Community
Wiki Posts
Search

TSA to Test Encrypted Flight Boarding Passes

Thread Tools
 
Search this Thread
 
Old Feb 12, 2009 | 8:20 pm
  #16  
 
Join Date: Aug 2008
Posts: 239
I just want to make sure I understand the general position on this issue....
1. Security experts and frequent flyers complain that TSA's BP/ID checks can be thwarted by forging or altering the boarding passes at home.
2. In response, TSA and the airlines test encrypted boarding passes, which would make it more difficult or impossible for the average person to forge or alter a boarding pass successfully.
3. Some of the same experts and frequent flyers who complained about the forgery problem complain that the new measure may inconvenience them by making it more difficult for them to forge or alter their boarding passes.

Am I missing anything?
spotnik is offline  
Old Feb 12, 2009 | 8:30 pm
  #17  
10 Countries Visited
20 Countries Visited
30 Countries Visited
15 Years on Site
 
Join Date: Dec 2007
Location: North of DFW
Programs: AA PLT, HH Gold, TSA Disparager Gold, going for Platnium
Posts: 1,535
Originally Posted by spotnik
I just want to make sure I understand the general position on this issue....
1. Security experts and frequent flyers complain that TSA's BP/ID checks can be thwarted by forging or altering the boarding passes at home.
2. In response, TSA and the airlines test encrypted boarding passes, which would make it more difficult or impossible for the average person to forge or alter a boarding pass successfully.
3. Some of the same experts and frequent flyers who complained about the forgery problem complain that the new measure may inconvenience them by making it more difficult for them to forge or alter their boarding passes.

Am I missing anything?
yeah like the whole point that none of it adds to security just hassle and alot of expense ontop of the mt Everest sized turd called tsa
Scubatooth is offline  
Old Feb 12, 2009 | 8:46 pm
  #18  
 
Join Date: Jan 2006
Location: Live: HVN -- Work: The World
Programs: DL - exPlat (now Gold) ; AB - Gold ; TK - Gold; BMI - exGold; US - exChairman ; UA-ex1K; NW-exGold
Posts: 1,248
The need for a more secure boarding pass has been discussed many times, by many people. I suggested the need for a secure boarding pass on my blog back in October. It has nothing to do with terrorism, but more to do with seeking out a way to verify a boarding pass. The hard part is making a secure boarding pass, that also removes the TSA from handling airline revenue issues.

I wrote about this topic in detail today on my Boarding Area blog here:
http://boardingarea.com/blogs/flying...-last-october/
sefrischling is offline  
Old Feb 12, 2009 | 9:21 pm
  #19  
 
Join Date: Aug 2008
Posts: 239
Originally Posted by sefrischling
The need for a more secure boarding pass has been discussed many times, by many people. I suggested the need for a secure boarding pass on my blog back in October. It has nothing to do with terrorism, but more to do with seeking out a way to verify a boarding pass. The hard part is making a secure boarding pass, that also removes the TSA from handling airline revenue issues.

I wrote about this topic in detail today on my Boarding Area blog here:
http://boardingarea.com/blogs/flying...-last-october/
Thanks for the link. Good article.
Personally, I'm not convinced that the focus on boarding passes and ID is the best place to spend security resources. (Of course, I'm also certain that I'm not privy to all the relevant info.) I just wanted to make sure I hadn't missed some part of the debate.
spotnik is offline  
Old Feb 12, 2009 | 9:35 pm
  #20  
 
Join Date: Jan 2006
Location: Live: HVN -- Work: The World
Programs: DL - exPlat (now Gold) ; AB - Gold ; TK - Gold; BMI - exGold; US - exChairman ; UA-ex1K; NW-exGold
Posts: 1,248
Spot,

There are various ways the TSA can focus its resources on security, outside of the encrypted bar code.

For economic resources, the bar code is really more effective as an airline revenue management tool. As airlines continue to roll out 'e-boarding pass' on Mobile Phones & PDAs, the scanners will be deployed eventually to most TSA check points and airlines will cover the expense of creating the encrypted boarding pass system, the actual costs will be minimal.

The DHS needs to refocus the role of the TSA and this new system will have its complications, but it can be a good thing if implemented correctly.
sefrischling is offline  
Old Feb 12, 2009 | 9:37 pm
  #21  
 
Join Date: Jan 2006
Location: Live: HVN -- Work: The World
Programs: DL - exPlat (now Gold) ; AB - Gold ; TK - Gold; BMI - exGold; US - exChairman ; UA-ex1K; NW-exGold
Posts: 1,248
Originally Posted by Scubatooth
yeah like the whole point that none of it adds to security just hassle and alot of expense ontop of the mt Everest sized turd called tsa
There is no real hassle with the scanning of an encrypted bar code. You hand the boarding pass to the TDC, they scan it while staring at your ID with a flash light and magnifying glass.

Either it matches up or it doesn't. It should actually reduce hassles.
sefrischling is offline  
Old Feb 12, 2009 | 10:02 pm
  #22  
 
Join Date: Aug 2008
Posts: 239
Originally Posted by sefrischling
Spot,

There are various ways the TSA can focus its resources on security, outside of the encrypted bar code.

For economic resources, the bar code is really more effective as an airline revenue management tool. As airlines continue to roll out 'e-boarding pass' on Mobile Phones & PDAs, the scanners will be deployed eventually to most TSA check points and airlines will cover the expense of creating the encrypted boarding pass system, the actual costs will be minimal.

The DHS needs to refocus the role of the TSA and this new system will have its complications, but it can be a good thing if implemented correctly.
I certainly think the encrypted BPs can be a good thing, especially if the program is a partnership with the airlines (as in, good for both the airlines and TSA, and supported by both groups). The potential problems, however, concern me.

I certainly don't want futher mission creep within TSA. Our job is not to run a criminal dragnet, and the notion of using this type of system to check NCIC status, or and criminal or immigration inquiries. I grow increasingly concerned when I hear about proposals to use TSA ID checks for this purpose. I see the value of getting bad guys off the streets, but I think the cost in decreased civil rights is too great to bear.

Furthermore, in the current economic and political situation, government should be particularly critical of where it spends cash and other resources. If this can yield real security benefits that are directly related to TSA's mission, I am glad for it. I have not read anything in public sources that indicates the sort of benefit I would hope to see.

On the other hand, if this is an item that the airlines want to offer, and TSA is merely cooperating with industry requests, I think it should be explained as such. After all, regulatory agencies are not supposed to inhibit or harm the growth and development of private industry. Regulatory agencies are simply supposed to make sure that public interests and safety are protected.
spotnik is offline  
Old Feb 12, 2009 | 10:25 pm
  #23  
30 Countries Visited
Community Builder
All eyes on you!
15 Years on Site
 
Join Date: Jul 2007
Location: Sydney (for now), GVA (only in my memories)
Programs: QF Lifetime Silver (big whoop)
Posts: 9,335
Originally Posted by sefrischling
...but it can be a good thing if implemented correctly.
Ah, there's the rub. TSA has a history of stuffing up the introduction of new technology, from unreliable puffers to "kindergarden safe" mmw scanners to inspecting print-at-home BPs with blacklights. Why would this be any different?
Originally Posted by sefrischling
There is no real hassle with the scanning of an encrypted bar code. ...
Either it matches up or it doesn't. It should actually reduce hassles.
That assumes that the accuracy of the scanning is 100%. I wouldn't bet on it. Especially when the outcome of a false positive is being handed over to the police.

As I said elsewhere, I think this is the "new toy" syndrome rather than any genuine attempt at (imaginary) security.

And checking IDs does not add to security, nor is it TSA's job to protect airline revenue or catch criminals.
RadioGirl is offline  
Old Feb 12, 2009 | 11:53 pm
  #24  
Ari
FlyerTalk Evangelist
10 Countries Visited
20 Countries Visited
30 Countries Visited
20 Years on Site
 
Join Date: Aug 2005
Location: Chicago
Posts: 11,680
Originally Posted by SDF_Traveler
Have also heard it was being done at ORD T3 (AA) - but I have not been through that checkpoint lately.
I can confirm.
Ari is offline  
Old Feb 13, 2009 | 12:19 am
  #25  
10 Countries Visited
20 Countries Visited
30 Countries Visited
15 Years on Site
 
Join Date: Dec 2007
Location: North of DFW
Programs: AA PLT, HH Gold, TSA Disparager Gold, going for Platnium
Posts: 1,535
Originally Posted by sefrischling
There is no real hassle with the scanning of an encrypted bar code. You hand the boarding pass to the TDC, they scan it while staring at your ID with a flash light and magnifying glass.

Either it matches up or it doesn't. It should actually reduce hassles.
Fish i was talking about from the airlines side from IT implementation, and even more on TSA for having to buy yet another gadget(to add to the black light) to waste tax payer money for no benefit. Its a 360 degree waste of money and time on all fronts for no benefit

you dont even have to get me started on the ID checking thing as thats BS from the word go, even more so that its not compared to anything. I could care less about fakes because 99.999% TSA doesnt know the difference between real and fake anyways unless it was a poor job that a blind person could pick out at a 100m. I also know where i can get novelty IDs that are dead on that even the cops cant tell there fake as there encoded correctly down to the RFID and mag strips.
Scubatooth is offline  
Old Feb 13, 2009 | 12:32 am
  #26  
Suspended
 
Join Date: Jul 2001
Location: Watchlisted by the prejudiced, en route to purgatory
Programs: Just Say No to Fleecing and Blacklisting
Posts: 102,077
Name-matching accuracy done comparing two printed documents is higher than of name-matching done comparing a printed document and an electronic display. That means a slight name adjustment that beats Soundex-type processing would work for a person whose name is on the blacklists to actually avoid the blacklists still -- at least unless the plan is to make an extraordinary suspect of every passenger who doesn't have a SecureFlight "approved"/"searchable" profile.

SecureFlight approved passenger profile = "registered" traveller. That's the backdoor way to getting this done.

Last edited by GUWonder; Feb 13, 2009 at 12:40 am
GUWonder is offline  
Old Feb 13, 2009 | 7:32 pm
  #27  
FlyerTalk Evangelist
40 Countries Visited
All eyes on you!
20 Years on Site
 
Join Date: Jun 2005
Posts: 38,543
Originally Posted by OrlandoFlyer
http://www.usatoday.com/travel/fligh...boarding_N.htm

More wasted tax payers money by the TSA. Why bother to forge a boarding pass when it is so easy to get one by buying an airline ticket.
Because you can book your ticket under a false name and avoid the no-fly list. Your ID is only checked against your boarding pass, not your ticket.
Loren Pechtel is offline  
Old Feb 13, 2009 | 7:42 pm
  #28  
Suspended
 
Join Date: Jul 2001
Location: Watchlisted by the prejudiced, en route to purgatory
Programs: Just Say No to Fleecing and Blacklisting
Posts: 102,077
Originally Posted by Loren Pechtel
Because you can book your ticket under a false name and avoid the no-fly list. Your ID is only checked against your boarding pass, not your ticket.
This adjustment is still a waste -- aside from ID still not being security, these stupid blacklists remain readily circumventable even with ID checks being run against electronically-displayed boarding pass info (even when it includes an encrypted authentication method).

Stupid waste of money.
GUWonder is offline  
Old Feb 15, 2009 | 6:38 am
  #29  
FlyerTalk Evangelist
10 Countries Visited
20 Countries Visited
30 Countries Visited
15 Years on Site
 
Join Date: Sep 2007
Location: SJC, SFO, YYC
Programs: AA-EXP, AA-0.41MM, UA-Gold, Ex UA-1K (2006 thru 2015), PMUA-0.95MM, COUA-1.5MM-lite, AF-Silver
Posts: 13,436
Originally Posted by JaggedMind
The problem I see is that this is going to be seen as such a fun challenge to hackers and crackers that an actual boarding pass generator program will be created and passed around in no time. A small amount of known data being encrypted with constant keys with loads of samples available is a small task to crack in today's world.

To make this pretty much secure you need:
- Passes checked against airlines' systems in real-time.
- Encryption keys updated often (weekly or sooner).
- Use stronger encryption or encrypt lots of extra "junk" data. This is probably not possible while keeping the decryption time low and the barcode within the size requirements.

And there is always the possibility of something like the TSA's copy of all the airline keys getting loose some day.
I was going to suggest that asymmetric key encryption is likely going to be used here (thus obviating the issue of the TSA losing the airline keys), but I then realized that the size of the keys (at least 128 bytes) is not going to lend itself to a BP as you pointed out. So I agree. This is the clipper chip fiasco all over again.

Another problem is that the airline changes the key, the pax generates a BP from the new key, and the TSA in Dogpatch Municipal airport didn't get the update. Pax is hauled away as a terrorist. Or the pax generates the BP from the old key, key is updated, and Dogpatch gets the update but does not have the old key. Same result.

At best, when a key update fails, the airport becomes a nightmare as pax go back to the check in counter to get new BPs. The airlines have long since re-aligned their (i.e. reduced) their staffing based on the assumption that most pax get BPs from a kiosk or PC. So the TSA will likely give up on descrypting BPs on days when the key update fails. Obvious avenue for a mischief maker.
Originally Posted by jkhuggins
Because the airline won't sell you one if you're on the no-fly list, and if you're on the selectee list, you'll get the magic SSSS tag on it, which will make it that much harder to get into the secure area with Bad Things(TM).

If you're going to have a no-fly/selectee list, then you have to have boarding passes which (mostly) can't be forged, and a way to verify that the person carrying the boarding pass is, in fact, the person named on the boarding pass. TSA has (essentially) done the latter already by (almost) requiring passengers to present an identity card at the checkpoint.

Again, this assumes that the no-fly/SSSS list makes sense ... which is a topic for another thread ...
A competent terrorist won't be on the no-fly/selectee list because he will be using a false name, and either fake ID, or the Real ID of someone who resembles him (where that someone is in cooperation with the terrorist, or that someone is dead in the trunk of the car the terrorist parked at the airport).

Really disappointing quote:
"Any moron with a printer could do it," security analyst Bruce Schneier said. "Encryption will solve that problem."
I can only hope that Schneier's comment was taken out of context.

This is purely about preserving airline revenue models, nothing else.

Last edited by mre5765; Feb 15, 2009 at 6:44 am
mre5765 is offline  
Old Feb 15, 2009 | 8:07 am
  #30  
A FlyerTalk Posting Legend
 
Join Date: Jul 2003
Location: NYC (formerly BOS/DCA)
Programs: UA 1K, IC RA
Posts: 60,745
Originally Posted by GUWonder
Stupid waste of money.
We really should just keep a running tab at this point.

You gotta wonder. How many child vaccines could we pay for with this money? Or life-saving cancer treatment research? It really is sickening how we throw money down the drain.
magiciansampras is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.