Risk
8/7/2009
11:51 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

TSA OKs Biometric Security For Flight Crews

The stage is set for a Transportation Security Administration pilot program that accelerates flight crew security screening in airports.

The Transportation Security Administration has approved standards for a new security program that sets the stage for nationwide expansion of a program that will use biometric identifiers to verify flight crew members.

The system, called CrewPASS (short for Crew Personnel Advanced Screening System), allows flight crew members who opt into the program to move quickly through security checkpoints by checking biometric credentials, an airline-issued ID, and another form of identification against a database of airline employees that includes pictures of employees for further verification.

Airline security being what it is after 9/11, some flight crew members will be pulled aside for random screening even after going through CrewPASS, but the system should accelerate crew members through security.

Currently, airline crew members have to go through the same process as airline passengers, though they can often be observed being taken to the front of long passenger security lines.

CrewPASS was created by the Air Line Pilots Association International in 2007 and further developed in conjunction with the TSA, partially in response to a law passed to fulfill the recommendations of the 9/11 Commission. Provisions in that law required that the TSA create plans for an ID management system for flight crew members that would expedite their security checkpoint process.

Pilot CrewPASS programs are currently in place at airports in Baltimore, Pittsburgh, and Columbia, S.C., with contractor ARINC.

Though privacy worries have long been cause for pause, biometrics are increasingly being used and considered by government agencies as another tier of security.

Sen. Charles Schumer, (D-N.Y.), recently said he would be introducing a bill that would require all government contractors to use biometric identifiers as part of E-Verify, a forthcoming system that aims to prevent undocumented immigrants from doing government work.

In a panel discussion earlier this week, Department of Defense officials lauded the importance of biometrics in military security.


InformationWeek Analytics has published an independent analysis on strategic security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5700
Published: 2014-09-22
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in blocks/loginbox/loginbox.template.php to index.php. NOTE: some o...

CVE-2014-0484
Published: 2014-09-22
The Debian acpi-support package before 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment."

CVE-2014-2942
Published: 2014-09-22
Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a privileged terminal session by calculating the superuser code, and then leveraging physical access or terminal access to enter this code.

CVE-2014-3595
Published: 2014-09-22
Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.

CVE-2014-3635
Published: 2014-09-22
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows remote attackers to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one m...

Best of the Web
Dark Reading Radio