Risk
8/7/2009
11:51 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

TSA OKs Biometric Security For Flight Crews

The stage is set for a Transportation Security Administration pilot program that accelerates flight crew security screening in airports.

The Transportation Security Administration has approved standards for a new security program that sets the stage for nationwide expansion of a program that will use biometric identifiers to verify flight crew members.

The system, called CrewPASS (short for Crew Personnel Advanced Screening System), allows flight crew members who opt into the program to move quickly through security checkpoints by checking biometric credentials, an airline-issued ID, and another form of identification against a database of airline employees that includes pictures of employees for further verification.

Airline security being what it is after 9/11, some flight crew members will be pulled aside for random screening even after going through CrewPASS, but the system should accelerate crew members through security.

Currently, airline crew members have to go through the same process as airline passengers, though they can often be observed being taken to the front of long passenger security lines.

CrewPASS was created by the Air Line Pilots Association International in 2007 and further developed in conjunction with the TSA, partially in response to a law passed to fulfill the recommendations of the 9/11 Commission. Provisions in that law required that the TSA create plans for an ID management system for flight crew members that would expedite their security checkpoint process.

Pilot CrewPASS programs are currently in place at airports in Baltimore, Pittsburgh, and Columbia, S.C., with contractor ARINC.

Though privacy worries have long been cause for pause, biometrics are increasingly being used and considered by government agencies as another tier of security.

Sen. Charles Schumer, (D-N.Y.), recently said he would be introducing a bill that would require all government contractors to use biometric identifiers as part of E-Verify, a forthcoming system that aims to prevent undocumented immigrants from doing government work.

In a panel discussion earlier this week, Department of Defense officials lauded the importance of biometrics in military security.


InformationWeek Analytics has published an independent analysis on strategic security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0702
Published: 2015-04-20
Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides shell access, aka Bug ID CSCus95712.

CVE-2015-0703
Published: 2015-04-20
Cross-site scripting (XSS) vulnerability in the administrative web interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCus95857.

CVE-2015-1235
Published: 2015-04-19
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME element.

CVE-2015-1236
Published: 2015-04-19
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a cr...

CVE-2015-1237
Published: 2015-04-19
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages ...

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.