Risk
8/7/2009
11:51 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

TSA OKs Biometric Security For Flight Crews

The stage is set for a Transportation Security Administration pilot program that accelerates flight crew security screening in airports.

The Transportation Security Administration has approved standards for a new security program that sets the stage for nationwide expansion of a program that will use biometric identifiers to verify flight crew members.

The system, called CrewPASS (short for Crew Personnel Advanced Screening System), allows flight crew members who opt into the program to move quickly through security checkpoints by checking biometric credentials, an airline-issued ID, and another form of identification against a database of airline employees that includes pictures of employees for further verification.

Airline security being what it is after 9/11, some flight crew members will be pulled aside for random screening even after going through CrewPASS, but the system should accelerate crew members through security.

Currently, airline crew members have to go through the same process as airline passengers, though they can often be observed being taken to the front of long passenger security lines.

CrewPASS was created by the Air Line Pilots Association International in 2007 and further developed in conjunction with the TSA, partially in response to a law passed to fulfill the recommendations of the 9/11 Commission. Provisions in that law required that the TSA create plans for an ID management system for flight crew members that would expedite their security checkpoint process.

Pilot CrewPASS programs are currently in place at airports in Baltimore, Pittsburgh, and Columbia, S.C., with contractor ARINC.

Though privacy worries have long been cause for pause, biometrics are increasingly being used and considered by government agencies as another tier of security.

Sen. Charles Schumer, (D-N.Y.), recently said he would be introducing a bill that would require all government contractors to use biometric identifiers as part of E-Verify, a forthcoming system that aims to prevent undocumented immigrants from doing government work.

In a panel discussion earlier this week, Department of Defense officials lauded the importance of biometrics in military security.


InformationWeek Analytics has published an independent analysis on strategic security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0619
Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

CVE-2014-2230
Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

CVE-2014-7281
Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

CVE-2014-7292
Published: 2014-10-23
Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.16125), and 2.3 (2.3.9074.18820) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter to ct.ashx.

CVE-2014-8071
Published: 2014-10-23
Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject arbitrary web script or HTML via the (1) givenName, (2) familyName, (3) address1, or (4) address2 parameter to registrationapp/registerPatient.page; the (5) comment parameter to all...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.