Feeds

Too many Watch Lists – Congress

How many does a country need?

  • alert
  • submit to reddit

SANS - Survey on application security programs

While errors in the Transportation Security Administration's "no-fly" list have famously raised the ire of innocent air travelers misidentified as terrorists, it's far from the only government watch list in use.

In a report released last week, the General Accounting Office, Congress' investigative arm, counted no less than 12 different government databases cataloging purportedly dangerous people, maintained by nine different federal agencies and accessed by 50 others -- a tangled web of largely incompatible systems that the GAO would like to see merged into one.

"[A]gencies have developed their respective watch lists, and have managed their use, in isolation from each other, and in recognition of each agency's unique legal, cultural, and technological environments," wrote investigators. "The result is inconsistent and limited sharing."

All of those lists contain names and birth dates; others -- like the INS's "Automated Biometric Identification System" and the State Department's "TIPOFF" database -- also hold fingerprints and photographs. Some include information on large financial transactions and travel history.

The problem, says the GAO, is that the systems use different software, run on three different operating systems, and store data in incompatible formats. All but four use closed proprietary standards. Seven aren't on interagency networks, so when sharing does occur, it's handled the old fashioned way -- by hand.

"According to several of these agencies, the manual workarounds are labor-intensive and time-consuming, and they limit the timeliness of the data provided," the report notes. "For example, data from the TIPOFF system are shared directly with the National Automated Immigration Lookout System through a regular update on diskette."

Consolidating the watch lists would benefit national security, investigators conclude.

Some of the government agencies involved agreed with the GAO that more sharing of data should occur, but seem less eager to create a single Super Watch List.

In a written response to the report, the Justice Department, which manages six of the lists, even cited civil liberties concerns over the idea of combining watch lists that include people suspected of criminal or terrorist involvement with lists of convicted offenders. But the bulk of Justice's response is devoted to the need to keep its lists secret from the public.

"There is no discussion of classified information in your report and the affect it will have on a consolidation effort due to the protection requirements such as clearances, 'need to know,' protection against improper disclosure, and handling of data," the department wrote.

The secrecy surrounding the watch lists is one of the things that peeves civil libertarians. Last month, the ACLU filed a lawsuit against the FBI, the Justice Department and the Transportation Security Administration in an effort to find out how two San Francisco peace activist wound up on the "no-fly" list, and were consequently detained and questioned at an airport.

© SecurityFocus logo

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.