Risk
4/18/2008
06:49 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

JFK And LAX Get Scanners That See Through Clothes

Despite privacy concerns, TSA says 90% of passengers who are subject to secondary screening opt for a millimeter wave scan over a pat down.

The Transportation Security Administration on Friday said that it's beginning new pilot tests of millimeter wave scanning technology at Los Angeles International Airport (LAX) and John F. Kennedy International Airport (JFK).

Millimeter wave scanners allow TSA personnel to see concealed weapons and other items that may be hidden beneath clothes.

When the first TSA pilot test of the technology began in October at Phoenix Sky-Harbor International Airport, TSA Administrator Kip Hawley said that agency was committed to protecting passenger privacy and that the potentially revealing body scans would not be stored.

At the time, Barry Steinhardt, director of the ACLU's technology and liberty program, warned that the "strikingly graphic images of passengers' bodies" were an assault on personal dignity and expressed doubt about TSA's ability to safeguard the images.

Such concerns seem all the more reasonable given the government's inability to prevent State Department employees from inappropriately accessing the passport files of presidential candidates Hillary Clinton, John McCain, and Barack Obama.

TSA counters that 90% of passengers subject to secondary screening opt for a millimeter wave scan over a pat down. The agency said that security officers viewing the scans would do so remotely, where they will not be able to recognize passengers but will be able to trigger an alarm if needed. The agency also said that a blurring algorithm is applied to passengers' faces in scanned images as an additional privacy protection.

In a post on the TSA blog, TSA blogger Nico Melendez endorses the technology. "As a married father of five small children, I wouldn't think twice about sending my wife, my four boys or little girl into this machine," he says. "I've seen the image it produces and I am not only confident as a TSA employee -- but as a citizen -- that TSA has done everything possible to address passengers' privacy concerns regarding whole body imaging."

Most of the comments on the TSA blog express skepticism about the effectiveness and/or the safety of the system.

TSA said that at LAX, millimeter wave scans would be used "in a random continuous protocol," and that an alternative screening option would be available for those reluctant to submit to a body scan. At JFK, millimeter wave scans will be a secondary screening option.

TSA maintains that millimeter wave technology is safe because the scanning machines emit 10,000 times less energy than a cell phone. It plans to purchase and deploy 30 more millimeter wave machines this year.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0972
Published: 2014-08-01
The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly prevent write access to IOMMU context registers, which allows local users to select a custom page table, and consequently write ...

CVE-2014-2627
Published: 2014-08-01
Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors.

CVE-2014-3009
Published: 2014-08-01
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct ph...

CVE-2014-3302
Published: 2014-08-01
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

CVE-2014-3534
Published: 2014-08-01
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a c...

Best of the Web
Dark Reading Radio