Bruce Schneier | |||||||||||||||
Schneier on SecurityA blog covering security and security technology. « The Neuroscience of Cons | Main | Skein and SHA-3 News » November 18, 2008Schneier for TSA AdministratorIt's been suggested. For the record, I don't want the job. Since the election, the newspapers and Internet have been flooded with unsolicited advice for President-elect Barack Obama. I'll go ahead and add mine. Although I'd be happy to see either Jim or John with it. I don't want it because it's too narrow. I think the right thing for the government to do is to give the TSA a lot less money. I'd rather they defend against the broad threat of terrorism than focus on the narrow threat of airplane terrorism, and I'd rather they defend against the myriad of threats that face our society than focus on the singular threat of terrorism. But the head of the TSA can't have those opinions; he has to take the money he's given and perform the specific function he's assigned to perform. Not very much fun, really. But I'd be happy to advise whoever Obama choses to head the TSA. The job of the nation's CTO would be more interesting, but I don't think I want it, either. (Have you seen the screening process?) Posted on November 18, 2008 at 1:46 PM • 63 Comments To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. Actually, I nominated you for head of Homeland Security. I agree, you need a much more far-reaching office to deal with the inanities of American Security Theatre. Sadly, you inability to write a book endorsed by Oprah is proving to be a major stumbling block. Posted by: Fred X. Quimby at November 18, 2008 2:20 PM Pournelle's Iron Law of Bureacracy strikes again! The vetting process will eventually eliminate anyone who has ever done anything! You certainly can't game the system any more. Zoe Baird and Kimba Wood proved that. "The purpose of government is to hire and pay government workers." Posted by: BobW at November 18, 2008 2:29 PM @Quimby: Posted by: RH at November 18, 2008 2:38 PM I don't want you as TSA Admin - I want you as the head of DHS. Posted by: Tom at November 18, 2008 2:48 PM I find it heartening that the current administration is proposing a Chief Officer and not a czar. Subtle but better. And Bruce, the world could use your advice in a more official capacity. I'll second the idea that you should reconsider if a post is offered. The stupidity of the process is overshadowed by the good that you could do in the position. Posted by: Matt Simmons at November 18, 2008 2:50 PM In all honesty, it is probably far more difficult than any of us critics viewing limited information from the comfort of our offices would like to admit. I think the liquids ban, for example, is mostly theatre against terrorism, since terrorists will find another way (probably not involving planes next time). That said, if some novice copycat that has lost his marbels was to blow up something on a single plane resulting in a highly publicized incident and great financial loss due to customer fear, I'd really hate to be the guy on the hot seat trying to explain why we ignored a previously published risk even if my defense was the absolutely correct assessment that it wasn't worth it. Please don't take that as me saying things are efficient. I think a great deal of scrutiny is deserved, but we should also concede that while they are inefficiently doing a job, it is probably not as easy of a job as we may think. I'm glad this is the internet, so I don't have to duck! *grin* Posted by: John at November 18, 2008 2:52 PM Being considered for this sort of thing must be heady stuff, but if you do get some kind of offer, think about it very carefully. The Federal TLA bureacracies have a way of eating up outsiders brought in to lead them, and spitting out the clean-picked bones. Remember Les Aspin, the professorial defense intellectual, who went to DOD, and discovered he couldn't get them to do anything he wanted? No offense, Bruce, but you've never run anything big enough to have a good feel for what running something like TSA would be like. If the Obama administration should succeed in talking you into some kind of senior role, make sure you bring along an experienced bureaucratic infighter with whom you see eye-to-eye, to ride shotgun for you. Posted by: Carlo Graziani at November 18, 2008 3:00 PM From the article quote: "And please, whatever you do, resist the temptation to let TSA workers unionize. Security from terror attacks should be a federal jobs program. You need the authority to fire underperforming screeners quickly and effortlessly." It's not surprising to see a Fox News commentator take a cheap shot at unions. Unions and professional organizations represent millions of emergency and security workers, from cops through doctors. And they provide a valuable additional protection against government abuses of power, such as hiring and firing people based on political beliefs or other non performance-related issues. Posted by: Sam Greenfield at November 18, 2008 3:09 PM @Sam Greenfield: I get your point, but Unions do have the unfortunate side effect of making it difficult to fire poor people. That's not to say they do no good, but it is to say it comes with a cost. I don't see where there view being different than yours as a cheap shot on their part. Posted by: John at November 18, 2008 3:20 PM @john agreed @sam greenfield i work in for a division of the federal govt. it is extraordinarily frustrating when someone who is not competent, and does not have the skill to do what they do, and as a result are in a position to harm the public through their ineptitude, cannot be dismissed without going through anywhere from 12 - 24 months of "process" to remove. i agree in protecting worker's rights, but not at the expense of castrating the employer to the detriment of the organization, the public, and the rest of the workers who ARE capable of doing their jobs. to quote dennis miller: "but that's just my opinion... i could be wrong". Posted by: FedGeek at November 18, 2008 3:40 PM @John: "I'd really hate to be the guy on the hot seat trying to explain why we ignored a previously published risk even if my defense was the absolutely correct assessment that it wasn't worth it." Speaking also of hot seats, it can be viewed similarly to the ankle bracelets on babies in hospitals. Infant abdunction is rare, and money is probably better spent on more significant risks (for example, far more babies fall victim to SIDs than abductions). However, nationwide, it may happen. So, if one day the TV is lit up with an alert to find an abduction at another hospital, and I receive a call to come before the board... *queue the darth vader music* Board Hotshot: "What are we doing to prevent infant abduction?" Me: "We have trained our staff and have cameras installed." Board Bigshot: "Why aren't we using bracelets?" Me: "Abduction is rare, and our resources are best used for more common threats. The bracelets aren't worth the money for an unlikely event." Board Hotshot: "What do you mean not worth the money? Have you seen the news? How can you claim it won't happen? Did you get your degree out of a cracker jack box?" Pink slip time. Even though I'm not responsible and I was right. Sad but true. Same could apply to security elsewhere, such as TSA. Posted by: John at November 18, 2008 3:59 PM If you want to directly affect budgeting decisions about who gets how much then I think you would have to run for Congress. Schneier 'N+1 Posted by: peri at November 18, 2008 4:00 PM I want Bruce for Secretary of State. What is diplomacy if not social engineering? And what are treaties if not security policies? Ain't nobody gonna con Bruce. Posted by: Tangerine Blue at November 18, 2008 4:05 PM Bruce is best speaking truth to power. He's a generalist in a specialized field. He shouldn't be head of a government department. Not yet, anyway. But he should be on advisory panels. Posted by: Baron Dave Romm at November 18, 2008 4:17 PM Anyone who *wants* to become head of the TSA is incapable, by definition. Posted by: Jurjen at November 18, 2008 4:29 PM The Department of Homeland Security should be disbanded. We already have a Department of Defense that is charged with protecting the homeland. The best placement for Bruce Schneier is that he remain where he is now. He is on the outside and has freedom to criticize. Posted by: Eric Norman at November 18, 2008 4:36 PM >> You need the authority to fire underperforming screeners quickly and effortlessly. I hate to point this out, but this is one strong advantage of contract security. You can't fire an underachiever. But you can pick up the phone and require that they be replaced. Today. So why did Globe Aviation, owned by Securitas AB, not detect the hijackers at Logan airport in Boston? Among other lapses, FAA regulations permitted passengers to bring blades less than four inches long through security. If you buy cheap security, don't be surprised at what you get. If you don't exercise intelligent oversight and management, you are merely throwing away money regardless of what kind of security you think you're buying. I don't see how making airport security a Federal monopoly-bureaucracy has helped matters any. I shudder at the thought of TSA unions. Posted by: Andrew at November 18, 2008 5:10 PM I agree with Eric Norman that the DHS should be disbanded, it's a complete boondoggle from the top down. The entire intelligence community including the respective roles of the pre-existing agencies needs a complete overhaul. Hercules needs to reroute the Potomac through the Pentagon one time, if you get my drift. I don't agree that Bruce would be more effective on the outside, although from a personal perspective he's definitely better off there. On the inside, he'd be able to better ax the deadwood (on both a policy and personnel level). The only problems are that he would have to deal with a lot of sordid stuff, and eventually he'd be at risk for one of those mysterious "accidents" or "suicides" because he WOULD blow the lid completely off any real nastiness he found if he felt the American public would be better off knowing about it. Posted by: Trichinosis USA at November 18, 2008 6:18 PM Board Bigshot: "Why aren't we using bracelets?" Me: "Abduction is rare, and our resources are best used for more common threats. The bracelets aren't worth the money for an unlikely event." SomeSmartGuy: "The money we saved by not using bracelets was used to save the lives of more than 10 critically ill babies. Do you want to kill 10 babies to save one? Are you a babykiller, sir?" Posted by: SumDumGuy at November 18, 2008 6:26 PM "Although I'd be happy to see either Jim or John with it." that's not very nice Bruce to throw away the poisoned apple ;). Posted by: Esurnir at November 18, 2008 7:00 PM @SomeSmartGuy: "The money we saved by not using bracelets was used to save the lives of more than 10 critically ill babies. Do you want to kill 10 babies to save one? Are you a babykiller, sir?" That would be true, but that probably wouldn't shush a bigshot looking for good pr. Posted by: John at November 18, 2008 7:41 PM How about Bruce Schneier Director of NSA/CSS? @eric Posted by: Caleb D at November 18, 2008 9:01 PM The "securitiy theater" of the TSA is a direct result of the "government theater" of the government. The head of TSA isn't there to form a truly effective deterrent; he is the performance director appointed by Congress. Posted by: Andrew Garland at November 18, 2008 9:08 PM "And please, whatever you do, resist the temptation to let TSA workers unionize." In a letter to the president of the AFL-CIO before the election, Obama already pledged to support "collective bargaining rights" for TSA employees. He also promised: "As President, I will make sure that the documented waste and mismanagement at TSA is subject to the same rules regarding contracting as other federal agencies. This year, TSA gave an enormous $1.2 billion sole source contract for human resources services without regard to the rules that require them to allow current TSA employees to compete for that work." Posted by: natenido at November 18, 2008 9:24 PM bruce, i say they create a chief marketing/pr officer for the TSA. you'd be ideal for creating the message, explaining the nuances and meaning, as well as fielding feedback. leave the ongoing maintenance/details to ops. Posted by: Davi Ottenheimer at November 18, 2008 9:50 PM I had John Mueller as a professor at Ohio State. He is one cankerous SOB, but right about the over stated threat of terrorism. I have some insight into security theater as I am Loss Prevention Manager for a major corporation. We utilize EAS tags, however we do not have the EAS towers at the doors. Even if we did, I could not stop a customer for the beep alone. Security theater pure and simple and besides they do not stop the professional thieves. The TSA acts very much like the EAS tags I am forced to use. They stop just enough amateur plots to justify the investment when it is the professionals that we should attempt to detect through intelligence. The TSA was never designed to stop professional terrorists. Posted by: Buckeye at November 18, 2008 11:38 PM What most commenters appear to have missed is the primary job function of any appointies job. It is effectivly hidden away in the, 63rd is all-encompassing question, "Please provide any other information, including information about other members of your family, that could suggest a conflict of interest or be a possible source of embarrassment to you, your family, or the president-elect." Of which the only important bit is, " ...source of embarrassment to... ...the president-elect." That is without doubt the soul selling job requirment that would enslave an (outsider) appointee. It has sealed the fate of anybody trying to make changes that the (insider) "unelected officials" don't like. They simply make a few phone calls to "friends outside" who then engineer a situation. When the time is right said official then "pulls the fat out of the fire" but in return require their policy endorsed (this is of course a gross over simplification of what an astute insider political operator would do by proxie through their established power base). The only thing of real interest to these "unelected officials" is "turf". As an "outsider" brought in it is unlikley that you would have a protective powerbase "inside". Therefore you end up in a "do as we say to keep the job" position. There is nothing quite as corupt as a "Well respected official" on the inside. If the President-elect is serious about reform then he must accept that to do the required decapitation job you need people with proven ability which means they have blood on their hands... Posted by: Clive Robinson at November 19, 2008 12:48 AM There is leadership, management, and consultancy and they differ. IMHO Bruce would make a solid consultant to the leadership, but wasted as management. The TSA in particular is an object lesson in waste management. ;) Posted by: Bill at November 19, 2008 4:07 AM Well, perhaps the notion that the head of a department should defend and expand its budget should also be turned on its head. Proudly announce that, if appointed, your goal will be to halve the TSA's budget with no reduction in quality. See what happens. It should be a safe claim, since reductions in quality would be impossible to achieve in any case. Posted by: Richard Braakman at November 19, 2008 5:12 AM "...Security from terror attacks should be a federal jobs program." Actually, the original article had an extremely significant "not" in there. And I would be surprised to hear Bruce say otherwise. [if for no other reason than blogs dont have voices] Posted by: bob at November 19, 2008 6:48 AM I kind of wish he would take the job. I've always wanted to see the self-proclaimed best quarterbacks (the Monday morning quarterbacks) suit up and show us how it is done. Posted by: Bob at November 19, 2008 7:36 AM Andrew saith: "So why did Globe Aviation, owned by Securitas AB, not detect the hijackers at Logan airport in Boston? Among other lapses, FAA regulations permitted passengers to bring blades less than four inches long through security. If you buy cheap security, don't be surprised at what you get." Wait, so, you're blaming the hijackers getting through Logan airport security on the contract security guards not preventing the hijackers from bringing something they were allowed to bring on the plane, onto the plane? For the record, I flew with a knife on September 10th. We will note that no planes were hijacked that day. If I'd been flying a day later, and out of the right airport... well, who knows what would have been the outcome. (Yeah, yeah, I know, internet commando talk.) Posted by: perlhaqr at November 19, 2008 7:57 AM You have misquoted Mr. Balko's piece at the FoxNews website. He says "Security from terror attacks should not be a federal jobs program.", but your version leaves out the "not". Posted by: dprovine at November 19, 2008 8:07 AM > Among other lapses, FAA regulations permitted passengers to bring blades less than four inches long through security. 1) This is, as you say, a reg not an independent decision by the contractor. 2) How is it a lapse? I carried a small knife on a/c a lot before the bans-on-everything, and hardly ever took over the plane with it. The will (and perhaps lack of threat understanding of an a/c takeover by everyone else) is more important than the tool. Posted by: Steven Hoober at November 19, 2008 8:33 AM >2) How is it a lapse? I carried a small >knife on a/c a lot before the bans-on->everything, and hardly ever took over >the plane with it. The will (and perhaps >lack of threat understanding of an a/c >takeover by everyone else) is more >important than the tool. Thank you Steven. I always carry a pocketknife and have always used it as a tool and never a weapon. Before 9/11 I used to put it in the little basket and go right on through security with it. Now the process has changed a little. I can't be trusted with my pocketknife on the plane, so I put it in my checked bag, TSA steals it out of my check bag - sometimes leaving a nice note, and subsequently sells it on Ebay. But we're all safer for it I'm sure! Interestingly, Titanium doesn't set off the metal detector, so I never get tackled for wearing my watch. Posted by: Zip7 at November 19, 2008 11:10 AM @perhaqr: "Wait, so, you're blaming the hijackers getting through Logan airport security on the contract security guards not preventing the hijackers from bringing something they were allowed to bring on the plane, onto the plane?" Good point. On one hand, a terrorist can try 100 times to get a bottle of liquids on the plane with no consequence (they throw it away, no concern). On the other, since it was published that terrorists tried to take down a plane using bottles of liquids, some idiot not affliated with any organized terror, perhaps a McVeight style nut job, may in fact blow himself up by copying what he read in the paper. It seems having the liquid ban is ineffective against terrorism (since there is no consequence, and organized terrorism will find another way), but not having it may not be the best either. It only takes one nut job that we have no reason to be afraid of to do damage on one plane and the whole industry is damaged. I personally think the liquids ban would be more effective if every confiscated liquid was bagged and tagged (with information about the person who confiscated it), giving some means to trace it back if it was in fact found to be something dangerous. Then again, that no doubt has holes as well. No easy answers. Posted by: John at November 19, 2008 11:11 AM In regards to the pocket knife discussion, I used to have one on my key ring as well. Thousands do and never taken over a plane. However, after 9/11, considering PR, reputation, and passengers feeling of security (not necessarily security in itself), what decision-maker in their right mind would want to tell the public they aren't concerned with small knives so long as the cockpit door is secured? Sometimes, as we've read in columns on this site, a little theater is good for business at times since you need passengers to feel secure to get to buy products (be it packaged foods they fear may be poisoned, hospital choice when they fear their baby may be abducted, or airline travel if they freak out when they see a 1 inch blade on a key ring). There are costs both ways. Posted by: John at November 19, 2008 11:17 AM > But I'd be happy to advise whoever Obama choses to head the TSA. Having already said that the head of the TSA has too little scope for action, this seems an incomplete option. If you've the opportunity to advise Obama regarding who to head the TSA, you'd also be able to opine about the TSA itself. Were the opportunity to present itself, you'd come close to your goals by changing the straight jacket, not the wearer. Posted by: Mel at November 19, 2008 12:02 PM Rather than taking a position, bringing you in as a consultant in an adviser role might be the better solution. Posted by: Steve C at November 19, 2008 12:14 PM Dear Mr. Schneier, with all due respect to your decision about the position as head of the TSA, please allow me to ask You to reconsider. If you take the position, it would only take half a day to shut down and disband TSA, thus ending a waste of taxpayer money and needless inconvenience to travellers all across the nation. You could take the rest of the day off and relax. On the following day, you could return to BT Counterpane and do something productive and useful. :-) Posted by: doppelfish at November 19, 2008 2:13 PM Too bad. We need qualified people up there. We also need to figure out a good copyright czar, lest we get left with an industry hack. Posted by: Moe at November 19, 2008 2:17 PM @doppelfish If you think the TSA has no purpose, you are mistaken. Inefficent? Yes. Too much theater, yes, even though to comfort a jittery public may be more necessary than we care to admit. Your post seems more a cheap shot than anything. The TSA needs reassessed, not removed, in my humble opinion. Posted by: John at November 19, 2008 2:31 PM Mr. Schneier, Posted by: Arash at November 19, 2008 4:19 PM @Buckeye - "I had John Mueller as a professor at Ohio State. He is one cankerous SOB" Ewwww. Oh, wait - did you mean "cantankerous"? Posted by: Chris S at November 19, 2008 4:36 PM @Zip7 It depends on the amount of Ti and the sensativity of a reader, however it can be detected. Posted by: Eric at November 19, 2008 6:33 PM "It's not surprising to see a Fox News commentator take a cheap shot at unions." Posted by: hwertz at November 19, 2008 9:28 PM "On the other, since it was published that terrorists tried to take down a plane using bottles of liquids, some idiot not affliated with any organized terror, perhaps a McVeight style nut job, may in fact blow himself up by copying what he read in the paper." Posted by: hwertz at November 19, 2008 9:37 PM @hwerz Fair enough. I'm not saying its always rational. I'm just saying there is more to consider. While a person is generally intelligent and can be reasoned with, people as a whole are panicky and unpredicatable. It's similar to what Bruce wrote about infant bracelets as a poor control--a mother that heard of infant abduction the day before her birth needs to feel safe letting her baby out of her site. Likewise, many people that heard of shoe bombs or liquid explosive attempts may likewise need to feel a bit safer. As a security professional, I've often dealt with the difference between rationalizing with a person and trying to deal with people. It is surprisingly different. Posted by: John at November 20, 2008 8:58 AM I'd rather see the TSA eliminated. Give the job to the Coast Guard. They protect our waterways, why not our airways? Their basic mandate is keeping civilians safe. They do have civilian law enforcement duties in boating safety regulations, so it wouldn't seem as though we were becoming a scary a police state as it would if Marines were checking your carry on luggage. And the Coast Guard doesn't have a reputation for frivolous regulations or "security theater". The Coast Guard has no union representation. You also would not have anyone working the job for so many years they become burned out by it. Posted by: Tom M at November 20, 2008 10:11 AM Here's another example of security theater being turned into a positive public danger: Easyjet's response at the end is particularly humorous. Posted by: kangaroo at November 20, 2008 12:33 PM I always find this railing against unions humorous (and simply stupid). Why this assumption that the "firer" is competent? That giving people at upper administrative levels a free hand is likely to lead to good results, while give people at a lower administrative level a free hand is likely to lead to incompetence? It's particularly funny when you consider that most of these buffoons will simultaneously complain about the incompetence and malice of upper administrative levels, often going to the "black helicopter" edge. Everywhere is fantasy land. Posted by: kangaroo at November 20, 2008 12:45 PM Unionizing this would be terrible. I've noticed that when your job is solid, you slip; when I make mistakes at my job, I pretty much handwave it away because 1) if I break something, I fix it, and nobody cares; and 2) at the end of my shift, if there's something that should be done, my shift's over and I can walk off with no responsibility. I've done both a couple times but my conscience and personal integrity gets to me. The unionized cleaning staff here, however, is useless. We call them to do something, and 5 hours later they didn't do it. Once this had to do with removing hazardous objects (broken glass) from an area; they didn't come to do it at all, and when they got called and asked a second time because "nobody has come up yet" they sent someone up first to argue with us, who spent about 20 minutes explaining that "it's not that it wasn't done; it just wasn't done -well- according to what -you- want." We got chewed out about how we're NEVER to say that maintenance and cleaning "didn't" do something. Then someone else came up 2 hours later. Other things we've reported have gone completely ignored. I could imagine being a union worker at a TSA checkpoint. I'd probably just wave a wand at things, and stare vacantly at a screen; no knife, but "suspicious" objects that don't fall strictly into the list? Pff, why do I care? I'm not getting metered for this, I get a paycheck as long as I stare blankly at the screen. They can't fire me anyway, I can complain to my union. Posted by: John at November 21, 2008 7:50 PM Why think small? Schneier for National Security Advisor. Posted by: John David Galt at November 22, 2008 1:45 PM While I agree that Bruce would make a great, positive splash at or any national security agency, much of what he describes as "security theater" performed by the TSA is mandated by law. He couldn't stop screening if he wanted to. That being said, it would be amazing to see what he would be able to do! I think his offer to advise the next Administrator is exciting and will afford him the opportunity to affect change without compromising his creative thinking. Posted by: Anthony Amore at November 30, 2008 8:42 AM re: CTO and screening process... Dear Bruce, I hope you reconsider on the CTO thing. I doubt Hillary Clinton went through the intense screening process described by the NYT. Or Rahm Emanuel? That process is for cold calls. I'm guessing that a highly qualified and vetted individual such as yourself could fairly easily get an opportunity to talk seriously about a job without (or at least before) such an invasive process. Now of course, once in public office, life changes a lot. But you're already more famous than Chuck Norris. =) Posted by: Will at December 2, 2008 9:44 AM If it was up to you, you would get rid of all unions, including police, fire, paramedic, customs, imigration and border patrol and replace them all with private contracted firms, that way you and all your corporate buddies could have a field day with all our tax payers money. Posted by: Edthetraveler at December 9, 2008 3:12 AM Edthetraveler, if that rant was directed at Bruce, you need to read more carefully. If it was directed at someone else, you need to write more carefully. Either way, it would help if you hit return twice between paragraphs. Posted by: Moderator at December 9, 2008 4:15 PM Dear Mr. Moderator, If the shoe fits, wear it. Here's your hit return twice, for ya! Sincerely, Posted by: Edthetraveler at December 9, 2008 11:37 PM Post a comment
Powered by Movable Type. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments