DEPARTMENT OF HOMELAND SECURITY AUTHORIZATION ACT FOR FISCAL YEAR 2008 -- (House of Representatives - May 09, 2007)
BREAK IN TRANSCRIPT
Mr. VAN HOLLEN. Madam Chairman, I yield myself such time as I may consume.
Madam Chairman, let me start by commending Chairman Thompson, Ranking Member King and the Homeland Security Committee on a bipartisan basis for their good work on this piece of legislation. I have an amendment that I hope will be agreeable to all sides.
In January of this year, the TSA launched a Web site. Some of you may have seen it. It was called the Traveler Verification Identification Program, and it was designed to allow those passengers who were wrongfully identified on the no-fly lists or the selectee lists the opportunity to start the process of getting their names removed from that list.
The way you did that was you go and you log on to the TSA Web site and submit sensitive security information and personal information, like your Social Security number, the place and date of birth, your drivers license number and other personal identification numbers in order to demonstrate and prove to TSA that you were not a ``person of concern'' on their list. That was an important step forward, a positive list. I think we have all heard the stories about individuals who were wrongfully placed on that list or whose identifications were mistaken for somebody else. So that was a good way to start to get people off the list.
But right after the launch of that program, they had to shut it down. The TSA had to shut down the site because, as was reported in The Washington Post and the high-tech magazine Wired, it was determined that the information that individuals were entering onto the TSA Web site was not secure, very personal types of information. Security experts found that the site lacked many of the basic measures necessary to protect personal information, no encryption devices, no other safeguards, and that the data being transferred to TSA was essentially vulnerable to being taken and used for identity theft and other purposes.
After these concerns were brought to the attention of TSA, they had to bring down the Web site. They put up another Web site and program in February called the Travelers Redress Inquiry Program.
Now, the TSA has said that it has made the necessary adjustments to protect this very personal and confidential information from exposure and theft, but it is not clear that they have taken all the measures that are necessary, especially in light of the fact that only last week we found out that a hard drive containing the personal data of almost 100,000 TSA employees disappeared.
Data security does not seem to have been taken seriously enough by the TSA. This amendment is designed to focus greater attention on that issue.
This amendment is very simple. It requires TSA to take the necessary steps required to protect the personal information submitted online by passengers, by our constituents, when they are seeking to remove their names from the no-fly list, the selectee list or other related lists. It is designed to get at a very specific problem that has arisen in recent months, and I urge its adoption.
BREAK IN TRANSCRIPT
Mr. VAN HOLLEN. Madam Chairman, I thank the gentleman, and I appreciate the point you are raising. As it says, such sums as may be necessary to address this issue. I wouldn't expect it to be a very large sum. TSA is telling us they have addressed this issue. I am not sure we are totally convinced. If we could get this amendment passed, obviously as we go through the process, if there is some claim that this is going to cost billions of dollars, I wouldn't expect it would, but I would be happy to work with the gentleman.
BREAK IN TRANSCRIPT