Feeds

US airport body scanners can store and export images

Uproar likely over threat of blurry customs pr0n

Top 5 reasons to deploy VMware with Tegile

Full body scanners at US airports can transmit digital strip search images of people, contrary to US Transportation Security Authority assurances.

The TSA has maintained that such scanners cannot store or transmit scanned body images of people, stating that "the machines have zero storage capability."

A TSA release stated that any scanned full body image "won't be stored, transmitted or printed, and [will be] deleted immediately once viewed." This is wrong too.

But according to documents obtained under freedom of information laws by EPIC (Electronic Privacy Information Center), they do indeed have a storage capability.

According to the TSA procurement specification, v1.02, 23 September 2008, the scanner, termed a Whole Body Imager (WBI) will have "a high capacity read/write drive... to permit data uploads and downloads." It will also "provide capabilities for data transfers via USB devices" and support both Ethernet and TCP/IP. Field reporting data for up to a year will be stored on the hard drive.

The procurement spec specifies two operating modes. In screening mode the WBI system will "prohibit the storage and exporting of passenger images."

However, "when not being used for normal screening operations, the capability to capture images of non-passengers for training and evaluation purposes is needed" and this is provided in test mode. In screening mode, the system will be prohibited from exporting passenger image data. The spec states: "During Test Mode, the WBI shall not be capable of conducting passenger screening."

Therein lies the rub. The system does not know a passenger from a non-passenger - both are simply humans inside the system's scanning field. The spec does not state how the system is switched between modes.

Another document obtained by EPIC says one system, identified by the government, can record images for training purposes. This capability is configurable at a superuser level and will be disabled in operational systems.

So that leaves us with full body scanners that can capture strip search scanned images of people when in test mode and export them either by USB or TCP/IP transfers (which are subject to certain security restrictions), and at least one system that can store scanned images.

That leaves privacy campaigners salivating at the mouth with the possibilities for information abuse, and the TSA with much egg on its face for issuing misleading statements. ®

Intelligent flash storage arrays

More from The Register

next story
The 'fun-nification' of computer education – good idea?
Compulsory code schools, luvvies love it, but what about Maths and Physics?
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
'Cowardly, venomous trolls' threatened with TWO-YEAR sentences for menacing posts
UK government: 'Taking a stand against a baying cyber-mob'
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Doctor Who's Flatline: Cool monsters, yes, but utterly limp subplots
We know what the Doctor does, stop going on about it already
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.