Showing posts with label flight screening. Show all posts
Showing posts with label flight screening. Show all posts

Friday, February 18, 2011

UK citizen denied travel from Canada to UK due to inclusion on US no-fly list

Canada’s Star reports that a UK citizen has been unable to fly home to Sheffield from Toronto because his name is on the US no-fly list. After being told he couldn’t board an Air Transat flight, he tried both Air Canada and British Airways. But both carriers refused to take him, according to the story. The Star states: “Airlines that operate from Canada have been known to reject passengers whose names are on the U.S. no-fly list. That's because many flights pass over American airspace or may be forced to land at a U.S. airport in the event of an emergency.“ Application of the US no-fly list to flights originating from Canada but that do not land anywhere in US territory has been “long-standing” according to the paper. The Star also notes that a bill is currently before the Canadian Parliament that would permit Canadian air carriers to transmit passenger information for the US Secure Flight passenger screening program.

Friday, November 19, 2010

Increasing Controversy with Introduction of New Pat-Down Procedures for US Airline Travel

When the US deployed backscatter x-ray and millimeter wave scanners, travellers were given the choice to opt for a physical pat-down instead of going through the scanner. Now, the TSA has introduced new, more invasive pat-down procedures that involve exploring around breasts and genitals and between the buttocks (See for instance this particularly graphic account as well as this account reportedly from author Erin Chase). Some early reports speculated that the new measures were introduced in order to intimidate those who would otherwise choose the pat-down into deciding that maybe the scanners aren’t that bad. Jeffrey Goldberg of The Atlantic has stated that TSA personnel explicitly admitted that that was the reason behind the new policy. John Pistole, Administrator of the TSA, who was called before the US Senate Commerce Committee this week, suggested that the new procedures are in response to covert testing of the old pat-down method which indicated it wasn’t “thorough” enough.

Meanwhile, concerns about the health effects of the scanners continue. Four scientists affiliated with the University of California at San Francisco drafted an open letter last spring to President Obama’s Assistant for Science and Technology outlining their concerns with the backscatter scanners. They argue that official assessments of the health impact from backscatter radiation may underestimate the potential effects of the low-levels of dosage that the scanners emit since they are based on whole body exposure, whereas the scanners would concentrate all radiation in the skin. Additionally, they express concern that certain groups or individuals may be particularly vulnerable to the increased radiation exposure, and they decry the failure to publish key data that would permit independent assessment of the health risks. Both the Allied Pilots Association and the US Airline Pilots Association have advised their members not to go through the scanners. The US Airline Pilots Association further notes that experiences with the new “enhanced” pat-down procedures have involved “a wide range of possibilities … and the results can be devastating.” Others have more general objections to both the scanner/ pat-down procedures. Two commercial pilots have even filed a lawsuit against the Department of Homeland Security citing Fourth Amendment violations. A number of State legislators in New Jersey have objected to the current screening regime and have introduced resolutions calling on the TSA to reconsider its procedures. Additionally, one private individual is calling for a national “opt-out” day to stage a protest.

Wednesday, July 28, 2010

News: Body Scanner Developments

EPIC points out that DHS announced last week it plans to roll out full body scanners (now known as “Advanced Imaging Technology” in TSA-speak) to 28 additional airports. Meanwhile, EPIC has attempted to bring an action to suspend use of the scanners, and a bill has been introduced in the US Senate (S.3536) that would require deployment of the scanners at all US airports by 2013.

In Switzerland, the Zurich Airport began a pilot test involving a single body scanner on 8 June 2010. The test involved the “second generation” system which uses the gingerbread-man-like display rather than an actual scan image. The pilot test was completed on 14 July 2010, and the Airport states that the use of the system enjoyed a high acceptance rate among passengers. The results from the test are being assessed, and future tests may take place, but there are currently no plans to acquire any scanners, the Airport reports.

Monday, May 3, 2010

Israeli Security Expert Decries Body Scanners Before Canadian Parliament

The Vancouver Sun has reported that an Israeli security expert who assisted in the design of the security system at Tel Aviv's Ben Gurion International Airport suggested in parliamentary hearings that the deployment of body scanners is a “useless” waste of money.

“I don't know why everybody is running to buy these expensive and useless machines. I can overcome the body scanners with enough explosives to bring down a Boeing 747,” he is quoted as saying, “That's why we haven't put them in our airport.”

According to the story, a Canadian transport minister has defended the installation of body scanners at Canadian airports. Political scientist Mark Salter also reportedly testified that he viewed body scanners as a “genuine leap forward” in airline security. (Hat tip to unwatched.org)

Friday, January 8, 2010

News: Aiport Security Technology

Forbes has posted an interesting article today discussing various proposals for improving airport security, including behavioral analysis systems, physiological sensors, and increased use of profiling. One system being tested in Israel even sounds like psychological warfare—flashing images onto airport screens, “such as symbols associated with a certain terrorist group or some other image only a would-be terrorist would recognize” and then assessing individuals’ reactions to those images. The article also cites Jim Harper of the Cato Institute for suggesting that security be placed in the hands of the airlines in order to introduce more variation in security procedures.

Thursday, January 7, 2010

Comment: Christmas Day Plot, Part I (Update)

The Telegraph has published a story today claiming that US Customs and Border Protection had singled out Umar Farouk Abdulmutallab based on the human intelligence submitted by the State Department and were waiting to bring him in for interrogation in Detroit. This claim seems to take some steam out of the argument that US intelligence failed to “connect the dots.” This raises the question whether, under the circumstances, some other operative action should have been taken while the flight was in the air. Given what was known, would it have been appropriate to order the flight to turn back around to Amsterdam? Suppose Abdulmutallab caught on to what was happening and decided to detonate over Amsterdam upon the return. Would it have been appropriate to order the flight crew to restrain him? Think of the standards that would apply if the “suspect” were simply someone standing on a public street. Should different standards apply on airplanes?

The article also features an interesting quote from a “senior Homeland Security official” who indicated that “in-depth vetting only begins once the flight manifest has been generated, a few hours before takeoff.” This statement suggests that passenger name records are not submitted on a rolling basis as reservations are made but only once the list of passengers on any one flight has been relatively solidified.

Wednesday, January 6, 2010

Comment: Christmas Day Plot, Part I

“Failure to connect the dots” became a catch-phrase paraphrasing the mistakes within the intelligence community that permitted the 9/11 attacks despite the presence of intelligence within the possession of various US agencies that pointed toward the development of the underlying plot. This phrase has cropped up again in connection with the Christmas Day plot involving Northwestern Flight 253, leading to the question as to whether the lessons learned from the 9/11 review have been implemented.

As news of the attempted attack began to unfold, reports began to roll in that the individual behind the attempt, Umar Farouk Abdulmutallab, had raised a number of red flags which should have resulted in enhanced screening, potentially his detention for further investigation, or--as some have suggested--the denial of an entry visa for the US. First it was revealed that Abdulmutallab had been included in the National Counterterrorism Center’s TIDE (Terrorist Identitites Datamart Environment) database (more on TIDE in Part II) (See this story from CBS). Then, it came to light that Abdulmutallab’s father had approached US State Department officials in Nigeria with concerns that his son had “fallen under the influence of ‘religious extremists’ in Yemen” (See this story from CBS). According to a report from CBS News, this information was forwarded to officials in Washington (In fact, it may have been the basis for Abdulmutallab being entered in TIDE). Apparently, however, no flags were attached to Abdulmutallab’s US visa, and the CBS report suggests that US officials who had received information relating the father’s concerns did not realize that the individual in question had been issued a multiple-entry visa by the US Embassy in London that was valid from June 16, 2008 to June 12, 2010. Lastly, it has been reported that the NSA had identified communications among Al Qaeda members in Yemen concerning a plot involving a Nigerian (See articles here and here).

The Obama administration called for two reviews: one quick review of flight screening procedures and technologies, the other a more in-depth review of the terrorist watch list system in use in the US. President Obama has promised that the results of the reviews will be revealed in public reports in the near future. It will be interesting to see to what extent the details of what happened at each stage of Abdulmutallab’s journey will be released. For me, the following questions come up: 1) Were any personal data pertaining to Abdulmutallab submitted to the TSA before he boarded the flight from Nigeria? 2) What security procedures did Abdulmutallab undergo in Lagos (or Ghana)? 3) Was Abdulmutallab subjected to security procedures at Schiphol? It would be particularly interesting to know whether he underwent a full-body scan (such scanners are evidently in common use at Schiphol) (more on full-body scanning below)?

In this case, it isn’t clear to what extent fault can be found with US authorities. Clearly mistakes were made, but even if all the information on Abdulmutallab had come together and resulted in an operational decision, measures stemming from that decision would have to have been taken in Nigeria or the Netherlands in order to have been effective. The incident may primarily reflect the lack of uniform and coordinated procedures at the international level. The US has expressed the desire to receive passenger name records for all passengers who have booked flights to the US. Yet, the question arises as to how many airlines indulge that desire and with what level of accuracy. This requirement has been particularly contentious within the EU. However, given the fact that Abdulmutallab had booked passage with a US-based air carrier for the final leg of his journey, it seems likely that the US carrier submitted passenger record data on Abdulmutallab to the TSA. But again, even if the TSA had singled out Abdulmutallab for enhanced screening or identified him as being on the no-fly list, how does it ensure that Dutch or Nigerian airport security take appropriate action? If a Dutch or Nigerian equivalent of the TSA have special requests with respect to a particular passenger departing from the US en route to the Netherlands or Nigeria, would the TSA automatically comply in reciprocal fashion? Note that according to an editorial in the New York Times, the TSA can still request a US-bound flight to return to its point of departure if there is a suspicious passenger on board, but for long distance flights, this option may become unfeasible if the request is not received until later stages of the flight.

Suggestions for changes already began to be voiced soon after the incident. Among the calls for improvements to security that have emerged in public discourse, the notion of making more use of body scanners, such as millimeter wave scanners, has been particularly prominent--notably former US Department of Homeland Security Secretary, Michael Chertoff, has been among those advocating this move (see here) (although it later came to light that Chertoff’s company, the Chertoff Group, has a manufacturer of such machines as a client). Some commentators, however, have argued that such full-body scanners would have failed to detect the explosive device in this case. The Telegraph has cited two former US officials from counter-terrorism agencies for having long argued that swabbing for explosive substances and other chemicals is “cheaper, easier and more effective” than full-body scanners. In that article, Larry Johnson, former deputy director of Counter Terrorism at the US State Department was quoted as saying “[s]wabbing everyone is not hard and it’s just about the only way, short of making passengers fly naked and without luggage, of being reasonably sure they aren’t carrying a bomb.” Although swabbing would entail making bodily contact with the swabs, for some--if not most--it may raise fewer privacy concerns than the full-body scanners. The Telegraph article suggests that the swab tests would not need to be taken from the same part of the body or baggage where explosives were located. That means that contact with sensitive areas of the body could be avoided.

In Part II, I’ll discuss databases and watch lists.

Wednesday, October 7, 2009

Comment: Lies and Faces

The ABA Journal has published an interesting article on ongoing efforts to develop a better lie detector. Particular focus is placed on the use of various technologies such as EEGs and MRI to obtain a picture of brain activity. But the article also discusses the use of technology to examine eye movement and detect minute changes in facial expression. A number of critics have questioned the reliability of such methods. Given that the article appears in a publication of a lawyers’ professional association, it is not surprising that it places particular emphasis on the potential use of these technologies to develop evidence to be used in criminal prosecution. But, are there other ways that these methods might be implemented in the counter-terrorist context? Many of us have been put through little interview sessions at the airport during “heightened threat levels” before being permitted to board a flight. The idea behind these interviews being that the observation of our behavior when answering these questions as well as the actual content of the answers themselves might give us away if we have anything sinister planned. Immigration officials also generally ask us some questions before allowing us to enter a different country – although these interviews have a broader purpose than merely trying to ferret out terrorists. Might some government decide these interviews could be made more effective if we were having our brain activity, eye or facial movements scanned while they were being carried out?

On the subject of facial recognition technology, this area seems to be getting more and more attention, particularly in the security sector. There’s been a project at the University of Zurich which examined facial expression and emotion as well as their relevance for facial recognition technology. In order to be effective, this kind of technology will have to match faces that change in all manner of ways in the course of everyday human activity to static ID-photos that have been recorded in a database.

There’s also been a thread of research that has aimed at developing technology that can detect "abnormal behavior" or emerging dangerous situations - see for instance John's earlier post on INDECT. I can see how these two threads could merge where facial recognition technology would be used not only for identification but also in threat detection: i.e., the attribution of certain emotions to facial images could be used to determine whether dangerous or abnormal behavior is present.

Tuesday, September 1, 2009

Update: Registered Traveler

FederalComputerWeek reports that two members of the US House of Representatives have urged the TSA not to delete traveller information that is held in the TSA’s database for the Registered Traveler Program, the Central Information Management System (CIMS). The Representatives are concerned that the deletion of the data would hamper the continuation of the program.

I discussed the Registered Traveler Program in a post concerning the CLEAR program last month. Verified Identity Pass, Inc., mentioned in the FederalComputerWeek article, is the parent company of CLEAR.

Monday, August 3, 2009

Lack of Clarity with respect to fate of CLEAR data?

Anita Ramasastry recently wrote an article (Note: at the time of this post, this link no longer pointed to the correct article; until this problem is corrected, you may find the original article here in Google's cache) for FindLaw discussing the imminent demise of CLEAR—a private company which worked in conjunction with the Transportation Security Administration to offer customers less hassle at airport security in exchange for giving up some of their privacy (and payment of an annual membership fee). Perhaps it was inevitable that some enterprising American would develop this kind of business model following the ever increasingly burdensome and inconvenient security measures being imposed at airports subsequent to 9/11. One might question, however, whether the federal government should have allowed it (See also this article for criticism that CLEAR failed to deliver on its “promise”). The business model was made possible by the TSA’s "Registered Traveler" program.

Although CLEAR was not the only provider of such services in the US, it was the most popular with approximately 165,000 members, according to Ramasastry. She reports that members had to provide CLEAR with biometric data in the form of fingerprints and iris scans to participate in the program. This data was then encoded on the member’s CLEAR card, which had to be tendered to bypass the standard security checkpoint lines. Now that CLEAR is going out of business, what will happen to all the personal data they hold, Ramasastry asks: Will it be sold to one or more other companies? Will the TSA claim it? What say does each member have as to what will happen with his or her data?

Unlike the EU, the US doesn’t have any overarching legal instrument that establishes a basic framework for the handling of personal data. And as Ramasastry points out, CLEAR, as a private company is not subject to the same kinds of privacy regulations as government agencies. But should companies that operate in this area not be subject to the same privacy standards as government bodies? Or should the TSA be authorized to intervene to secure personal data on behalf of former customers of CLEAR? An announcement on the CLEAR website reassures customers of its commitment to protect their personally identifiable information. Yet, even assuming CLEAR had a strong corporate privacy policy in place, it’s UNclear how the company will ensure that that policy is upheld if it ends up being liquidated in bankruptcy. Not to mention, former customers may find it difficult if not impossible to seek compensation for any violation of the policy. The website also speaks of TSA/ federal requirements. But, one source has suggested that neither TSA nor the Dept. of Homeland Security have any relevant requirements in place. The TSA website itself states that “all RT [Registered Traveler] service providers were obligated to follow data security standards to continue offering service [following the initial pilot project]. Each service provider's use of data, however, is regulated under its own privacy policy and by its relationship with its customers and sponsoring airport or airline.” (emphasis added) The only data usage requirement that the TSA imposed may have been that “RT service providers . . . use customer data only for purposes of the RT program unless customers expressly opted-in to other uses.”

In the meantime, the other two Registered Traveler operators, FLO, Corp. and Vigilant Solutions, have reportedly also both closed down the special security clearance lanes they operated at US airports.

Friday, July 3, 2009

What Powers Should Airport Screeners Have?

The Wall Street Journal has published a story which asks whether the US agency that conducts security screenings at US airports, the Transportation Security Administration (TSA), hasn’t begun overstepping its authority. The story discusses two recent US federal cases which have challenged the legality of searches and seizures conducted by the TSA. One case, before the district court for the Southern District of Ohio, concerned the seizure of three fake passports. That case has already been resolved with the finding that the seizure did not comport with the Fourth Amendment of the US Constitution. The second case is evidently still pending before the U.S. District Court for the District of Columbia.

In the Ohio case, Judge Algenon L. Marbley found that Congress has only authorized the TSA to search for weapons and explosives; therefore, when the TSA searches for other things, it goes beyond its mandate. Yet, according to the Journal’s story, TSA is “now training airport screeners to spot anything suspicious, and then honoring them when searches lead to arrests for crimes like drug possession and credit-card fraud.” This charge is reminiscent of reports that Federal Air Marshalls were expected to meet quotas in terms of the number of “Surveillance Detection Reports” they filed which were also tied to salary raises, awards, and bonuses (Note: The Air Marshalls are also under the authority of the TSA).

The story and court cases raise a number of significant questions in terms of air transportation policy: Should the individuals who conduct airport screenings have general police powers? Would it enhance the ability to ensure flight safety and counter terrorism? Is it necessary for these ends? The scope and limits on the powers of screeners is likely to vary from nation to nation. Does that fact present a problem for effective counter-terrorist efforts?

Incidentally, Chris Soghoion has dedicated a number of blog entries to the TSA and his experiences with them, including one incident that involved the interplay of TSA and local police authority. Chris has long pointed out that the maintenance of a no-fly list is of limited effectiveness so long as individuals are permitted to board domestic US flights without some form of identification (Note TSA spokesman Greg Soule’s discussion of identity in the Wall Street Journal article).