Showing posts with label Flaw. Show all posts
Showing posts with label Flaw. Show all posts

Tuesday, December 28, 2010

Video: TSA investigating pilot for posting videos that show security flaws

He’s not in trouble with the airline, but his status as an official federal Flight Deck Officer is in mortal peril.

Three days after he posted a series of six video clips recorded with a cell phone camera at San Francisco International Airport, four federal air marshals and two sheriff’s deputies arrived at his house to confiscate his federally-issued firearm. The pilot recorded that event as well and provided all the video to News10.

At the same time as the federal marshals took the pilot’s gun, a deputy sheriff asked him to surrender his state-issued permit to carry a concealed weapon…

According to the letter, the review was directly related to the discovery by TSA staff of the YouTube videos. “The content and subject of these videos may have violated regulations concerning disclosure of sensitive security information,” the letter said.

The gun was issued to him by the feds pursuant to his status as an FDO, so presumably they’re required to take it back when an investigation is pending. Meanwhile, Drudge is splashing this with a banner headline about Napolitano punishing the guy for merely being “critical of TSA,” but I don’t know how he can be so sure. It depends on what’s in the clips, which have since been made private on YouTube. If he violated the regs by putting something on film that might inadvertently show a bad guy how to get through, thereby creating a security risk, what are they supposed to do while they’re (hopefully) figuring out a way to eliminate that risk? Shrug it off and hope that no one with bad intentions finds the clip? It’s not clear here either whether this guy approached anyone at TSA with his concerns first or whether he took care to make sure there was nothing in the vids that might expose any security holes. It reminds me a bit of Wikileaks, actually. Which is not to say that Drudge isn’t right — maybe this really is all about TSA trying to protect its image by silencing a whistleblower — but I wouldn’t jump to conclusions just because the agency is usually (very) unsympathetic.

Update: I’ve got a feeling that even a cautious semi-defense of TSA won’t play well with readers, so I’ve added a second clip below to smooth things over. It’s seasonal, too!


Wednesday, December 8, 2010

Visited Porn? Web Browser Flaw Secretly Bares All

Visited Porn? Web Browser Flaw Secretly Bares All

SAN FRANCISCO (AP) — Dozens of websites have been secretly harvesting lists of places that their users previously visited online, everything from news articles to bank sites to pornography, a team of computer scientists found.

The information is valuable for con artists to learn more about their targets and send them personalized attacks. It also allows e-commerce companies to adjust ads or prices — for instance, if the site knows you’ve just come from a competitor that is offering a lower price.

Although passwords aren’t at risk, in harvesting a detailed list of where you’ve been online, sites can create thorough profiles on its users.

The technique the University of California, San Diego researchers investigated is called “history sniffing” and is a result of the way browsers interact with websites and record where they’ve been. A few lines of programming code are all a site needs to pull it off.

Although security experts have known for nearly a decade that such snooping is possible, the latest findings offer some of the first public evidence of sites exploiting the problem. Current versions of the Firefox and Internet Explorer browsers still allow this, as do older versions of Chrome and Safari, the researchers said.

The report adds to growing worry about surreptitious surveillance by Internet companies and comes as federal regulators in the U.S. are proposing a “Do Not Track” tool that would prevent advertisers from following consumers around online to sell them more products.

The researchers found 46 sites, ranging from smutty to staid, that tried to pry loose their visitors browsing histories using this technique, sometimes with homegrown tracking code. Nearly half of the 46 sites, including financial research site Morningstar.com and news site Newsmax.com, used an ad-targeting company, Interclick, which says its code was responsible for the tracking.