Community
Wiki Posts
Search

No bid TSA website found insecure

Thread Tools
 
Search this Thread
 
Old Jan 17, 2008 | 1:29 am
  #1  
Original Poster
 
Join Date: Jul 2000
Location: Lake Oswego, Oregon USA
Programs: UA Mileage Plus, Alaska Air, American Airlines, SWA RapidRewards
Posts: 143
No bid TSA website found insecure

No surprise here

http://blogs.ittoolbox.com/security/...insecure-21810

No bid TSA web site found insecure
Dan Morrill (Security Project Manager) Posted 1/15/2008
Comments (0) | Trackbacks (0)


In what should be a warning to travelers and just about everyone on the internet, a web site built for the TSA has been found to have significant security issues, endangering travelers, as well as the reputation of the TSA and the company that built the web site.

A report issued on Friday by the House Oversight and Government Reform Committee says that between October 6, 2006, when the TSA launched its Redress Management System [RMS] site, and February 13, 2007, when the site ceased operation following revelations about its lack of security, "[a]t least 247 travelers submitted their personal information through the unsecured 'file your application online' link." Source: Information Week


There is some very interesting commentary on this over at Techdirt.

You can read the report here.

The issues surrounding this, beyond the no-contract bid issued by a person who used to work for the company that built the web site is the apparent lack of understanding about basic security measures.

People should at this point know enough to look for the lock icon on their web browser, and seriously question a web site that does not have one when entering personal information. This is such a basic issue, that it is surprising that it was not done at all, and now people are worried about their identities being stolen.
PDXracer is offline  
Old Jan 17, 2008 | 5:15 pm
  #2  
All eyes on you!
20 Years on Site
 
Join Date: May 2004
Location: Los Angeles, CA
Programs: UA MM (former 1K) - DL PM (former DM) - Marriott Platinum
Posts: 298
Is this the same report already being discussed here?
LAX-1K is offline  
Old Jan 17, 2008 | 7:28 pm
  #3  
Original Member
10 Countries Visited
100k
Community Influencer
25 Years on Site
 
Join Date: May 1998
Location: PDX
Programs: TSA Refusenik charter member
Posts: 16,127
Originally Posted by LAX-1K
Is this the same report already being discussed here?
It is. So we'll close this thread and continue to funnel the discussion there.

----------
essxjay
TS/S moderator
essxjay is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.