<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tsa &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/tsa/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Mon, 02 Sep 2024 04:01:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>SQL Injection Attack on Airport Security</title>
		<link>https://noise.getoto.net/2024/09/02/sql-injection-attack-on-airport-security/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 02 Sep 2024 11:07:04 +0000</pubDate>
				<category><![CDATA[air travel]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[tsa]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69312</guid>

					<description><![CDATA[<p>Interesting <a href="https://ian.sh/tsa">vulnerability</a>:</p>
<blockquote><p>…a special lane at airport security called Known Crewmember (KCM). KCM is a TSA program that allows pilots and flight attendants to bypass security screening, even when flying on domestic personal trips.</p>
<p>The KCM process is fairly simple: the employee uses the dedicated lane and presents their KCM barcode or provides the TSA agent their employee number and airline. <a href="https://www.apfa.org/wp-content/uploads/2019/10/KCM-Program-Changes_OCT19.pdf">Various forms of ID</a> need to be presented while the TSA agent’s laptop verifies the employment status with the airline. If successful, the employee can access the sterile area without any screening at all...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>No-Fly List Exposed</title>
		<link>https://noise.getoto.net/2023/01/23/no-fly-list-exposed/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 23 Jan 2023 12:02:56 +0000</pubDate>
				<category><![CDATA[air travel]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[no-fly list]]></category>
		<category><![CDATA[tsa]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=66620</guid>

					<description><![CDATA[<p>I can’t remember the last time I thought about the US no-fly list: the list of people so dangerous they should never be allowed to fly on an airplane, yet so innocent that we can’t arrest them. Back when I thought about it a lot, I realized that the TSA’s practice of giving it to every airline meant that it was not well protected, and it certainly ended up in the hands of every major government that wanted it.</p>
<p>The list is back in the news today, having been <a href="https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotected-server-commuteair/">left exposed</a> on an insecure airline computer. (The airline is CommuteAir, a company so obscure that I’ve never heard of it before.)...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 34/58 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-08 12:43:02 by W3 Total Cache
-->