Risk
8/7/2009
11:51 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

TSA OKs Biometric Security For Flight Crews

The stage is set for a Transportation Security Administration pilot program that accelerates flight crew security screening in airports.

The Transportation Security Administration has approved standards for a new security program that sets the stage for nationwide expansion of a program that will use biometric identifiers to verify flight crew members.

The system, called CrewPASS (short for Crew Personnel Advanced Screening System), allows flight crew members who opt into the program to move quickly through security checkpoints by checking biometric credentials, an airline-issued ID, and another form of identification against a database of airline employees that includes pictures of employees for further verification.

Airline security being what it is after 9/11, some flight crew members will be pulled aside for random screening even after going through CrewPASS, but the system should accelerate crew members through security.

Currently, airline crew members have to go through the same process as airline passengers, though they can often be observed being taken to the front of long passenger security lines.

CrewPASS was created by the Air Line Pilots Association International in 2007 and further developed in conjunction with the TSA, partially in response to a law passed to fulfill the recommendations of the 9/11 Commission. Provisions in that law required that the TSA create plans for an ID management system for flight crew members that would expedite their security checkpoint process.

Pilot CrewPASS programs are currently in place at airports in Baltimore, Pittsburgh, and Columbia, S.C., with contractor ARINC.

Though privacy worries have long been cause for pause, biometrics are increasingly being used and considered by government agencies as another tier of security.

Sen. Charles Schumer, (D-N.Y.), recently said he would be introducing a bill that would require all government contractors to use biometric identifiers as part of E-Verify, a forthcoming system that aims to prevent undocumented immigrants from doing government work.

In a panel discussion earlier this week, Department of Defense officials lauded the importance of biometrics in military security.


InformationWeek Analytics has published an independent analysis on strategic security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5211
Published: 2015-01-27
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

CVE-2014-8154
Published: 2015-01-27
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overf...

CVE-2014-9197
Published: 2015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

CVE-2014-9198
Published: 2015-01-27
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

CVE-2014-9646
Published: 2015-01-27
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.