Risk
4/18/2008
06:49 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

JFK And LAX Get Scanners That See Through Clothes

Despite privacy concerns, TSA says 90% of passengers who are subject to secondary screening opt for a millimeter wave scan over a pat down.

The Transportation Security Administration on Friday said that it's beginning new pilot tests of millimeter wave scanning technology at Los Angeles International Airport (LAX) and John F. Kennedy International Airport (JFK).

Millimeter wave scanners allow TSA personnel to see concealed weapons and other items that may be hidden beneath clothes.

When the first TSA pilot test of the technology began in October at Phoenix Sky-Harbor International Airport, TSA Administrator Kip Hawley said that agency was committed to protecting passenger privacy and that the potentially revealing body scans would not be stored.

At the time, Barry Steinhardt, director of the ACLU's technology and liberty program, warned that the "strikingly graphic images of passengers' bodies" were an assault on personal dignity and expressed doubt about TSA's ability to safeguard the images.

Such concerns seem all the more reasonable given the government's inability to prevent State Department employees from inappropriately accessing the passport files of presidential candidates Hillary Clinton, John McCain, and Barack Obama.

TSA counters that 90% of passengers subject to secondary screening opt for a millimeter wave scan over a pat down. The agency said that security officers viewing the scans would do so remotely, where they will not be able to recognize passengers but will be able to trigger an alarm if needed. The agency also said that a blurring algorithm is applied to passengers' faces in scanned images as an additional privacy protection.

In a post on the TSA blog, TSA blogger Nico Melendez endorses the technology. "As a married father of five small children, I wouldn't think twice about sending my wife, my four boys or little girl into this machine," he says. "I've seen the image it produces and I am not only confident as a TSA employee -- but as a citizen -- that TSA has done everything possible to address passengers' privacy concerns regarding whole body imaging."

Most of the comments on the TSA blog express skepticism about the effectiveness and/or the safety of the system.

TSA said that at LAX, millimeter wave scans would be used "in a random continuous protocol," and that an alternative screening option would be available for those reluctant to submit to a body scan. At JFK, millimeter wave scans will be a secondary screening option.

TSA maintains that millimeter wave technology is safe because the scanning machines emit 10,000 times less energy than a cell phone. It plans to purchase and deploy 30 more millimeter wave machines this year.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0607
Published: 2014-07-24
Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file.

CVE-2014-1419
Published: 2014-07-24
Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.

CVE-2014-2360
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high battery voltage.

CVE-2014-2361
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.

CVE-2014-2362
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.