Risk
4/18/2008
06:49 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

JFK And LAX Get Scanners That See Through Clothes

Despite privacy concerns, TSA says 90% of passengers who are subject to secondary screening opt for a millimeter wave scan over a pat down.

The Transportation Security Administration on Friday said that it's beginning new pilot tests of millimeter wave scanning technology at Los Angeles International Airport (LAX) and John F. Kennedy International Airport (JFK).

Millimeter wave scanners allow TSA personnel to see concealed weapons and other items that may be hidden beneath clothes.

When the first TSA pilot test of the technology began in October at Phoenix Sky-Harbor International Airport, TSA Administrator Kip Hawley said that agency was committed to protecting passenger privacy and that the potentially revealing body scans would not be stored.

At the time, Barry Steinhardt, director of the ACLU's technology and liberty program, warned that the "strikingly graphic images of passengers' bodies" were an assault on personal dignity and expressed doubt about TSA's ability to safeguard the images.

Such concerns seem all the more reasonable given the government's inability to prevent State Department employees from inappropriately accessing the passport files of presidential candidates Hillary Clinton, John McCain, and Barack Obama.

TSA counters that 90% of passengers subject to secondary screening opt for a millimeter wave scan over a pat down. The agency said that security officers viewing the scans would do so remotely, where they will not be able to recognize passengers but will be able to trigger an alarm if needed. The agency also said that a blurring algorithm is applied to passengers' faces in scanned images as an additional privacy protection.

In a post on the TSA blog, TSA blogger Nico Melendez endorses the technology. "As a married father of five small children, I wouldn't think twice about sending my wife, my four boys or little girl into this machine," he says. "I've seen the image it produces and I am not only confident as a TSA employee -- but as a citizen -- that TSA has done everything possible to address passengers' privacy concerns regarding whole body imaging."

Most of the comments on the TSA blog express skepticism about the effectiveness and/or the safety of the system.

TSA said that at LAX, millimeter wave scans would be used "in a random continuous protocol," and that an alternative screening option would be available for those reluctant to submit to a body scan. At JFK, millimeter wave scans will be a secondary screening option.

TSA maintains that millimeter wave technology is safe because the scanning machines emit 10,000 times less energy than a cell phone. It plans to purchase and deploy 30 more millimeter wave machines this year.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9710
Published: 2015-05-27
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time windo...

CVE-2014-9715
Published: 2015-05-27
include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insufficiently large data type for certain extension data, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via outbound network traffic that trig...

CVE-2015-1157
Published: 2015-05-27
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2)...

CVE-2015-2666
Published: 2015-05-27
Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to t...

CVE-2015-2830
Published: 2015-05-27
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrate...

Dark Reading Radio
Archived Dark Reading Radio
After a serious cybersecurity incident, everyone will be looking to you for answers -- but you’ll never have complete information and you’ll never have enough time. So in those heated moments, when a business is on the brink of collapse, how will you and the rest of the board room executives respond?