Saturday, September 19, 2015

Hackers have created master keys to TSA-approved locks, and the TSA couldn’t care less

First, some background. In 2003, Travel Sentry introduced a new type of TSA-approved lock with a built-in backdoor. A TSA agent armed with the appropriate tools could open the lock, inspect the item, and then send the luggage on its way. The entire system was meant to ensure that officials could still search luggage without forcing consumers to give up all of their security in the process.For years, the US TSA (that’s the Transportation Security Agency, a division of Homeland Security) has recommended that travelers in the United States buy and equip their luggage with a TSA-approved lock. The ostensible reason for this is because it allows the agency immediate access to your bag in the event that it needs to inspect your luggage rather than requiring agents to cut the lock physically in order to inspect its contents. Now, a team of hackers have demonstrated that the seven master keys that collectively open every TSA-approved lock ever manufactured have been broken.

The TSA has recommended that passengers use these locks on multiple occasions, despite growing concern that the devices might be compromised. This week, Ars Technica proved that 3D printing could be used to print new master keys, thereby obviating the entire point of buying a TSA key in the first place (at least, as far as security is concerned). Granted, luggage isn’t particularly secure, with or without a key, since soft-sided luggage can be cut or the zipper compromised, but it’s still embarrassing for an organization that holds itself forth as the gold standard in security theater safe travel.
Oops
The Intercept   reached out to the TSA to discover how the organization intended to respond to the news and discovered it really doesn’t care. “The reported ability to create keys for TSA-approved suitcase locks from a digital image does not create a threat to aviation security,” wrote TSA spokesperson Mike England in an email to The Intercept.
“These consumer products are ‘peace of mind’ devices, not part of TSA’s aviation security regime,” England wrote.
It goes without saying that the TSA has never listed “peace of mind” as a reason for purchasing a specific, TSA-approved key. But there’s more at stake here.

Backdoor metaphor

The problem with the TSA key is that it relied on the idea that only the “right” people (read: TSA officials) would have access to the proper keys. So long as that was true, luggage was arguably secure (though the TSA has acknowledged its own problems with theft in various blog posts over the years). Once a single photograph showed how the key teeth were patterned, however, the cat was out of the bag.
This is why backdoor encryption of the sort espoused by various government agencies is so incredibly dangerous. In the real world, keys get photographed, spies discover and leak codes, and even top-level cryptographic systems like the German Enigma of WW2 can be brought down by poor security practices, imperfect operation, or strokes of luck. Hackers have proven adept at chaining together personal information to create attacks against individuals by exploiting weaknesses of multiple services. Airport luggage may seem pedestrian compared to the advanced hacks that swarm across the modern web, but spear phishing — the practice of fooling users into revealing critical data about themselves to a person they think represents a legitimate business — is alive and well. The devices we lock down may be radically different, but the principles that ensure their security haven’t changed so very much.
Discovering that the TSA locks are just as worthless as you likely thought they were won’t change your life — but it’s a practical example of how backdoors can immediately destroy the security of a system.

No comments:

Post a Comment

Facebook Friends

Labels

Microsoft Nvidia Security Amd Google Android Apple Samsung Windows 10 Autos Science Smartphones Apps Automobiles Cars Encryption Gpu Intel Ios Iphone Nasa Pc Ps4 Software VW Volkswagen Xbox One 3d Printing Gaming Gtx 980 Hardware Internet Maxwell Mobile Operating Systems PC Gaming Privacy Ps3 Tesla Wearables Windows diesel diesel engines pollution space 3d Printers 4g 8K Apple Car Astrophysics BMW Comcast Cpu Developers Directx 12 Displays Google Fiber Graphics Gtx 970 Holograms How-To ICar Lte Malware Medicine Memory Nanoparticles OLED Oculus Rift PCS Piracy Project Morpheus Quantum Entanglement Robotics Smart Tv Spectrum Tablets Torrents Uhd Valve Virtual Reality Wearable Computing Windows 9 Wireless Communications Xbox 360 clean diesels diesels emissions government ipad lcd lg 1080p 2160p 21:9 34UC87C 3D 3d Photography 4K 4KTv A123 Systems ABP ARM AT&T ATS Acura RDX Ads Aero Air Gap Airmont Alienware Amazon American truck simulator App Apple Pay Apple Watch Apu Astronomy Asus Atmosphere Atom Audi Augmented Reality Auto Show Top Cars Auto Shows Avg Bandwidth Batteries Battery Life Bing Bittorrent Blizzard BlueStacks Bonan Brain Brains Branson Braswell Broadwell Business CALL OF DUTY: BLACK OPS 3 CNNIC Cameras Cancer Car Shows Carrington Event Certificate Authority Charging Chevrolet Equinox Chicago Auto Show Chips Chromebook Pixel Chromebook Pixel 2 Chromebooks Climate Change Console DX11 David Irvine Dci Deals Dell Diablo 3 Directx Dota 2 Downloads Dream Dx12 EPA EVs Eighth Generation Electric Vehicles Electromagnetic Electrons Enterprise Enthusiast Et European Union Exoplanets Female Festival Fiber Firefox 41 Fisker Karma Fitness Tracker Ford Explorer Ford Police Interceptor Formula E Fukushima Fukushima Daiichi Future GRIP Digital GTX Game Streaming Gamers Gchq Google Wireless Gorillapod Grid HDTV Health Heat Holographic Displays Holographic Storage Holographic Universe Holography Hololens Honda Pilot Htc Http Huang IETF ISPs Icera Illumiroom Imagination Technologies Imaging Inkjet Printers Internet Of Things IoT Iphone 6 Iphone 6 Plus Itanic Itanium Keller Kinect Kinectic Energy Kittson LED Laptops Lasers Latency Lenovo Lidar Light Liquid Metal Lithium-Ion Low Latency API MCS Holdings MCV MRI Machine Learning Magnetic Field Man In The Middle Mantle Masturbate Medical Medical Imaging Mercedes Microsoft Access Microsoft Excel Microsoft Office 2016 Microsoft Office 365 Microsoft One Microsoft PowerPoint Microsoft Research Microsoft Word Miscrosoft Mobile Computing Model S Modems Modems 0 Comments Mozilla Muon Tomography Mvno NOx NSA Navigation Net Neutrality Networking Neural Networks Neurology Nexus 6 Noaa Nokia Note Nova Nuclear Nuclear Power Nvidia Shield Office 365 Online Ouya Overclocking Paid Paintings Palmer Particles Performance Photography Physics Pirate Bay Plaintext Plasma PornHub Pornhub Wankband Porsche Poulson Power VR Project Tango ProtocolI Qualcomm Quantum Computing Quantum Mechanics Quantum Physics R9 290X RAM RPV Radeon Richard Branson Russia SCS SEC SLS SOEDESCO SSL/TLS Same-Day Delivery Samsung Galaxy Note SanDisk Scanning Sdk Search Seattle Senate Launch System Servers Setup Sharp Shield Silvermont Siri Slideshow Smartphone Smartwatches Snowden Society Soft Robotics Software As A Service Solar Sony Sound Sound Waves Spacetime Spectroscopy. ESO Spying Stars Steam Stellar Dynamics Observatory SDO SunLock Superfish Swarm TDI THQ TPB TSA TSA locks Tegra Terrible Posture Games Titan Titan Black Titan Z Torrentfreak Tower of Guns Toyota Avalon Toyota Camry Toyota Corolla Travel Sentry Uhdtv Ultra VR Verizon Versioning Very Large Telescope Video Games Virgin Virgin Atlantic Virtualbox Virtualization Viruses Voice Wankband Wide Wifi Windows 10 Technical Preview Windows 8 Windows Nt 6.4 Windows Phone WindowsI Wireless Spectrum World Of Warcraft Xbox Xbox Live Xeon Yahoo Yandex Zen ai apollo artificial intelligence artist backdoor biology bitcoin blender block broadband broadcast car sales chain chrome clean diesel corporate fraude court cpus diesel emissions dreamcast edgeadblock plus electric cars etherium ets ets2 euro truck simultor euro truck simultor 2 exploration fifth amendment fingerprint firefox freedom game development game theory games genetic engineering geometry gtx 980m heed Martin high speed cameras iMo iMove ibm internet explorer k12 konami language learning licenses mars math metal gear solid metal gear solid 5 microSD microsoft office missions mobile gaming model e model x moon nano-optics nanotechnology netflix orion os pHTTP/2 pachinko passcode programming robots rock paper scissors scandinavian security theater sega self-incrimination smart contracts space launch system telecommunications terahertz trucks tv waveguides x86