Skip ads and navigation
Advertising
Our network sites seattlepi.comHelp
Print thisE-mail this
TSA exposed travelers to potential identity theft

In October 2006, the Transportation Security Administration set up a Web site so that travelers whose names were mistakenly on "no fly" lists had a way to request that their names be removed. Thousands of people went onto the site and entered personal data (via Consumerist).

Turns out, the site wasn't very secure, exposing citizens to potential identity theft, accordingto a report released last week by the House Oversight and Government Reform Committee.

The site wasn't hosted by a government domain. The home page where people logged on wasn't encrypted. One of the data submission pages wasn't encrypted and the ones that were weren't properly certified. All of this went unnoticed for four months, even as TSA Administrator Kip Hawley testified before Congress that the agency had assured "the privacy of users and the security of the system" before its launch, the report said.

Thousands of people used the site, including at least 247 travelers who entered large amounts of personal data including their names, addresses, Social Security numbers and places of birth, according to the report.

How did a small, Virginia-based contractor called Desyne Web Services get the no-bid contract in the first place? The TSA "technical lead" used to work at Desyne, went to high school with the company's owner and regularly socialized with him, the report said.

Here's the new TSA site for travelers seeking redress from security delays.

To read the full report, click here [PDF].

Here's TSA's response.

Posted by at January 15, 2008 9:02 a.m.
Categories: ,
Comments
There are currently no comments for this blog entry.

! Login below to post a comment.

Registered users, log in here
E-mail 
Password 
Remember me
 HELP! I forget my password

Unregistered users, sign up now

Or post anonymously (About this feature)

Your comment (No HTML allowed, use these special codes instead)
Violating our Terms of Service may result in your post being removed.

Special codes
  • [b]selected text[/b] -- Display the selected text in bold.
  • [i]selected text[/i] -- Display the selected text in italics.
  • [link]www.seattlepi.com[/link] -- Creates a link to the url between the link tags.
  • [link title="Seattle Post-Intelligencer"]www.seattlepi.com[/link] -- Creates a link to the url between the link tags, uses title as link text.
  • [mail]newmedia@seattlepi.com[/mail] -- Creates a link to an email address.
Enter the code shown:
What is this?
SUBSCRIBE

RSS
Headline widget

BLOGGER BIO
photo
Phuong Cat Le: Staff reporter
ARCHIVES
Search this blog

Recent entries
· Court says AT&T can't force arbitration
· To reach a live person, press ...
· Homeowners sue Countrywide
· No more unwanted "robo calls"
· Refinancing not always an easy ride

Browse by month
Browse by category

RSS/Web feeds (help)
RSS 2.0RSS 1.0Atom
Headlines for your site

LINKS

Consumer blogs / sites
· Blawg of the Attorney General's Office
· Consumer Reports Shopping Blog
· Consumer Reports WebWatch
· Consumerist
· KOMO TV consumer page
· National Consumer Law Center

Where to complain
· WA Attorney General's Office
· Better Business Bureau
· Federal Trade Commission

Recalls
· FDA recalls
· Consumer Product Safety Commission
· Recalls of cars, tires, child car seats
· USDA recalls (meat, poultry, eggs)

Government sources
· Attorney General's Office
· WA Dept of Financial Institutions

ADVERTISING

Most recent posts
· Living Simply: Happy Thanksgiving Canada!
· United Planet: Pastor in Pakistan Suffers Police Attacks, and Death Threats
· Velocity: Ladies: Race in the dirt!

*Would you like to blog for us?

Advertising

Seattle Post-Intelligencer
101 Elliott Ave. W.
Seattle, WA 98119
(206) 448-8000

Home Delivery: (206) 464-2121 or (800) 542-0820
seattlepi.com serves about 1.7 million unique visitors
and 30 million page views each month.

Send comments to newmedia@seattlepi.com
Send investigative tips to iteam@seattlepi.com
©1996-2007 Seattle Post-Intelligencer
Terms of Use/Privacy Policy

Hearst Newspapers