Podcast
Root Causes 275: No Fly List Stolen


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
February 6, 2023
In a recently revealed security breach, an attacker gained a copy of the full 2019 TSA No Fly list, including subject PII. This breach was enabled by failures in digital identity and encryption. Join us in unpacking what happened and the lessons to be learned.
Podcast Transcript
Lightly edited for flow and brevity.
So, it’s funny what is overlooked and something like a no-fly list you think that’s pretty sensitive stuff. But it doesn’t affect me and my job at the whatever government organization is responsible. So whatever. I’m sure that the reason why it’s even in a CSV is because as these things are shared with computer systems that belong to airlines it’s just easy to feed. It might have been just a DBA at United or whatever that said, hey can you just send me that in a CSV file and I’ll plug it into my computer database.

