Live data from Hacker News

TSA Pressures Mainstream Media Not To Cover Story

tsaoutofourpants.wordpress.com

121–130 of 156 posts

Re: TSA Pressures Mainstream Media Not To Cover Story

#121
FTA: "For obvious security reasons, we can’t discuss our technology's detection capability in detail"

The only situation that would make this "obvious" is if the technology is inadequate. Basically by saying that, they're admitting to a large amount of security through obscurity.

Imagine a bank's website saying "For obvious security reasons, we can’t discuss how our passwords are store in detail". Wait, why not? If the technology is adequate to the task you should be able to explain exactly how it works without compromising anything!

Re: TSA Pressures Mainstream Media Not To Cover Story

#122

They're not really threatening anything, they're just asking "please don't cover this story". That's their right and it's not censorship unless the journalist faces consequences for covering the story (no future interviews, harassment by the legal system, etc.) It doesn't seem like any consequences are mentioned or implied, so this doesn't bother me. Of course the TSA doesn't want negative press. Would you?

No, they're not asking ""please don't cover this story"" . They are "strongly cautioning" them not to, which can reasonably be interpreted as a veiled threat.

A threat to do what?

Re: TSA Pressures Mainstream Media Not To Cover Story

#123

Earlier quoted context omitted.

Favor the machines over a pat-down. They would actually _prefere_ neither.

Sorry, this is wishful (I share your wish). The reality is, the polls aren't posing the either/or question. Respondents can favor the imaging machines and reject the pat-downs. Here's a sample question: The Transportation Security Administration is increasing its use of so-called 'full-body' digital x-ray machines to screen passengers in airport security lines. (Supporters say these machines improve the ability to sp…

It is right that about half of the Americans don't fly very often and seem for the scanners according to some recent polls. My "failure of democracy" statement was exaggerated I think.

On the other hand, people who fly somewhat frequently seem to be almost all against them. The guy who published the video said comments against the machines on his blog outnumber 20 to 1 the people who support them.

Re: TSA Pressures Mainstream Media Not To Cover Story

#124

Earlier quoted context omitted.

There might be a suit brought on behalf of one of these reporters and/or their employer arguing that the implication of consequences from such a powerful entity without a court order constitutes illegal interference with their business, possibly entitling them to some damages, and more importantly, establishing some very important precedent which might prevent the TSA from ever attempting such a stunt in the future.…

You are not familiar with Sovereign Immunity. No lawyer in the world salivates at the thought of suing the federal government.

Real lawyers do. We don't have real lawyers.

Re: TSA Pressures Mainstream Media Not To Cover Story

#125
post #98

Though both the email and the blog response from TSA are incredibly unprofessional, the email is NOT intimidation or a "veiled threat", and exaggerating by claiming it is is not going to help a sane discussion about this issue. What do you think the TSA is "threatening" to do? They have no power over the media. All the TSA are saying is "exercise caution with reporting on bloggers that make random statements because…

Is there an implied threat of being less cooperative with feeding the journalist info though?

It doesn't have to be "we will put you on a no-fly list" so much as "well, that's our right but we don't have to let you in to any press conferences anymore...."

Re: TSA Pressures Mainstream Media Not To Cover Story

#126

Earlier quoted context omitted.

He doesn't want to ruin his relationship with the source by doing so, but again, it should be a public record releasable under FOIA

What kind of relationship does he have with a TSA agent who is mildly threatening him or intimidating him at least?

The TSA as a journalistic source?

Re: TSA Pressures Mainstream Media Not To Cover Story

#127
post #28

So the TSA is "securing" airports by trying to keep vulnerabilities secret. Their thinking seems to be, "if no one knows where the open door is, no one will get in." Surely that will work out well. Not! Bruce Schneier must be getting a kick out of this.

Indeed. Here's what I posted on Facebook (mildly edited for clarity) about the TSA's response (btw one of my Facebook friends is a TSA screener):

Some thoughts about this.

The main defense that the TSA offers over the body scanners in this regard is that it is somehow better/harder to circumvent than the metal detectors, and that it's only one part of a larger program using layers of security.

We can argue about the specifics but the idea of layers of security is one thing the TSA is doing right. One of my complaints about the body scanners is that they are not implemented in a way that makes full use of this (tandem to a metal detector, as separate layers, ideally in conjunction with behavioral indicators). But that's neither here nor there. I want to talk about testing.

As a software engineer, I know there is testing, and there is testing. Extensive pre-deployment testing is important. There can't be any doubt of that. However, it is also by definition incomplete. Stuff will always get missed. Real testing in a security environment involves the sorts of things that this video involves--- many people looking for ways to circumvent a given technology and doing so. A few professional testers will miss stuff because everyone has blind spots. This has to be an ongoing thing, and it has to rely on independent individuals not beholden to the organization ordering the testing.

In the computer software field, while the stakes are lower, we deal with a level of constant attack unmatched in any physical security field. A firewall in the rural US is under more constant attack than any US troops on any battlefield and I have logs to prove this, so in my industry we have had to find better ways of dealing with these problems than we see with the Department of Homeland Security today. While my life may not depend on my firewall holding up, my livelihood very well might, as does all of your credit card data depend on firewalls of places like Amazon.

The video I linked to yesterday, while I don't agree with all of the political remedies proposed is a solid example of penetration testing, and the sort that makes us more secure. We should no more trust the TSA with securing our airports than we should trust Microsoft with securing our data. Microsoft can't get there without armies of white-hat hackers reporting vulnerabilities before the bad guys find and exploit them. The TSA shouldn't attempt this either.

Just this week we saw a massive security hole discovered at Github, which many open source projects use. This hole allowed anyone who had an account (and anyone can sign up!) the ability to commit software changes to any project on the system. The severity of this problem was just unbelievable. In all likelihood this would have gone at least partially unfixed (given past attempts to get the software fixed) had it not been for one daring individual breaking into the system in a reasonably responsible (as far as we know, but if you use github, audit your code!) way.

But imagine if a bad guy did this? What critical systems would be vulnerable for years because of malware planted? The fact that it was reported in a public way after a previous fix was attempted and fell flat was a good thing.

I have been on the receiving end of accusations of fearmongering for exposing security holes (in software). The fact though is that this is usually the first step to getting the problem fixed. Whatever else is discussed, we need to keep that in mind.

The correct response should have been, "We are evaluating this report and, once we are finished doing so, will institute whatever corrective steps appear to be necessary to solve the problem." This is not it.

Re: TSA Pressures Mainstream Media Not To Cover Story

#128
post #29
post #16

Overlay a thin layer of material over the metal plate (the dark/black region in the images) that has a regular repeating pattern (think checkerboard) that shows objects suspended beyond the body's silhouette. Problem solved.

The problem isn't that this one particular technique exists. The problem is that the TSA's decision making process led them to spend billions of dollars a year against the advisement of the top security experts in the world. For an organization who's sole purpose is the security of the American people, they're awfully bad at doing things that ensure the security of the American people.

How many places do you think assume security is a problem that can be solved by buying fancy products?

This is an all-too-common mistake. I am sure we have all seen it in the IT industry. I am surprised we don't just recognize it and call it out as such when we see the federal government doing the same.

Re: TSA Pressures Mainstream Media Not To Cover Story

#129

Earlier quoted context omitted.

There might be a suit brought on behalf of one of these reporters and/or their employer arguing that the implication of consequences from such a powerful entity without a court order constitutes illegal interference with their business, possibly entitling them to some damages, and more importantly, establishing some very important precedent which might prevent the TSA from ever attempting such a stunt in the future.…

You are not familiar with Sovereign Immunity. No lawyer in the world salivates at the thought of suing the federal government.

Maybe you're not familiar with the Federal Tort Claims Act, which provides a waiver for the federal government's immunity in the case that a federal employee has been shown to have caused wrongful damage.

Re: TSA Pressures Mainstream Media Not To Cover Story

#130
post #63

The term "security theater" has been tossed around a lot, but I think it's pretty clearly coming to that. Asking the mainstream media not to cover something like this is completely indefensible from a security standpoint - what, terrorists only learn about security flaws from TV?. It's pretty patently only about keeping their budget. Also, just going to throw this out there, but it is fairly possible that the email i…

No. It's not "coming to that". We're well past the security theater stage, and into the nightmare stage. Even hinting that any media not cover this or ANY story is so, so far beyond the purview of TSA that it is shocking (or should be shocking—it has become rather hard to be shocked by TSA) that they would even consider pulling this. The Supreme Court should slap them so hard that their acronym gets mixed up. This is…

> No. It's not "coming to that". We're well past the security theater stage, and into the nightmare stage.

If you want to stick to the theatrical vocabulary while being pedantic, you could talk about security phantasmagoria

Post reply on HN