4 ms·
To entertain an actual technical discussion for a moment on this (and assuming air security is a legitimate goal), I wonder what kind of pen testing certain peo
by supernova87a 3y ago
To entertain an actual technical discussion for a moment on this (and assuming air security is a legitimate goal), I wonder what kind of pen testing certain people might try on this, given that now there is not someone so actively watching if you display suspicious behavior. As in, at least with traditional checkpoints, an agent watching your moves could easily see if you were fiddling with something to try to evade detection. And that would deter people from trying anything.
But with an automated portal, who knows what someone might try and test the tolerances of, to understand how it works and the limits.
Although, perhaps if it is operated like some automated immigration checkpoints abroad, a dedicated officer still does oversee several booths and will probably notice lingering behavior where someone is acting suspiciously.
Imagine it's like if you knew that after 3 tries, your login attempt gets reported to root, versus if you know that never happens.
- mike_d 3y ago> I really wonder what kind of pen testing certain people might try on this After getting spanked by DHS OIG in 2017ish, TSA has really stepped up their testing program. They have an internal DHS red team as well as hiring outside experts for regular testing. Additionally they have a program called index testing where they take screeners from one airport and train them to do covert testing and send them to other airports, to both increase the volume of regular testing as well as exploit insider knowledge. Despite all the shit they catch, TSA has gotten really good at detecting some of the stuff that I would covertly travel with.
- islewis 3y ago> After getting spanked by DHS OIG in 2017ish I'd love to read more about this, but a quick google search didn't bring up much. Any good sources?
- mike_d 3y agohttps://www.oig.dhs.gov/sites/default/files/assets/2017/OIG-17-112-Sep17.pdf https://www.oig.dhs.gov/sites/default/files/assets/2017/OIG-... This is the unclassified summary. It has been a while so I have just submitted a FOIA request to release it publicly, we will see where that goes.
- techdragon 3y agoInternal DHS red team sounds like one hell of a job if they include physical security checks (aka “Airport Security”) in the list of things the red team is allowed to attempt to bypass/exploit … like this could be a boring government desk job … or… it could be professional heist movie LARPing with all the fun of sneaking past the real security stuff but none of the risk of getting thrown into a jail cell to rot… and the follow on question is how they monitor and supervise this, like if it is physical pen testing the airport security line, do they carry any sort of documentation to stop things getting out of hand or is it entirely up to their superiors up the chain to stop them winding up in jail for real… I’m expecting it isn’t as exciting as it could be, but I really want to know more.
- kmoser 3y agoSeveral decades ago I was hired by a multinational bank to do software development, and one of my first tasks was to glean as much information as I could about one of the competitors' ATMs. My manager gave me a letter (on company letterhead) to carry with his contact info that described what I was doing, in the event security stopped me for spending an inordinate amount of time going through as many screens on the ATM as I could and writing down things about the UI. (Spoiler alert: nobody stopped me.) I'm not an expert in airport security at all, but I'd bet dollars to donuts that anybody doing physical pen testing of that type will carry documentation describing who they are, who they work for, and what they are doing.
- techdragon 3y agoSee this was my first thought but then it occurred to me that they’re trying to bypass people who are meant to be inspecting your stuff, does part of the job become “sneak past with this bit of paper” or do they carry nothing official on them to make the test more authentic, having paper documents risks biases towards staff procedures that would catch people with the document and thus end any pen testing attempts with potentially only a perceived improvement to security when they could be failing to catch people with usb drives or whatever else they are meant to be on the lookout for…
- edrxty 3y agoWhat were you traveling with that they detected?
- miki123211 3y agoFriend of mine worked in an adjacent industry (not TSA, not in the US even, for a contractor doing "mystery passenger" testing for major airlines I believe. Many countries require airlines to do their own checks at departure for international incoming flights, and levy big fines if a traveler with invalid documents is let through, so airlines do care about this a great deal. He once tried to travel internationally without a Passport / ID, I don't remember if this was within Schengen or not. He had a sob story about his mother dying and him trying to get home to her funeral. He was let through, partly because of people believing him, partly because of incompetence and people just not checking. A good few employees were sacked because of this.
- pluto_modadic 3y ago> "actively watching if you display suspicious behavior" oh lord, the potential for racist bias here. Or just bias against nervous fliers. the "one officer monitors multiple kiosks" thing just again makes me think they'll pick on a certain crowd