Bruce Schneier | |||||||||
Schneier on SecurityA blog covering security and security technology. « Conversation with Kip Hawley, TSA Administrator (Part 4) | Main | Face Recognition Test Results » August 2, 2007Security Hole at Phoenix AirportThe news: We've discovered a 4.5 hour time frame each night when virtually anything can be brought into the secure side of Phoenix Sky Harbor Airport. There's no metal detector, no X-ray machine, and it's apparently not a problem. I have mixed feelings about this story. On the one hand, it's a big security hole that not everyone knew was there. On the other hand, airport employees are allowed to bring stuff in and out of airports without screening all the time. So yes, the airports aren't secure -- but they never have been, so what's the big deal? The real issue here is that people don't understand that an airport is a complex system and that securing it means more than passenger screening. Posted on August 2, 2007 at 11:35 AM • 15 Comments • View Blog Reactions To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. Not only is it a huge vulnerability, but it is a significant one that has never been really closed: I wish you asked Kip Hawley the question of: Why did the TSA for so long resist scanning all ground crew, when this vulnerability has been responsible for both the PSA flight 1771 crash in 1987 and the terrorist hijacking in Algeria? If you are going to do CYA security, I think this is a critical one. Posted by: Nicholas Weaver at August 2, 2007 12:04 PM Phoenix Mayor Phil Gordon gave an interview shortly after this went public. His demeanor toward the reporter was very disturbing to say the least. In it, he staunchly defended the security measures in place as being more than adequate. He gave almost no straight answers to the questions about the lack of searches and attacked the security consultants as having a greedy agenda. Since then they've taken steps to correct the measures. I don't know that he's given a public statement and even if he did I doubt you could hear anything over the sound of backpedaling. http://phoenix.gov/skyharborairport/customer_service/press-announcements.html Posted by: Boston at August 2, 2007 12:13 PM I allways asked, how you could avoid smuggling "dangerous liquids" to duty-free shops. Closing every hole is too expensive. Posted by: Stefan Wagner at August 2, 2007 12:17 PM @Stefan Wagner That is why the TSA tries to pass the expense off onto the travelers. How many hours are wasted each year at the airport? Time is money. Security is about the evaluation of threats and reducing their effectiveness. What we have is cheap, reactive "security theatre". Posted by: Brandioch Conner at August 2, 2007 1:03 PM This is utterly, utterly nothing new - it's a classic version of the idea that the best time to launch an attack is while the defenders are changing the guard, or "send out masses of spam while your ISP's abuse-desk is on night-shift". Posted by: Tanuki at August 2, 2007 1:42 PM I'd be most annoyed learning this if I was a scrupulous day-shift employee. I once (travelling lots, cannot recall the city) saw the TSA guys bringing a TV monitor and a bunch of office supplies fresh from the store thru their x-ray machine. The employee who brought the stuff to screening hung around, not interfering, while they were screened by other staff. Once passed, they deployed the pens and postits to be used (the TV was some secondary monitor for the X-ray machine also). Yes, they screened stuff to be used only inches inside the secure zone, because that's what the regs say to do. Those TSA employees were at least trying. Too bad every other part of the system (and it continues to see, the system itself) is failing them. Posted by: shoobe01 at August 2, 2007 1:53 PM I've been wondering for a long time what will happen when a baggage handler goes over to the Dark Side, adds a package of his own, and a plane blows up as a result. Posted by: Roxanne at August 2, 2007 3:51 PM Can I suggest.... part 6 to the 5 part series? TSA knew about it for 2 years and did what? Posted by: gulfie at August 2, 2007 6:20 PM This is all an artifact of the airlines being forced to pay for security, and not really caring what happens as long as someone else can be blamed for it. I sympathize with the guards. What do you do, stay alert when you have authority to do NOTHING, or slink off and try to hide and curse the scheduler for sticking you on such a horrible post? I have always found it interesting that banks and airports have such poor security, and many other non-regulated sites have excellent security. I think the poor security is an artifact of the level of regulation . . . the security rises to the level of regulation, and no further. Ridiculous levels of regulation are required for nuclear power plants, to achieve barely effective security. (Barely == cost effective, I might add, so blame the utilities for that one.) Posted by: Andrew at August 2, 2007 7:02 PM I have wondered how restaurants in the "secure area" could work with full-size kitchen knives. I have seen them on several occasions. Posted by: MathFox at August 3, 2007 3:48 AM @MathFox: "restaurants in the "secure area" (...) with full-size kitchen knives" Well, they don't give them to you. Along with your meal, you get plastic knives. I assume, once they discover theft of a knive, they will alert security which will evacuate the secure area so that everybody can be re-screened. Posted by: Paeniteo at August 3, 2007 6:54 AM @MathFox: "full-size kitchen knives" Good point, the knives are there and all you need is an accomplice on the kitchen staff. But, nothing is perfect and screening people for knives makes it harder (not impossible) to get a knife on board. Every time you need an accomplice for something it makes the plan more complicated, it makes it harder to execute the plan, it makes it more likely some honest person is going to find out about it and tip off the police, and more likely that the entire plot will fail. The fact that a security technique (screening for knives) is not foolproof doesn't mean that its not a good security policy. Its a cost benefit analysis. Screening for weapons -- good (at least as far as my evaluation). Preventing me from carrying my 20 oz. Diet Mountain Dew -- not so good. Jeff Posted by: jeff at August 3, 2007 8:04 AM Burbank airport, some years ago: after the last flight departs for the night, the security check station is left unmanned. You could bring in whatever weapons you want (wait until there's a late arrival unloading to help mask the op) and hide them in a locker/restroom/etc. for someone to pick up the next day. Is it still that way? Beats me, but after this article I wouldn't be surprised at all. Posted by: Grumpy Physicist at August 3, 2007 8:09 AM For the most part TSA Officers are dedicated and efficient, they are crapped upon by piss poor management practices, they are stretched out so thin, that they operate below “Skeleton Crew Levelsâ€?, causing a highly overworked security force that is fatigued, and then becoming inattentive and unaware of their surroundings. If, T S A’s human resources department would attempt to have more knowledge of security and properly investigate operations around the country and at least reduce these issues by about 40%, our security would increase over 70% just by causing an improvement in the moral of the work force. Posted by: wild_guard_2020 at August 18, 2007 12:55 AM If you want something done, you can do it. It doesn't matter if the hole is 4.5 hours or minutes. In just reading the last ten posts I heard a variety of items described that I could use to due horribly nefarious things with. The name of the game is conviction. If someone wants it done bad enough, it will happen. The idea is to get it closed up before something does happen. It is the reason the other 19.5 hrs of the day are watchdogged, not for some quasi-political, number-crunching nonsense. Posted by: Steve Canyon at September 1, 2007 12:43 PM Post a comment
Powered by Movable Type 3.36. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments