Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Waxman: TSA Website Exposed People to ID Theft

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
babylonsister Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-11-08 10:42 AM
Original message
Waxman: TSA Website Exposed People to ID Theft
Edited on Fri Jan-11-08 10:42 AM by babylonsister
http://oversight.house.gov/story.asp?ID=1680

Information Security Breach at TSA: The Traveler Redress Website

In October 2006, the Transportation Security Administration launched a website to help travelers whose names were erroneously listed on airline watch lists. This redress website had multiple security vulnerabilities: it was not hosted on a government domain; its homepage was not encrypted; one of its data submission pages was not encrypted; and its encrypted pages were not properly certified. These deficiencies exposed thousands of American travelers to potential identity theft. After an internet blogger identified these security vulnerabilities in February 2007, the website was taken offline and replaced by a website hosted on a Department of Homeland Security domain.

At the request of Chairman Henry Waxman, Committee staff have been investigating how TSA could have launched a website that violated basic operating standards of web security and failed to protect travelers’ sensitive personal information. As this report describes, these security breaches can be traced to TSA’s poor acquisition practices, conflicts of interest, and inadequate oversight.

The report finds:


o TSA awarded the website contract without competition. TSA gave a small, Virginia-based contractor called Desyne Web Services a no-bid contract to design and operate the redress website. According to an internal TSA investigation, the “Statement of Work” for the contract was “written such that Desyne Web was the only vendor that could meet program requirements.”

o The TSA official in charge of the project was a former employee of the contractor. The TSA official who was the “Technical Lead” on the website project and acted as the point of contact with the contractor had an apparent conflict of interest. He was a former employee of Desyne Web Services and regularly socialized with Desyne’s owner.

o TSA did not detect the website's security weaknesses for months. The redress website was launched on October 6, 2006, and was not taken down until after February 13, 2007, when an internet blogger exposed the security vulnerabilities. During this period, TSA Administrator Hawley testified before Congress that the agency had assured “the privacy of users and the security of the system” before its launch. Thousands of individuals used the insecure website, including at least 247 travelers who submitted large amounts of personal information through an insecure webpage.

o TSA did not provide sufficient oversight of the website and the contractor. The internal TSA investigation found that there were problems with the “planning, development, and operation” of the website and that the program managers were “overly reliant on contractors for information technology expertise” and had failed to properly oversee the contractor, which as a result, “made TSA vulnerable to non-performance and poor quality work by the contractor.”


Neither Desyne nor the Technical Lead on the traveler redress website have been sanctioned by TSA for their roles in the deployment of an insecure website. TSA continues to pay Desyne to host and maintain two major web-based information systems: TSA’s claims management system and a governmentwide traveler redress program. TSA has taken no steps to discipline the Technical Lead, who still holds a senior program management position at TSA.
Printer Friendly | Permalink |  | Top
Gormy Cuss Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-11-08 10:53 AM
Response to Original message
1. The first bullet point is enough to demand a senior level resignation
Edited on Fri Jan-11-08 10:55 AM by Gormy Cuss
The second bullet point identifies which one, the former Desyne employee. I'd bet money that this former employee has a financial interest in the firm.

edited to add link to old Wired.com story about this TSA page
http://blog.wired.com/27bstroke6/2007/02/homeland_securi.html
Printer Friendly | Permalink |  | Top
 
babylonsister Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-11-08 11:08 AM
Response to Reply #1
2. It's nice to see Waxman hitting it hard; these no-bid contracts
are rampant throughout this admin. I'm glad someone's hopefully going to do something about it.
How 'bout this one, from today? And that's not including the Halliburtons and Blackwaters out there...

http://www.democraticunderground.com/discuss/duboard.php?az=show_mesg&forum=389&topic_id=2659104&mesg_id=2659104
Printer Friendly | Permalink |  | Top
 
Gormy Cuss Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-11-08 12:27 PM
Response to Reply #2
3. I wish that the message would get out in the media as
"This is how your tax dollars are wasted."
Printer Friendly | Permalink |  | Top
 
Richard Steele Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-11-08 12:46 PM
Response to Original message
4. K&R
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Mon Apr 29th 2024, 12:34 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC