The Register® — Biting the hand that feeds IT

TSA makes a hash of 'no-fly' redress site

I'm not a terrorist and you know zip about net security

Free whitepaper – Securing your online data transfer with SSL

The Transportation Security Administration (TSA) website has not been hacked by identity thieves, despite appearances to the contrary.

The TSA recently created a website to enable people wrongly listed on its infamous "no-fly list" to establish that they were not a security threat. They were invited to submit detailed and confidential information, on a site hosted by a third-party, Virginia-based web design company spelled Desyne.

But as originally set-up, data was submitted to the site through an insecure link. Worse, people who used the site typically did so after they had been delayed from boarding a plane. And there was a good possibilty that they submitted the data from an airline terminal, an unfamiliar location where they might be more likely to stray onto a bogus network set up to trick the unwary.

To the astute, the TSA site had all the hallmarks of a bogus site run by conmen and designed to harvest personal information. After the shortcomings of the TSA's site were highlighted - by Chris Soghoian, the boarding pass generator hacker - the site was moved onto a secure server (https://trip.dhs.gov/index.html). Problems remain: the site is still outsourced and continues to use cookies (a practice that runs counter to federal policy).

The TSA's security SNAFU is reminiscent of the mistakes made last month by the UK government in establishing a MI5's terror status mailing list. In that case users were only submitting their name and email address whereas the TSA website invites submission of a full spectrum of confidential data, including their date and place of birth, drivers license details and passport number, making the TSA's slip-up even more galling. ®

Free whitepaper – The starter PKI program

Don’t Miss

GoogleGoogle cloud told to encrypt itself

Updated R in RSA wants s in https

thumbs down teaser 75Buggy 'smart meters' open door to power-grid botnet

Grid-burrowing worm only the beginning

Flag ChinaChinese firm hits back at cyberspy claims

Exclusive Huawei welcomes UK.gov backdoor probe

BlockMaster SafeStickBlockMaster SafeStick hardware-encrypted USB drive

Review Tough enough?