First look: body scanners

| Comments (2) | Security: Airport
I flew through Amsterdam on the way back from IETF Maastricht and got the opportunity—well, maybe opportunity isn't quite the right word, since I think it was mandatory—to try out the new body scanners they've installed at Schiphol. (My understanding is that they're millimeter wave, but they could be backscatter x-ray.) Anyway, it's pretty straightforward: you walk into the portal, hold your hands up in a goofy position for 5-10 seconds, and then walk on through.

I did get to see what it is the security screeners see on their display for few seconds. Looks like the public reports were right and they really don't get to see much. The display was maybe 8" diagonal with a sort of stylized figure (including hair, so either it's someone else or it's really stylized) with boxes that apparently indicate stuff that was detected. As I understand it, what's going on here is that the real image is shown somewhere else and then some screener elsewhere points out the regions of interest for local handling.

Here's something I've been wondering about: how are those signals transmitted to/from the screening room? Is it wireless or wired? If wireless, what's the security? If wired, do the cables run through an area that's potentially user-accessible. Interestingly, I didn't walk through the magnetometer, which means that the scanner is the sole line of defense for anything you carry on your body. An attacker who could control this network could, it seems to me, suppress warnings from the remote screener and walk through carrying anything he wanted. (They don't really do a complete pat down in many cases.) Another possibility would be to remotely subvert either the screening consoles or the scanner itself. There's sure to be plenty of software in both. Finally—even with a wired network—would be to monitor RF emissions off that network, constituting a privacy threat.

Anyone want to loan me a scanner?


Well that's odd. I left the IETF via Schiphol as well, but all four of us went through the magnetometer and were then subjected to the loving massage of Handsy McBody Search. We noticed that males were all being directed through the magnetometers and onto the crotch patdowns and all the females were going through the body scanners. We assumed the blatant discrimination was due to the large Muslim minority in the Netherlands.

They had one at Reagan National when I flew home from Usenix. No screens visible to passengers. The operator was somewhere else, presumably locked in a room. Communication with the security guards was via what appeared to be standard walkie-talkies. Assuming the security on those is poor, the attack vector against them is straightforward, assuming you can find a quiet place, within radio range, to set up your own base camp for an attack.

Annoying: "Please take *everything* out of your pockets."

First they took my pocket knife, then they took my nail clippers, then they took my shoes, and now they want me to completely f*#$(! empty out my pockets? I preferred those apparently ineffective puffer machines. At least you could keep your shoes on.

Leave a comment