<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Pontificus &#187; Security</title>
	<atom:link href="http://pontificus.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://pontificus.com</link>
	<description>Pondering the past, present and future...</description>
	<lastBuildDate>Fri, 12 Aug 2011 21:41:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>TSA Security Breach&#8230;</title>
		<link>http://pontificus.com/2009/12/tsa-security-breach/</link>
		<comments>http://pontificus.com/2009/12/tsa-security-breach/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 01:01:58 +0000</pubDate>
		<dc:creator>pontificus</dc:creator>
				<category><![CDATA[Government Incompetency]]></category>
		<category><![CDATA[War on Terror]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Terrorism]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[WOMAP]]></category>

		<guid isPermaLink="false">http://pontificus.com/?p=396</guid>
		<description><![CDATA[What terrorist needs an intelligence gathering operation when it has the Department of Homeland Security doing what it does best: screwing up? This time DHS decided to post a sensitive document &#8212; apparently not classified, but sensitive &#8212; online, detailing airport screening procedures, titled &#8220;Screening Management Standard Operating Procedures&#8220;.1 While the contents of the document [...]<div class="addthis_toolbox addthis_default_style addthis_" addthis:url='http://pontificus.com/2009/12/tsa-security-breach/' addthis:title='TSA Security Breach&#8230; ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div id="attachment_397" class="wp-caption alignleft" style="width: 160px"><a href="http://pontificus.com/wp-content/uploads/2009/12/tsa-screening-ciabadge.jpg" rel="shadowbox[sbpost-396];player=img;" target="_blank"><img class="size-thumbnail wp-image-397 " title="CIA Badge" src="http://pontificus.com/wp-content/uploads/2009/12/tsa-screening-ciabadge-150x150.jpg" alt="CIA Badge" width="150" height="150" /></a><p class="wp-caption-text">CIA Badge</p></div>
<p>What terrorist needs an intelligence gathering operation when it has the Department of Homeland Security doing what it does best: screwing up?</p>
<p>This time DHS decided to post a sensitive document &#8212; apparently not classified, but sensitive &#8212; online, detailing airport screening procedures, titled &#8220;<em>Screening Management Standard Operating Procedures</em>&#8220;.<sup class='footnote'><a href='#fn-396-1' id='fnref-396-1'>1</a></sup></p>
<p><span id="more-396"></span>While the contents of the document for the most part are obvious, it makes the search for potential exploits somewhat easier and less risky for a budding terrorist.</p>
<p>On the other hand, security through obscurity is never as secure as something that has been openly vetted. Perhaps DHS will now have the benefit of independent opinion on how to make their procedures better, though it remains to be seen how open DHS and TSA are to unsolicited input and opinions.</p>
<div id="attachment_401" class="wp-caption alignleft" style="width: 160px"><a href="http://pontificus.com/wp-content/uploads/2009/12/tsa-screening-section4.2.1.jpg" rel="shadowbox[sbpost-396];player=img;" target="_blank"><img class="size-thumbnail wp-image-401 " title="CIA WOMAP" src="http://pontificus.com/wp-content/uploads/2009/12/tsa-screening-section4.2.1-150x150.jpg" alt="CIA WOMAP" width="150" height="150" /></a><p class="wp-caption-text">CIA WOMAP</p></div>
<p>For curiosity value the document details the existence of a CIA program known as the <em>Worldwide Operational Meet and Assist Program (WOMAP)</em>.<sup class='footnote'><a href='#fn-396-2' id='fnref-396-2'>2</a></sup></p>
<p>It&#8217;s unclear what the program is, as a standard Google search only had 9 hits, all of them after the SOP document was released.<sup class='footnote'><a href='#fn-396-3' id='fnref-396-3'>3</a></sup> In any case, it&#8217;s likely the program will be renamed no later than next week.</p>
<p>The manual is also much clearer about what can be taken through security and what can&#8217;t. Naturally this list might change, but it reflects the status as of June 30, 2008.</p>
<div id="attachment_403" class="wp-caption alignnone" style="width: 310px"><a href="http://pontificus.com/wp-content/uploads/2009/12/tsa-screening-attachment6-1-2.jpg" rel="shadowbox[sbpost-396];player=img;" target="_blank"><img class="size-thumbnail wp-image-403 " title="Hazardous Materials 1" src="http://pontificus.com/wp-content/uploads/2009/12/tsa-screening-attachment6-1-2-150x150.jpg" alt="Hazardous Materials 1" width="150" height="150" /></a><a href="http://pontificus.com/wp-content/uploads/2009/12/tsa-screening-attachment6-1-1.jpg" rel="shadowbox[sbpost-396];player=img;" target="_blank"><img class="size-thumbnail wp-image-402 " title="Hazardous Materials 2" src="http://pontificus.com/wp-content/uploads/2009/12/tsa-screening-attachment6-1-1-150x150.jpg" alt="Hazardous Materials 2" width="150" height="150" /></a><p class="wp-caption-text">Hazardous Materials</p></div>
<h3>Update 1</h3>
<p>It seems the document was first published by the The Wandering Aramean.<sup class='footnote'><a href='#fn-396-4' id='fnref-396-4'>4</a></sup></p>
<div class='footnotes'>
<div class='footnotedivider'></div>
<ol>
<li id='fn-396-1'><a href="http://cryptome.org/" target="_blank">Get your copy from cryptome.org</a> <span class='footnotereverse'><a href='#fnref-396-1'>&#8617;</a></span></li>
<li id='fn-396-2'>Section 4.2.1 on page 36 <span class='footnotereverse'><a href='#fnref-396-2'>&#8617;</a></span></li>
<li id='fn-396-3'><a href="http://www.google.com/search?q=%22Worldwide+Operational+Meet+and+Assist+Program%22" target="_blank">Google it</a> <span class='footnotereverse'><a href='#fnref-396-3'>&#8617;</a></span></li>
<li id='fn-396-4'><a href="http://www.wanderingaramean.com/2009/12/tsa-makes-another-stupid-move.html" target="_blank">The Wandering Aramean</a> <span class='footnotereverse'><a href='#fnref-396-4'>&#8617;</a></span></li>
</ol>
</div>
<p style='text-align:left'>&copy; 2009, <a href='http://pontificus.com'>Pontificus</a>. All rights reserved. </p>
<div class="addthis_toolbox addthis_default_style addthis_" addthis:url='http://pontificus.com/2009/12/tsa-security-breach/' addthis:title='TSA Security Breach&#8230; ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://pontificus.com/2009/12/tsa-security-breach/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

