| Page 2 of 2 < |
Fliers' Data Left Exposed, Report Says
|
Discussion Policy
Comments that include profanity or personal attacks or other inappropriate comments or material will be removed from the site. Additionally, entries that are unsigned or contain "signatures" by someone other than the actual author will be removed. Finally, we will take steps to block users who violate any of our posting standards, terms of use or privacy policies or any other policies governing this site. Please review the full rules governing commentaries and discussions. You are fully responsible for the content that you post.
|
According to the report, the primary author of the contract's requirements was Nicholas Panuzio, a TSA official who also was assigned an oversight role of the Web site. Panuzio "had a prior relationship with Desyne" that included having worked for the company for eight months several years earlier, the report says.
Panuzio had also known the company's owner since high school and "still met regularly with Desyne's owner and others for drinks and dinner," according to the report.
Panuzio could not be reached for comment yesterday.
The report said Panuzio reported the conflict of interest to the agency's chief counsel but not to the project's managers. The report did not say when the disclosure was made, and a TSA spokesman was unable to pinpoint a time.
TSA officials said that Panuzio did not profit from the contract, which was valued at $48,816. "A thorough review determined that no disciplinary action was necessary," said White, the spokesman.
A few months after the site was launched, Chris Soghoian, a graduate student at Indiana University discovered that it was not secure.
Soghoian told investigators that the site's appearance "was so poor that he first suspected it was a 'phishing' site," or one set up by hackers to imitate official sites to lure people into giving personal information that could then be stolen, the report found.
Soghoian posted his concerns in February on a blog then picked up by news outlets, including a http:/

