Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Privacy Protection: Oversight committee requests documents

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
cal04 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-23-07 09:59 PM
Original message
Privacy Protection: Oversight committee requests documents
The Oversight committee has requested documents from the Transportation Security Administration (TSA) amid recent reports that the TSA web site collected personal information without basic security measures to ensure privacy protection. Chairman Waxman writes:

There have been many problems with individuals incorrectly identified on the no-fly list. Persons with names similar or identical to names on the no-fly list — including senior Members of Congress such as Representative Don Young and Senator Edward Kennedy — have been prevented from boarding flights or otherwise detained and questioned because their names come up in no-fly list checks.

According to media reports, on February 13, 2007, TSA tried to address these problems by launching a new web page to allow travelers whose names are identical to the names of persons on TSA’s “no-fly list” to establish they are not the persons of concern. This new site, which was linked from TSA’s “Our Travelers” page, announced a “Travel Verification Identity Program,” which in turn asked travelers to submit sensitive personal information, such as their Social Security number, date of birth, height, weight, and eye color.

As soon as the site was launched, several web security experts alleged that this site lacked basic security measures to ensure that the submitted personal information would not end up in the hands of third parties. For example, these experts claimed that the site was not protected with a “secure sockets layer” (SSL), which would have ensured the secure transfer of the data to TSA. They also claimed that this failure to encrypt the data could have allowed a third party — including a terrorist — to obtain this sensitive personal information.

According to these experts, the site was not operating out of the TSA web domain, but instead was operating out of the following commercial domain: http://rms.desyne.com. This domain appears to belong to Desyne Web Services, Inc., a web design company whose mailing address is a post office box located in Boston, Virginia. In addition, security experts pointed out that the website text had numerous spelling errors and that the attached form did not have an OMB number, which all federal government forms are required to have. In fact, the overall appearance of the site was so poor that web experts first assumed it was a so-called “phishing” site, a site internet hackers had created to look like a TSA website page.

The site also appears to have been launched prematurely. A notice in the Federal Register on January 18, 2007, announced that, in compliance with the Privacy Act of 1974, the Department of Homeland Security would be creating a new system of records. This system, called the Traveler Redress Inquiry Program (TRIP) would support travelers’ ability to redress complaints that they have been incorrectly placed on no-fly lists. The comment submission period for this notice was open until February 20, 2007. If TSA’s traveler identity verification website is part of the TRIP system, it was launched while the comment period for this notice was still open.

Click here to read the full letter to Edmund Hawley, the Assistant Secretary of the Transportation Security Administration.

http://www.speaker.gov/blog/?p=54
Printer Friendly | Permalink |  | Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC