:4, Insightful)
Yet today the DHS and TSA are still focused on the box cuters. Patrick Smith of the New York Times points out just how pointless the TSA searches have become. Why for example do they confiscate tubes of toothpaste or shampoo bottles potentially containing explosive materials, only to throw them out in the trash unchecked? Why do cleaners and garbage workers handle these supposedly dangerous contraband unprotected? The ban on fluids itself flies in the face of scientific opinion: "The notion that deadly explosives can be cooked up in an airplane lavatory is pure fiction."
http://jetlagged.blogs.nytimes.com/2007/12/28/the-airport-security-follies/index.html [nytimes.com]
Re: (Score:3, Insightful)
Why for example do they confiscate tubes of toothpaste or shampoo bottles potentially containing explosive materials, only to throw them out in the trash unchecked? Why do cleaners and garbage workers handle these supposedly dangerous contraband unprotected?
Every promotion at the TSA requires that you get beaten in the head. The people who you see on the floor doing menial labor have not yet been beaten in the head. They know that there is nothing to fear from toothpaste.
Re: (Score:2)
Remember the story they made up for that one: the tubes contain components of liquid explosives, which would have been mixed in the lavatory to make the explosives. The tubes don't contain explosives themselves.
Of course, the story's bogus, because t
Re: (Score:2)
OK, I here this meme all the time and it's finally annoyed me to post something. It's a preventative measure. A terrorist going to an airport wouldn't be able to easily take in liquid explosives (or otherwise nasty liquid chemicals) by stuffing them into toothpaste tube or shampoo bottle. Checking ALL the confiscated items would be prohibitivel
Re: (Score:2)
Nothing new to see here, move along... (Score:2, Insightful)
DHS and the TSA were never meant to actually prevent harm to any citizen, but rather as a transfer of power from the citizen to the government. In that context, the ineptitude, mismanagement, harassment, failures, and the 'kill the messenger' attitude, begin to make a kind of sense. Much as any despotic entit
representatives (Score:4, Insightful)
Re: (Score:1)
I'm a DC resident and don't have an elected representative, you insensitive clod!
Incompetence Pays! (Score:1)
Privacy is myth!
All information is available SOMEWHERE.
Pay the piper... (Score:1)
My bet is anyone with a permutation of Chris Soghoian's name already has a 'SSSSS' on his boarding pass.