"Clear" Air-Travel Pass Data Stolen From SFO
Kozar_The_Malignant writes "A laptop containing the unencrypted security data for 33,000 travelers using the Clear system was stolen at San Francisco International Airport on July 26, according to CBS5 Television. The Clear system allows travelers who register and pay a $100.00 annual fee to speed through airport security by using a smart card at special kiosks in some airports. TSA has suspended new registrations in the system, which is run by a private contractor, Verified Identity Pass, Inc., a subsidiary of GE. The laptop was apparently stolen from a locked office at SFO. The company has now decided that it might be a good idea to encrypt the data in their systems. They are in the process of notifying customers that all of their personal data, including name, address, SSi number, passport number, date of birth, etc. has been compromised."
To have a company intimately involved with *security* not apparently able to manage their own security in a manner that protects the country and their customers is a joke. Fine... having a laptop stolen is common enough and I don't fault them, but having unencrypted data of 33,000 of your customers on that laptop is a crime.
I never liked the idea of handing over private information in the security theatre that our nation has become, but events like this where private companies motivated by the lowest common denominator really get under ones skin. Why the data was stored in unencrypted formats is inexcusable. I don't know what the penalty should be for something like this, but it should be commensurate with the potential damage it could cause.
The whole point of outsourcing information and jobs like this to the private sector is to get the job done better and more efficiently. When the government then has to police these private companies like the TSA is apparently having to now do, the concept is made moot. So.... our options are to continue to live the security theatre with private companies like this or turn the job back over to the government (who's job it to ensure safety of travel and should not have been in the business of verifying identity for air travel anyway).
Or... we could go back to the way things were when I could carry pocket knives on planes. (I also remember when you could carry long guns on planes back in the late 80's/early 90's.)
Visit Jonesblog and say hello.
... especially since at my workplace, they are starting to think about encryption laptop hard drives, that contain personal information about government related investigations related to people working without permits and that kind of deal.
The thing is, though, they're only encrypting the new tablet PCs we just bought, not the older Thinkpads we used - And the database is imported from the web, which means the unencrypted laptops contain the same data the encrypted ones do...
I have a feeling we'll see even more of these in the near future.
Assuming this system allows them to reliably identify a person, so what? Do they do extensive background checks and continuous monitoring to ensure that the people aren't involved in terrorism? Or if I have no obvious problems in my background and enough money to pay for it, can I get treated differently too?
Does it basically come down to people paying to not have to stand in line with the rest of humanity at the airport?
I'm becoming quite skeptical about this whole 'stolen laptop' B.S. After the first few big news stories, I'd expect most corporations to have strict guidelines in place to prevent this sort of thing. And a policy of coming down hard, very hard, on violators.
I wonder how much one can get per personnal record for selling this sort of data to organized crime. And cover your ass by reporting a stolen laptop.
Have gnu, will travel.
I was just thinking earlier today of signing up for that. I do a lot of travel and thought the cost might be worth it to cut down on wait time. Guess not.
Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
The company has now decided that it might be a good idea to encrypt the data in their systems.
NOW? They're NOW deciding that it might be a good idea to encrypt the data? Ok, I don't work in the industry and all but even I, as an uneducated outsider, knows that it's a good idea to encrypt that sort of data. Jebus... That should have been one of the first priorities in developing their systems and procedures...
Back up there. For all you know, there were people within the company who were calling for proper security controls but were ignored. That's certainly what happened at my last job: our IT team continually raised the subject of full-disc encryption on laptops and we were continually ignored, right up until a laptop with a demo version of our software was stolen from a trade show. Apparently that was high-profile enough that the board of directors finally woke up and ordered full-disc encryption for every laptop, although of course by then it was too late.
Mod parent up.
Another thing - suppose this laptop is recovered, and someone has added some names and data to the DB - ones that can be later used as covers?
Well, not only that, but shouldn't that laptop have a tracing program on it? One of those services that helps you find the stolen laptop?
A new security industry created by the government's drive to snoop in all our lives has proven exactly why no one is to be trusted with your ID info. period. Makes you wonder who the real terrorists are? Bin Laden must be laughing his last lung out.
The weakest link in your security is always a human and since humans work for the NSA, DHS et al, there is NO reason to trust them with anyone's data never mind your own.
Before 9/11 this would not have happened because this business would not have existed. There is no justification for it's existence that makes any logical sense at all.
Support NYCountryLawyer RIAA vs People
I wonder how that number is affected when one considers that the government is more likely to be required to report these types of crimes whereas a private company is not (for the most part).
-- Humans, because the hardware IS the software.
Exactly. Why is my Social Security number needed to purchase a cell phone and contract? Does my insurance company need it? Why do credit checks have to be run for everything nowadays? I would honestly prefer giving something like my fingerprint at the store, as long as the employee also had to give theirs, as a way of certifing "yes, they pressed their thumb, I watched them, and they were not coerced".
I think that the best thing that can happen is that more ID's are stolen, as in millions, as in IRS or some states database. If they can no longer be trusted, they will no longer be used..
What are we going to do tonight Brain?
Honestly, I think it's time to institute a punishment for a corporation, the most severe punishment that can happen to something that can't be thrown in jail.. Revoke their charter, and nullify the entire company. The corporate death penalty, if you will.
If it happens more often, companies will start to realize that this isn't a matter of getting fined, which their insurance will cover, and their rates will go up a little, but that the company will no longer exist, and can't write paychecks, can't purchase goods, can't deposit money, and their assetts will be sold off to the highest bidder. Might make them a little more "caring" about important issues..
What are we going to do tonight Brain?
It's possible that is an "inside job", rather than an opportunistic theft. I mean, the laptop could have been "stolen to order". Identity criminals are getting more organised. Who knows what other data was on that laptop, given that it was being used by a security professional.
Everybody assumes that this data would go to criminals for use in ID theft mischief. What if terrorists used it to program their own Smart cards in order to "speed through airport security"?
You expect commercial interests to do dumb stuff like this out of greed or incompetence. Accordingly, the fact that TSA/DHS didn't certify this company's procedures tells you something about their competence/security.
The only reasonable thing that they did after 9/11 was lock the cockpit doors. Everything else is BS designed to make you think that they're doing something useful.