Showing posts with label airline security. Show all posts
Showing posts with label airline security. Show all posts

05 November 2008

Ads At TSA Airport Security Checkpoints : Should They Be For Sale?

Web: www.thetravelstrategist.com -- E-Mail: fish@flyingwithfish.com

5/11/2008 – Ads At TSA Airport Security Checkpoints : Should They Be For Sale?

Over the past year the U.S. Department of Homeland Security's Transportation Security Administration (TSA) has experimented with selling advertising space at 14 airports through out the United States. As this year long advertising experiment concludes, and the TSA moves to roll out this option throughout the United States. I feel this program gives the impression that the United States Government's first line of defense, for the security of those traveling in the United States, is for sale.

The security of the traveling public, which is a serious and challenging task, should not have perception of corporate influence. Many look at this program as something that is not a big deal. The TSA provides ad space, through Security Point Media, on the bottom of the checkpoint personal item bins, as well as on the tops of the tables leading up to the x-ray machine. If security was a private entity, or if it was owned by the airport authority, I would not give the advertising scheme a second thought.......but its not, security is maintained by the United States Department of Homeland Security's Transportation Security Administration.

Given that security is a branch of the Federal Government, under the Department of Homeland Security, I believe there should be no mixing security with ad revenue. Under the TSA's current advertising sales scheme the advertisers purchase the bins, bin carts and tables for the TSA. In trade for purchasing these items, the company secures the advertising rights to the tables and the bins.

This may be seen as a 'donation,' such as a volunteer fire department having a small sticker on a truck that reads, "This ambulance donated by XYZ Corp." In other situations this may be seen as a way for a corporation to try and gain political leverage though their financial contribution to a specific federal agency.

The TSA has shown that it has a long way to go in making sure loop holes in security are closed up and that the agency has a genuine interest in securing the traveling public. Diverting its efforts to a program that is counter productive to its image, as well as offering no benefit to security, should be rethought and revisited once the agency has its security issues under control.

What will be next? Will we see ads on passport control stations, and Custom's inspection tables, operated by the Department of Homeland Security's Customs & Border Protection (CBP) Officers?

Security must not only be secure, but it must also give the pure appearance there is no impropriety.

Happy Flying!

24 October 2008

U.S. Flyers Required To Provide Full Name & Date-of-Birth In 2009

Web: www.fishfoto.com -- E-Mail: fish@flyingwithfish.com

24/10/2008 - U.S. Flyers Required To Provide Full Name & Date-of-Birth In 2009

As a flyer I am very much in favour of security.

Let me clarify the above statement.........As a flyer I am very much in favour of effective security.

What I am not in favour of as a flyer, as a US Citizen and as a U.S tax payer, is an ineffective security system that increasingly reminds me of George Orwell’s classic novel "1984," that in return offers the traveling public no additional effective security measures.

Beginning in 2009 flyers in the United States will be required to provide airlines with their full name and date of birth. Currently you can purchase tickets with your first two initials and your last name, and no other information is required, now you'll need to provide first, middle, last name in your reservation.

Homeland Security Secretary Michael Chertoff
has stated that the new rules will dramatically reduce the number of flyers who are mistaken for those on the "No Fly List," which includes those on the terrorist watch list. Given that the "No Fly List" has never caught a terrorist, or come close to catching a terrorist, the Department of Homeland Security (DHS) may want to revamp its security measures in a less invasive manner to those traveling in the United States.

Flyers who fail to provide their full name and date of birth will be unable to print boarding passes at home, or at the airport, for any flight originating or terminating in the United States, as of July 2009. If you fail to provide this information you will be required to check in with an airline's counter agent and provide them with the information.

I do not believe these new security rules will in any way deter a terrorist from purchasing an airline ticket. The new security measures will it certainly not prevent a terrorist from boarding a flight.

As discussed in this post, 20/10/2008 – TSA Rolls Out PDA Based Boarding Pass : A Security Double Standard, anyone with a credit card or debit card can purchase a ticket online with anyone's name on it. Airline tickets can even be purchased with 'Gift Cards’ with a Visa/MasterCard/Amex logo, or an airline's gift card, these cards are not traceable back to the person using them. When the person who intends to use the ticket checks in online they simply create a PDF file of the boarding pass, then save it and import it into Photoshop. Once the PDF is open in Photoshop any name can be entered on the boarding pass. All anyone needs to do is to show proper identification and a boarding pass to get through security.

The Department of Homeland Security should begin the process of making encrypted scan-bars on boarding passes a high priority. An encrypted scan-bar would be virtually impossible to forge and change the name of the passenger using that boarding pass.

Requiring a full name and date of birth of a passenger may reduce the name of false-positives on the 'No Fly List,' but it will not reduce a determined person's ability to do harm should they choose to. There needs to be a more secure system in place......and this new one simply isn't it.

This new system is an attempt to demonstrate security to the public by creating something that sounds viable, but in reality offers nothing. This is the Transportation Security Administration's way of saying "we are focused on security,' when in reality the security loop holes are wide open and glaring.

TSA Chief Kip Hawley is quoted as saying "You have to give this information." I'd like to reply to Mr. Hawley’s quote and say "You have to provide us with valid and well planned out security measures for the flying public."

Happy Flying!

21 October 2008

Mail From United Airlines That I Wish Was True : New Scam To Steal Frequent Flyer Miles

Web: www.fishfoto.com -- E-Mail: fish@flyingwithfish.com

21/10/2008 – Mail From United Airlines That I Wish Was True : New Scam To Steal Frequent Flyer Miles

This morning I went to my PO Box to pick up my mail. My mail had the usual bills, a few catalogs and an envelope from United Airlines.

Inside the envelope was a single piece of paper with only the following information, in addition to my name and address

Frischling/Steven Mr.

03 Dec 08
Swiss 345 Coach Class
Lv: Lon / Heathrow 600a nonstop Confirmed
Ar: Zurich 835a
Snack

04 Dec 08
Swiss 1248 Coach Class
Lv: Zurich 650a nonstop Confirmed
Ar: Stkhlm/Arlanda 915a
Snack

05 Dec 08
Lufthansa 3001 Coach Class
Lv: Stkhlm/Arlanda 1005a nonstop Confirmed
Ar: Frankfurt 1215p
Snack

06 Dec 08
Lufthansa 3258 Coach Class
Lv: Frankfurt 820a nonstop Confirmed
Ar: Prague 925a
Snack

07 Dec 08
Swiss 1485 Coach Class Operated By-Helvetic Airways
Lv: Prague 950a nonstop Confirmed
Ar: Zurich 1110a
Snack

07 Dec 08
Swiss 638 Coach Class
Lv: Zurich 1235p nonstop Confirmed
Ar: Paris/DeGaulle 155p
Snack


I read this over and at first I said "Great!" Then of course reality set in when I noticed three glaring problems with receiving this itinerary in the mail.

Problem #1 : My frequent flyer number was no where to be found in the info

Problem #2: The itinerary showed no flights getting me to London or home from Paris

Problem #3: This was NOT my itinerary.

Of course the fact that this was not my itinerary should have been "Problem #1" and eliminated problems #2 and #3, but sometimes you have to just say "Hey, maybe they made a mistake and this is mine!"

After a 15-minute call with United Airlines I learned that this reservation was made on the 15th of October. The person who made the reservation had my old address, with a business phone number I have listed in various places online.

When the reservation was made, who ever made it gave incorrect billing information. Despite the incorrect billing information the seats remain "confirmed" without the tickets being issued.

So what is the point in all this? This appears to have been someone's attempt to steal my frequent flyer miles.

By creating a detailed itinerary and having a 'billing problem' whoever made the reservation would then call back in an attempt to get my frequent flyer information. Once they have my frequent flyer information they would call back and attempt to book the flights using my frequent flyer miles.

Anyone doing this would need to travel with my passport right? Wrong!

Flying on a forged boarding pass is not that risky. A flyer can check-in online, create PDFs of the boarding pass, and then insert 'their name' on the boarding pass using Photoshop. To be caught doing this would require someone visually scanning the boarding pass to actually read the name on the boarding pass while also reading the name that pops up on the screen to see if they match at the gate.

How often do gate agents read the name on the boarding pass while also looking at the name that pops up on the boarding pass scanner? Almost never.

Luckily for me, while I fly United Airlines often, nearly all my miles are credited to a Europe based Star Alliance airline. Should the person who made this reservation have pressed forward in an attempt to steal my miles they would not have gotten very far. I have used nearly all my United Mileage Plus miles and only have roughly 21,000 miles in my account.

FYI: 21,000 miles won't even get you an award seat between Washington Dulles (IAD) and Chicago O'Hare (ORD)

I have been in contact with United Airlines. The reservation is cancelled, my information has been flagged and unfortunately I am not spending four days bouncing around Europe.

New scams are created daily, and I am glad United Airlines sent me off this envelope with this itinerary. Without this letter in the mail I would have had no idea someone was created travel itineraries in my name.

For those of you who are known to fly often and rack up a lot of miles, check your accounts once in a while. Make sure all your miles are in your account and no one is trying to take vacations with your hard earned mileage!

Happy Flying!

20 October 2008

TSA Rolls Out PDA Based Boarding Pass : A Security Double Standard

Web: www.thetravelstrategist.com -- E-Mail: fish@flyingwithfish.com

20/10/2008 – TSA Rolls Out PDA Based Boarding Pass : A Security Double Standard

The Transportation Security Administration (TSA) has begin a beta program that allows flyers to download their boarding pass to the Blackberry/iPhone/PDA and skip printing out a paper boarding pass.

When a flyer downloads the boarding pass to their PDA, the electronic boarding pass displays an encrypted bar code that contains the passengers basic travel information. This information includes the passenger’s name and flight information. When the flyer approaches the TSA travel document checker (TDC) the PDA based boarding pass is electronically scanned by a hand-held scanner. The information displayed on the hand-held scanner is then verified against the flyers valid photo identification.

With the ability to create, and alter, boarding passes printed at home (or at the hotel), changing a passengers name to bypass security measures is very easy to accomplish. Shouldn't all boarding passes have this 2-dimensional encrypted barcode?

If a potential flyer is on the 'No Fly' list, who is a legitimate threat to national security, really wants to fly, they will purchase a ticket in the name of someone who is not on the 'No Fly' list.

Once this ‘threat’ has purchased the ticket they will check in online, and get to the print page. Once at the print page they'll create a PDF and import the PDF into Photoshop. In Photoshop they will change the name on the boarding pass to their name. With their name on the boarding pass they can walk up to the TSA's TDC with their legal legitimate photo identification and the forged boarding pass. The names will match and they'll be on their way. Once at the gate they use a non-forged boarding pass and they board the plane.

..........no I am not giving away national security secrets here. What I am discussing is information that the Department of Homeland Security is well aware of.

By implementing a bar-code scanning system through the TSA's travel document checking system it would be extremely difficult to bypass the security measures in place. The system of checking encrypted boarding passes should not be limited to the use of PDA boarding passes at a total of 8 airport checkpoints.

This system is not at 8 airports, but at 8 airport checkpoints, specific to certain airlines. New York's LaGuardia Airport (LGA) for example has approximately 9 TSA check points. The PDA boarding pass program however is only available at one single checkpoint. You can only use the PDA boarding pass in the Delta/Northwest Terminal, and only if you are flying on Delta Airlines (not Northwest Airlines).

We need a secure system to keep a nation in transit safe. A system of positively checking boarding passes should be in place not only in the United States by around the world. A secure system of boarding pass verification should be in place not only at major airports, but at minor airports as well.

Why minor airports? Because if you seek to do harm and strike fear into the hearts and minds of the flying public, you won't risk dealing with security at a major airport such as Philadelphia International Airport (PHL). To make your job easier, you'll board your flight at a small regional airport such as New Haven (HVN), which is easier to pass through and connect to a full-loaded transcontinental or transatlantic flight out of PHL.

Checking photo identification against a piece of paper that cannot be verified is a waste of resources. Dealing with 21st century threats with mid-20th century technology is not staying one-step ahead of the threat. Current security measures react to past threats rather than looking forward towards new threats.

Having encrypted bar codes on all boarding passes is a 21st century answer to a 21st century threat and it should not be limited to an extremely small number of travelers who chose to use their PDA rather than a paper boarding pass.

Happy Flying!

16 October 2008

The Jewish Holiday Of Sukkot Is Not A Threat To Airline Security According To The Department Of Homeland Security

Web: www.fishfoto.com -- E-Mail: fish@flyingwithfish.com

16/10/2008 – The Jewish Holiday Of Sukkot Is Not A Threat To Airline Security According To The Department Of Homeland Security

Three days ago at Sunset, on the evening of the 13th of October, the Jewish festival of Sukkot began. Sukkot is the joyous holiday essentially celebrating the harvest.

With the holiday of Sukkot approaching the U.S. Department of Homeland Security (DHS) and the Transportation Security Administration (TSA) put out the following press release a few days before the start of this holiday.

Religious Events of Sukkot

TSA recognizes that the travel period for Sukkot, a significant event for persons of the Jewish faith, begins approximately on October 14, 2008, and ends approximately on October 20, 2008.

TSA’s standard operating procedures do not prohibit the carrying of the four plants – which include a palm branch, myrtle twigs, willow twigs, and a citron through the airport or the security checkpoints, or on aircraft. These plants are not on TSA’s Prohibited Items List.

TSA understands that this is a significant religious event for the Jewish faith and has reminded its security workforce that members of the Jewish faith may be observed engaging in religious practices or meditations and carrying the four plants.


I have read this press release and reread this press release, and for the life of me I cannot fathom why someone at the DHS or TSA though they needed to announce you could travel with the items customarily found in a Sukkah while celebrating Sukkot. None of these items are banned from carry-on baggage at any time during the year.

..............so with the TSA's blessing (so to speak).........To all the Jewish readers of Flying With Fish, L'shanah tovah, and happy and a healthy 5769!

Happy Flying!

15 October 2008

Registered Traveler 'Clear' Card Fee Goes Up To US$199: Is This Worth It? I Think Not

Web: www.fishfotoworldwide.com -- E-Mail: fish@flyingwithfish.com

15/10/2008 – Registered Traveler 'Clear' Card Fee Goes Up To US$199: Is This Worth It? I Think Not

A few days ago Verified Identity Pass (VIP) announced that it would be increasing the fee for registering for a "Clear" card

VIP issues the Clear Card in accordance with the U.S. Department of Homeland Security's Registered Traveler Program. The idea of the Registered Traveler is to perform background checks on applicants for the program, speed up their airport security process.

Having looked over the Clear program, and the Registered Traveler program in general, I see only one distinct advantage to holding a Clear card. This advantage is facing shorter airport security wait times, at a limited number of airports.

Back in December 2007 I discussed Clear, and explained that I did not see the value in spending $100 for a Clear card in this entry : 18-December-2007 : To Register Or Not To Register That Is The Question! Should You Be A Registered Traveler?


Now as we are nearing the end of 2008, and Clear raises it’s cost to US$199, I see less value for Clear on a number of levels.

For the US$199 fee a Clear flyer must submit to a lengthy and invasive background check. In this check you must disclose a significant amount of personal information. In addition to this information you must also submit your fingerprints and retina scan. Back in December 2007 I said that I did not believe in a conspiracy theory, I didn't think there were black helicopters circling my house. Although I am my conspiracy theorist, I like to keep my private information private.

In the past year VIP has proven that it is not ready to secure personal and sensitive data. The most notable glitch in VIP's Clear security was in August of 2008 (which I wrote about here: 5/08/2008 - 'Clear' Registered Traveler User Information Stolen) . A laptop, containing the personal information of more than 33,000 Clear applicants and users was stolen from an office at San Francisco International Airport (SFO). To make matters worse, the data on this computer was not encrypted. All the information was available for the taking. The laptop was mysteriously returned to the same office it as stolen from a few days later, with no explanation. VIP claims the computer was not tampered with, however it would be hard to tell if a non-encrypted computer's hard drive was cloned or not.

So with all this in mind what does paying US$199 to Clear get you as a Registered Traveler?

- You are still subject to TSA searches
- Your laptop must still be removed from your bag
- You still may not bring liquids through security
- You are still subject to random secondary searches
- You may still have "SSSS" printed on your boarding pass for secondary screening

......you will however be escorted to a machine that will scan your fingerprints and your retina; you will cut the entire security line; you may (in some airports) leave your shoes on.

Since Registered Travelers are subject to all the same security restrictions of every other traveler what is the benefit of being a registered traveler? That you can leave your shoes on?

Personally I don't mind taking my shoes off. I'd rather be able to leave my laptop in my bag. I am able to leave my laptop in my bag in many other countries. If I have submitted to an intensive background check and offered up a scan of my fingers and my eye, why can't I bring a bottle of Canada Dry ginger ale from home through security with me?

Given that companies that administer the Registered Traveler program are responsible for researching and carrying out the security background checks, rather than the Federal Government, how secure is this system? Since airport security was Federalized to create a uniform system of airport security (except the few airports, such as SFO that are private airport security) shifting the responsibility to a private company is detrimental to the overall security of commercial aviation.

The installation of the Registered Traveler program is profitable to the Department of Homeland Security, but should ‘Security Theater’ be acceptable? Should allowing companies that are not proven in handling secure personal data to determine who is and is not a potential threat?

With the way the Registered Traveler companies operate, can we just have a system in place where we pay US$100 and simply get to skip the line?

.......come on, the background check does NOTHING to alter our security screening anyway when we get to the TSA checkpoint.

Happy Flying!

08 October 2008

Protecting Your Sensitive Valuables In Checked Baggage : A Last Resort

Web: www.fishfoto.com -- E-Mail: fish@flyingwithfish.com

8/10/2008 - Protecting Your Sensitive Valuables In Checked Baggage : A Last Resort

WARNING: THE FOLLOWING LAST RESORT SUGGESTION IS ONLY VALID FOR DOMESTIC TRAVEL WITHIN THE UNITED STATES

With the recent news of a Transportation Security Administration (TSA) screener being caught and confessing to the theft of hundreds of expensive cameras, lenses, laptops, video equipment and other items at Newark Liberty International Airport (as I reported here on Flying With Fish : 7/10/2008 - Airport TSA Security Screener Busted For One-Man Theft Ring) I have received dozens of e-mails today asking how photographers can securely checked their equipment.

The subject of checking photographic equipment securely is one I have discussed in various online forums for quite some time. The bad news is that if someone wants to steal from you they will. The complex issue is that the most secure checked baggage scenario I am aware of is only available for travel domestically within the United States. The troubling issue is that in order to verify that your gear is securely checked you must travel with a firearm.

I have weighed the positives and negatives on discussing the last resort options to ensure a checked bag is locked upon check in and remains locked upon arrival. Ultimately I have decided that it is the best interest of photographers, and others traveling with sensitive valuables that must be checked, to know the one 'trick up the sleeve' that will ensure a bag can be visually checked, locked, never opened again by the TSA or anyone else while in transit, and be delivered via 'special handling' at your destination.

There is a little known rule in place by the TSA that allows a passenger to check an unloaded firearm in a securely locked hard-sided case. This rule applies to something as simple as a 'starter pistol' that requires no permit. If you slip a simple $30 starter pistol into your Pelican Case with your checked camera equipment, your camera case is now a 'gun case.'

How does this work? Let me explain

1) When you check in for your flight you declare that your checked case contains a firearm to the airline counter representative.

2) Once you have declared the weapon to the airline counter agent you must prove to them that the firearm has an empty chamber and is not loaded with any ammo.

3) Once you have satisfied the airline requirements you must present your hard-sided case, containing the firearm, to a TSA Agent.

4) The TSA screener will then visually inspect the contents of your case in front of you. By law you MUST be present as your case is inspected by the TSA Agent.

5) Following the inspection you must lock your case with a non-TSA Sentry Lock. This means that the lock you use will in no way be accessible to any TSA agents, or ramp agents, who have access to TSA Sentry Lock keys. Both key and combination locks are acceptable, however a combination lock is suggested, as is using two locks instead of one

6) Once the TSA accepts your hard-sided case, locked with two non-TSA Sentry Locks, it is identified in such a way that it will not be opened again until it delivered to your destination and is back in your hands, and you choose to unlock it.


You CANNOT check the case containing the firearm at curbside check-in. You should check with the airline you will be flying on to check what rules and regulations that may have for checking a firearm on their flights.

Personally, I strongly suggest making every effort to carry your gear on-board. Look into a combination of a backpack that can hold a significant amount of equipment. Choose a backpack that by design does not draw the attention of an airline representative and use it in conjunction with a full size roll-aboard to carry additional equipment and longer lenses.

If you cannot deal with a backpack and roll aboard for your gear, then look into the last resort and pack a starter pistol between your 400f2.8 and 600f4 inside your Pelican Case.

For the Official TSA information on traveling with a firearm check here:
www.tsa.gov/travelers/airtravel/assistant/editorial_1666.shtm

Happy Flying!

12 August 2008

Baggage Identification With Duct Tape : A Simple Solution

Web: www.fishfoto.com -- E-Mail: fish@flyingwithfish.com

12/08/2008 - Baggage Identification With Duct Tape : A Simple Solution

Over the past two years I have received countless e-mails asking me various solutions for labeling baggage so it is easily identifiable. I have written on the topic many times, each time detailing various ways. These topics range from how I colour code my bags to be easily spotted, to making sure my name and contact info is clearly found inside and outside of the bags.

Overall the quick and easy visual identification of my bags is carried out by the simple use of brightly coloured duct tape.

Duct tape, as everyone knows, has thousands of uses. Duct tape is used to fix heating ducts (its original purpose) to NASA's use of duct tape to keep astronauts alive on Apollo 13 (it was used to help modify the carbon dioxide filters....and again on Apollo 17 to repair a damaged fender on a lunar rover on the moon).

If duct tape can keep astronauts alive why overlook it as a simple solution to baggage identification? I generally use one colour tape on my bags so I can quickly spot my bags and to keep them all uniform. The colour I have chosen is "Flamingo Pink."

Duct tape will adhere to almost any surface and remain in place until removed, which makes it ideal for bags that will go from hot on the ramp to frozen in the baggage hold, to pouring rain waiting for your rental car.

My bags get wrapped with 1.88in (4.77cm) tape on the top and side handles, then additional tape on the front, back and remaining untaped side. By placing florescent coloured tape on all four sides of my bag not only can I identify my bag quickly, but also airport and baggage thieves are deterred from approaching my bag.

As I have also discussed many times in the past airport thieves want an easy target and a piece of luggage wrapped clearly in multiple places in extremely bright (and in some cases bordering on obnoxious) tape is not a bag they want to try and blend into the crowd with.

While I also use coloured electrical tape and gaffers tape on my equipment and personal items, my bags are primarily taped in duct tape. In the United States the easiest tape to find (in my experience) is Duck brand duct tape, however for ease of purchase when buying 'matching' duct tape, vinyl tape, electrical tape and gaffers tape I have not found any place that equals the quality and selection offered by TapeBrothers.com

Below is a photo of three rolls of duct tape I have on my shelf for labeling various pieces of travel gear. These three rolls of 'Duck Tape' are coloured Blaze Orange, Island Lime and Funky Flamingo (which is on my bags).

Happy Flying!

--Click Image To Enlarge--

09 August 2008

Stolen 'Registered Traveler' Laptop Found...But Is The Data Safe?

Web: www.fishfotoworldwide.com -- E-Mail: fish@flyingwithfish.com

9/08/2008 - Stolen 'Registered Traveler' Laptop Found, But Is The Data Safe?


Earlier this week I had written about a laptop being stolen containing the data of more than 30,000 'Clear' card users from a Verified Identity Pass (VIP) office at San Francisco International Airport (SFO). Verified Identity Pass operated the 'Clear' card program at 17 airports throughout the United States under the Registered Traveler Program.

I have received multiple e-mails asking why I had not written about the stolen laptop being found this past Tuesday, the day I wrote this entry: 5/08/2008 - 'Clear' Registered Traveler User Information Stolen

I had not written about the laptop being 'found' in the very office it was reported missing from 10 days earlier for a simple reason. This reason is that no one from VIP has been able to explain why VIP was delayed in reporting the theft to the US Department of Homeland Security (US DHS) and they are unable to explain where the laptop was for 10 days.

Authorities searched the office and it was clearly not in the office it went missing from. Ten days later the laptop 'magically' reappears in plain site in the very office it was stolen from. The laptop was clearly not 'found', it was not 'recovered,' it was returned.

Steve Brill, CEO of VIP states "We don't believe the security or privacy of these would-be members will be compromised in any way." Considering the laptop, containing sensitive information regarding more than 30,000 people, was unaccounted for and outside of a secure environment, for more than 10 days with completely unencrypted data how can this statement be made?

It is possible that no harm was done directly to the laptop. After speaking with a few computer security experts they all have a similar scenario suggestion that the laptop's hard drive was simply cloned. Cloning a hard drive appears to be fairly simple according these computer experts. These experts almost all universally agree that accessing a hard drive only protected by two passwords, rather than encrypted data, would be fairly simple to crack for an experienced hacker.

So, while I am happy to hear that the laptop has been returned to VIP, I do not believe the data related to "Clear's" Registered Traveler Program is secure. The information contained on the stolen laptop could very easily be used to steal the identity of those who had their information stored on the hard drive by VIP.

At this time the Transportation Security Administration (TSA) is continuing the suspension of enrollment for new 'Clear' users.

Happy Flying!

06 August 2008

British Government Seeks To Access Airline PNRs As Its New Passport Fails Security Tests

Web: www.fishfoto.com -- E-Mail: fish@flyingwithfish.com

6/08/2008 – British Government Seeks To Access Airline PNRs As Its New Passport Fails Security Tests

As security tightens around the world the British government is now seeking to gain access to airline Passenger-Name-Records (PNRs) as a method of tracking criminals.

Under the current European Union (EU) law, governments may only use PNRs when actively investigating terrorist threats or for the investigation of organized crime. The British Government, while a member of the EU is not a "Schengen Country" (referring to the Schengen Agreement among European nations) which may end up playing a factor in their argument with the EU over their desire to use PNR numbers to track passengers.

To further track those traveling, passengers the British Government is also considering seeking access to PNR information related to domestic passengers as well. As photo identification is not required at all British airports for domestic travel, the British Government may want to try improving some basic security measures before leaping into complex security measures for the identification of those flying within the United Kingdom.

The British Government's request to access PNR information comes at the same time The Times of London reported that the UK's new "fake proof" ePassport could be cloned in minutes. The cloning of the ePassports RFID chips is being reported just a few days after it was reported that 3,000 blank British passports were stolen.

For more information on the cloning of the British ePassport check out today's story at the TimesOnline here:
http://www.timesonline.co.uk/tol/news/uk/crime/article4467106.ece

Happy Flying

31 July 2008

Flying With Fish Featured On A Canadian National Radio Show Today......Tune In!

Web: www.fishfotoworldwide.com -- E-Mail: fish@flyingwithfish.com

31/07/2008 – Flying With Fish Featured On A Canadian National Radio Show Today......Tune In!

This morning the Charles Adler Show contacted me, a talk radio show broadcast across Canada, to discuss the topic of passenger personal security. With the rate of airport thefts increasing and the tactics used by airport thieves becoming more intricate this segment on the Charles Adler Show will focus on both how thieves work and how passengers can protect themselves when traveling.

The segment on the Charles Adler Show, which is broadcast on the Corus Radio Network, will begin at 3:05pm EST/12:05pmPST today.

For those outside of Canada, or those who don't receive the Corus Radio Network, you can listen to the show live here:
http://www.cjob.com/StationShared/AdlerOnline.aspx

Happy Flying!

29 July 2008

Are Thieves Using Self Check-in Kiosks?

Web: www.fishfotoworldwide.com -- E-Mail: fish@flyingwithfish.com

29/07/2008 – Are Thieves Using Self Check-in Kiosks?

In the past week Canadian low cost airline WestJet stopped allowing passengers to check-in with their credit cards as the self check-in kiosks. WestJet is not trying to be difficult, they are not trying to force you to wait in line for an agent, what WestJet is doing is trying to protect their passengers from potentially being victims of credit card fraud.

Recently both MasterCard and Visa in Canada began investigating a potential security breach of airline self check-in kiosks at Toronto's Pearson International Airport (YYZ). While neither MasterCard nor Visa will comment on how credit card information may have been stolen via the Kiosks software, it is suspected that savvy thieves have found a way to collect and store the data, then retrieve the stolen data through the network that connects the kiosks directly to the airlines.

While the incidents bring investigated are currently isolated to YYZ, it does not mean that is not being employed elsewhere in a way that is not yet detected. It also does not mean that thieves are not working to employ this technology elsewhere to collect as much credit card data as possible.

An odd twist in this potential security breach is that in theory an airline check-in kiosk should only be reading your credit card for your name to match it to your reservation. When you check-in, the kiosk asks you to swipe your card and type in your destination airport. This information combined is used to eliminate the potential of confusing passengers with the same name. When you check in, you do not need to use the same credit card you purchased the ticket with. Any valid credit card with your name can be used to check-in.

Since the current software that drives the self check-in kiosks should read no vital credit card information passengers should be protected from credit card theft. Clearly in some cases this is not what is happening and the hacked machines, which are produced by IBM Canada and use software created by both ARINC of Annapolis, Maryland (USA) and SITA or Geneva, Switzerland, are not only reading vital data, but more importantly, the machines are storing it somewhere within the machines' systems.

So are thieves hacking the software in a small number of the 70,000+ self-service check-in kiosks at North American airports? Not exactly.

While companies such as Kinetics, which creates the software used in approximately 75% of the self check-in kiosks in the United States, will not discuss the specific details of how the machines work, it is known that a self service check-in reads your information off the magnetic strip on the back. The software reads all the information in that magnetic strip, and then it only takes the data it needs. One the system has the date it need it should purge the rest of the data from the system....... but only if the software being used it programmed to purge this information.

How can you avoid having your credit card information from a potentially unsecured self check-in kiosk?

When you check in you can use your reservation number or your passport. Some airlines allow you to check-in using your airline frequent flyer card. When using an airline frequent flyer card you must usually use the membership card of the airline you are traveling on and not those of affiliate or partner airlines (with limited exceptions). Personally, I find it easy enough to have my reservations number with me; it is stored in my Blackberry. I type it in; take my boarding pass and head to security.

Not all airport thieves are watching you and waiting to steal your items. Some are far away sitting a computer waiting to take what they want undetectable to unsuspecting passengers.

Happy Flying!

16 July 2008

Airline Missile Defense System Takes Flight With First Commercial Passenger Flight

Web: www.fishfoto.com -- E-Mail: fish@flyingwithfish.com

16/07/2008 – Airline Missile Defense System Takes Flight With First Commercial Passenger Flight

This morning an American Airlines (AA) Boeing 767-223 (762), departing New York's JFK International Airport (JFK), for it's 5-hour 34-minute flight to Los Angeles International Airport (LAX). The AA 762 slowly pushed back from Terminal 8's Gate #4, it made it's way to taxi-way 'Whiskey' then rolled to taxi-way 'Bravo' and then wound it's way to it's departure runway, it powered up its engines and lifted off into the sky................

What made this routine daily flight between JFK-to-LAX different than all others? This flight was the first ever U.S. passenger plane to complete a passenger flight with the BAE Systems created JetEye Infrared Missile-Defense System. The JetEye system detects a heat-seaking missile, and defends the aircraft by firing it's own laser that diverts the in-bound missile away from the aircraft.

With security experts fearing the use of a shoulder-launched heat seeking missile, such as those used in attacks on commercial aircraft in Baghdad and Kenya, this system can thwart potential attacks, if installed on 'high-probibilty-target' aircraft. It is unclear what determines a 'high-probibility-target' aircraft, however that is an entirely different subject to cover.

While the installing of the JetEye is not intended to be mandatory on commercial aircraft in the United States, American Airlines will be installing the system on two additional 762 aircraft. These 762 aircraft, like the one that flew today, will fly domestically only on daily trans-continental routes. These commercial passenger flights will be used by BAE Systems engineers to test the reliability and maintainability of the system.

Over the past few months tests of the JetEye system has been evaluated on an ABX Air aircraft 767-232F, as well as eleven FedEx MD-10F and MD-11F. The FedEx test aircraft have been flying with the JetEye system for over a year and logged more than 4,500 flights.

Of all the press literature release regarding the maiden commercial passenger flights, I think by far the best quote from an American Airlines spokesperson is this: "No missiles will be fired at these flights."

This quote leaves me with two questions
1) Who in their right mind would fire missiles at a flight full of passengers to test a weapons defense system?
2) If no missiles are being fired at these aircraft (not that missiles should be fired at the AA,ABX or FedEx aircraft) how does BAE Systems know that the system is reliable and maintainable?

A third question does come to mind.....if the missiles are diverted away from the aircraft, where is the missile redirected to?

The JetEye Infrared Missile-Defense System is the final phase of the U.S. Department of Homeland Security (DHS) 'Counter-Man-Portable Air Defense System' (C-MANPADS). This program was established to test the sustainability of a commercial aircraft missile protection systems. The testing of these systems should run for a minimum of 7,000 flight hours.

Happy Flying!