More depressing news on TSA Web site security

 

The US government's Transportation Security Administration had a Web page for airline passengers who were suffering from being on the list of those too frightening to fly not not so bad they can be arrested. It's sometimes called the watch list. If a person was on the watch list and was not too frightening, then they were to access the "Traveler Identity Verification Program" Web page. Clicking the link to that page took people to a domain owned by a Web design firm, not to the TSA. Wired magazine began reporting this on February 14, in their article entitled Homeland Security Website Hacked by Phishers? 15 Signs Say Yes. As the title says, Wired found 15 things that rang their reporters' alarm bells, including the problem that the site asked for details allowing identity theft without any security mechanisms in place.

 

Wired received a phone calll from a person purporting to be with the TSA claiming that there was no problem and that the site had been replaced.

 

Like all good reporters everywhere, Wired then asked other questions, concerning the site's use of cookies in violation of federal policy. Today, Wired reports that the page in question has been removed: TSA Removes Online Traveler Redress System and that the agency is reporting that it takes security seriously. Passengers are now directed to download a Word document and mail it in.

 

The reporter says that the collection of information still fails to comply with government rules and that the form has no OMB control numbers; there still is no answer on the noncompliant use of cookies on the TSA site.

 

While it might be interesting to have someone steal the identity of a person on the watchlist, I guess it wouldn't matter if the thief never flies under that name. People on the watchlist are likely to have had their credit wrecked anyway. A quick Web search turns up several news reports of people being denied credit because they are on the watch list and are suspected of money laundering.


Page Information

  • 1 year ago [history]
  • View page source
  • You're not logged in
  • No tags yet learn more

Wiki Information

Recent PBwiki Blog Posts