Risk
4/18/2008
06:49 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

JFK And LAX Get Scanners That See Through Clothes

Despite privacy concerns, TSA says 90% of passengers who are subject to secondary screening opt for a millimeter wave scan over a pat down.

The Transportation Security Administration on Friday said that it's beginning new pilot tests of millimeter wave scanning technology at Los Angeles International Airport (LAX) and John F. Kennedy International Airport (JFK).

Millimeter wave scanners allow TSA personnel to see concealed weapons and other items that may be hidden beneath clothes.

When the first TSA pilot test of the technology began in October at Phoenix Sky-Harbor International Airport, TSA Administrator Kip Hawley said that agency was committed to protecting passenger privacy and that the potentially revealing body scans would not be stored.

At the time, Barry Steinhardt, director of the ACLU's technology and liberty program, warned that the "strikingly graphic images of passengers' bodies" were an assault on personal dignity and expressed doubt about TSA's ability to safeguard the images.

Such concerns seem all the more reasonable given the government's inability to prevent State Department employees from inappropriately accessing the passport files of presidential candidates Hillary Clinton, John McCain, and Barack Obama.

TSA counters that 90% of passengers subject to secondary screening opt for a millimeter wave scan over a pat down. The agency said that security officers viewing the scans would do so remotely, where they will not be able to recognize passengers but will be able to trigger an alarm if needed. The agency also said that a blurring algorithm is applied to passengers' faces in scanned images as an additional privacy protection.

In a post on the TSA blog, TSA blogger Nico Melendez endorses the technology. "As a married father of five small children, I wouldn't think twice about sending my wife, my four boys or little girl into this machine," he says. "I've seen the image it produces and I am not only confident as a TSA employee -- but as a citizen -- that TSA has done everything possible to address passengers' privacy concerns regarding whole body imaging."

Most of the comments on the TSA blog express skepticism about the effectiveness and/or the safety of the system.

TSA said that at LAX, millimeter wave scans would be used "in a random continuous protocol," and that an alternative screening option would be available for those reluctant to submit to a body scan. At JFK, millimeter wave scans will be a secondary screening option.

TSA maintains that millimeter wave technology is safe because the scanning machines emit 10,000 times less energy than a cell phone. It plans to purchase and deploy 30 more millimeter wave machines this year.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4231
Published: 2015-07-03
The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.

CVE-2015-4232
Published: 2015-07-03
Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.

CVE-2015-4234
Published: 2015-07-03
Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.

CVE-2015-4237
Published: 2015-07-03
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv0...

CVE-2015-4239
Published: 2015-07-03
Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report