Hacker News new | past | comments | ask | show | jobs | submit login
Pornoscanners trivially defeated by pancake-shaped explosives (boingboing.net)
84 points by panarky on Dec 12, 2010 | hide | past | favorite | 36 comments



I was in 4 different airports in the US recently. Didn't have any problems in any of them.

I will note though that the big scanner off to the side that I saw in one airport had the product name:

"Rapiscan"

... which probably doesn't seem like such a good idea now to their marketing team.


The question is: is anybody surprised? (particularly curious about those at DHS/TSA, and scum like Chertoff... I'm guessing not)


I'm against security theater, but this sounds like an information visualization problem: if the image contains enough signal that a theoretically optimally trained eye can detect the contraband, they should be able to use machine learning algorithms to detect suspicious items and make them show up with higher contrast.

In other words, the software should magnify anything out of the ordinary, like contraband. It's not foolproof of course, but would help.


I think the issue is that if you can produce anything approximately the size and density of a gut, you can get it past a scan - no machine learning is going to be able to pick up something that for all intents and purposes looks like a normal beer belly.


Fully agreed that that's a real problem.


Sorry, but what you're suggesting is the equivalent of "every airplane should fly flapping its wings"

"if the image contains enough signal that a theoretically optimally trained eye can detect the contraband, they should be able to use machine learning algorithms to detect suspicious items and make them show up with higher contrast."

The type of processing which you'd run on an image to make it easy on the human eye is entirely different than what you'd do for ML applications.


I'm not talking about making it "easy on the human eye". I'm suggesting that they use the output from a classifier to make parts of the image stand out more.


They aren't meant to detect explosives. They are meant to detect weapons that the metal detector might not pickup

The explosive you would just put through the x-ray machine anyway where it wouldn't be detected.


> They aren't meant to detect explosives.

Yes, they are.

http://www.tsa.gov/approach/tech/ait/faqs.shtm

> Advanced imaging technology safely screens passengers for both metallic and non-metallic threats, including weapons and explosives, which may be concealed under a passengers’ clothing without physical contact to keep the traveling public secure.


That's a TSA website - it also claims that they are professionals working for our security.


The scanners may not do a good job of it, but it's pretty clear that one of the things they were sold as doing is detecting explosives.


Great headline based on a simulation. Says so in the second sentence of the abstract. Is it hard to do a test using real machines? What's stopping them?


The government and the manufacturer refuse to give people access to the machines.

And the government has refused to release testing data; EPIC's currently got a FOIA suit.


Why should the company that makes these machines allow access to them?


Shouldn't the airports or governments (or whoever is paying for these) test them properly?


That's true if their main concern is security, as opposed to security theatre.


I'm not even sure security simulation is the main concern at this point. it rather seems to be giving as much tax dollars to the companies who helped politicians get into office in the first place.


To me it seems that at this stage it's purely a matter of refusing to back down on any "security" measure because that could be interpreted as "letting the terrorists win" by political opponents or voters.


The money allotted to the TSA for the scanners was specifically part of a stimulus package (ba-da-bing!). It didn't directly have anything to do with security, more pass through grant to the scanner companies.


I'm really curious about this. People on HN are saying "oh it's just security theater" as if the TSA purchasing officials are knowingly disingenuous. I suspect the testing procedures are badly flawed and the TSA has no clue whether the devices that they buy work. Right now I don't haven enough data to say either way - lying or stupid. Both hypotheses fit the facts.


Suppose as you hypothesize the TSA really doesn't know whether or not they work and whether or not they pose radiation risks to travelers and TSA employees. But they've told the President and Congress that this is the only way to keep us safe and we absolutely must spend $2.4B.

Would you consider that 'lying' or 'stupid'?


I was proposing two hypotheses. First, TSA knows exactly what is going on and they are lying about it. Second, TSA's testing procedure is flawed so they don't know what is going on, but they may think that they do. So if they are using a flawed test without being aware of the flaws, 'stupid'. If they are using a flawed test and they know it, 'lying'.


Security experts are saying it's security theater. And they're right.


I completely agree. I'm questioning whether TSA knows that or not.


Well they could add up how many terrorists they have caught


Let's say a terrorist had a plastic container with a wirelessly detonatable bomb inside surgically implanted in his abdomen. After a few weeks to allow the incision to heal, the guy went through airport security. Given the number of implantable devices on the market, I bet the TSA folks are quite used to feeling the odd lumps of pacemakers, etc. on people's torsos. While the backscatter xrays might show a bunch of wires and such, would the image look much different than someone who had a pacemaker implanted with various leads into the heart? What if that guy was rubbed down with the bomb detection cloth pad (name?) which is then placed in the explosives detector? After a few weeks of being sewn up, would he trigger an alarm?

What's interesting about this scheme is that the bomb would be ready-to-go, and the terrorist could throw himself right before hitting his remote control button toward the area of the plane deemed to maximize the likelihood of death.

Is this scenario at all possible? How could the TSA possibly deal with it without harassing a bunch of people with pacemakers installed? If a single terrorist tries such a scheme, I predict that everyone with any sort of implanted object will have be added to some sort of pre-screening registry so the TSA can sort-of verify the legitimacy of the thing which shows-up on xray/pat-downs/etc.

As is obvious to most HN readers, the TSA's security measures can only make it more difficult for terrorists to operate. However, the scenarios thought to still be possible do not seem terribly sophisticated compared to the incentive to commit these acts.


Wow. There is a "Journal of Transportation Security"...


Cut the foreplay, TSA, we all know eventually we will have to get on the plane naked!

After a good cavity search.

Because, let's face it, all it takes is one bra-bomber and panty-bomber for this to become a reality.


Cavity searches aren't profitable.


Not sure why you got downvoted. You are correct in that the government can't exactly hand out a giant contrract for a cavity search scanner to some shadowy corporation with expensive lobbyists.


I liked my joke.


It would be very hard to conceal such conformally-packed explosives from sniffers and dogs.


I've been through a few airports since 9/11 and I've yet to see dogs patrolling security checkpoints.


You can't use dogs for static defense because they can only stay on task for so long. After 10-15 minutes of bomb sniffing the dog needs to take a break. You would need several dogs (and handlers) per checkpoint, which is cost ineffective.


If we had systems that sniffed for chemical residue of explosive compounds we wouldn't be having an argument about ineffective and silly porno-scanners, because they wouldn't be used.


Admittedly early for me, but I read the headline very differently.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: