3 ms·
I doubt this was meant seriously, but it's worth noting this actually doesn't work. You need each left/right decision to be independent so that positioning your
by agf 11y ago
I doubt this was meant seriously, but it's worth noting this actually doesn't work. You need each left/right decision to be independent so that positioning yourself at a certain place in line doesn't allow you to choose left/right.
- fabulist 11y agoSo you're saying this app operated by TSA agents is meant to defeat attackers looking to be screened by cooperative TSA agents? I can't help but feel something is lacking in this threat model.
- KMag 11y agoDefense in depth is a real thing.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- fabulist 11y agoMore and more it seems to me that there is no replacement for correctness, and you have to squint to tell this apart from theater. Perhaps I'm exaggerating. It would certainly raise costs to the attacker to recruit an additional collaborator, and to wait for a serendipitous scheduling. But I'm not convinced it raises the difficulty by $300k.
- agf 11y agoI'm not sure I understand this. If I were to observe the pattern before I reach the agent, it would be easy enough to let someone go ahead of me while pretending to finish a phone call or something. It doesn't require the cooperation of the TSA agent.