Feeds

US airport body scanners can store and export images

Uproar likely over threat of blurry customs pr0n

Internet Security Threat Report 2014

Full body scanners at US airports can transmit digital strip search images of people, contrary to US Transportation Security Authority assurances.

The TSA has maintained that such scanners cannot store or transmit scanned body images of people, stating that "the machines have zero storage capability."

A TSA release stated that any scanned full body image "won't be stored, transmitted or printed, and [will be] deleted immediately once viewed." This is wrong too.

But according to documents obtained under freedom of information laws by EPIC (Electronic Privacy Information Center), they do indeed have a storage capability.

According to the TSA procurement specification, v1.02, 23 September 2008, the scanner, termed a Whole Body Imager (WBI) will have "a high capacity read/write drive... to permit data uploads and downloads." It will also "provide capabilities for data transfers via USB devices" and support both Ethernet and TCP/IP. Field reporting data for up to a year will be stored on the hard drive.

The procurement spec specifies two operating modes. In screening mode the WBI system will "prohibit the storage and exporting of passenger images."

However, "when not being used for normal screening operations, the capability to capture images of non-passengers for training and evaluation purposes is needed" and this is provided in test mode. In screening mode, the system will be prohibited from exporting passenger image data. The spec states: "During Test Mode, the WBI shall not be capable of conducting passenger screening."

Therein lies the rub. The system does not know a passenger from a non-passenger - both are simply humans inside the system's scanning field. The spec does not state how the system is switched between modes.

Another document obtained by EPIC says one system, identified by the government, can record images for training purposes. This capability is configurable at a superuser level and will be disabled in operational systems.

So that leaves us with full body scanners that can capture strip search scanned images of people when in test mode and export them either by USB or TCP/IP transfers (which are subject to certain security restrictions), and at least one system that can store scanned images.

That leaves privacy campaigners salivating at the mouth with the possibilities for information abuse, and the TSA with much egg on its face for issuing misleading statements. ®

Beginner's guide to SSL certificates

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Driving with an Apple Watch could land you with a £100 FINE
Bad news for tech-addicted fanbois behind the wheel
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Special pleading against mass surveillance won't help anyone
Protecting journalists alone won't protect their sources
Big Content Australia just blew a big hole in its credibility
AHEDA's research on average content prices did not expose methodology, so appears less than rigourous
Vodafone to buy 140 Phones 4u stores from stricken retailer
887 jobs 'preserved' in the process, says administrator PwC
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.