Tuesday 21 October 2003 — This is 21 years old. Be careful.
Every time I read something Bruce Schneier writes about security, I agree with him: Terror Profiles By Computers Are Ineffective.
I have an idea. Timothy McVeigh and John Allen Muhammad — one of the accused D.C. snipers — both served in the military. I think we need to put all U.S. ex-servicemen on a special watch list, because they obviously could be terrorists. I think we should flag them for “special screening” when they fly and think twice before allowing them to take scuba-diving lessons.
What do you think of my idea? I hope you’re appalled, incensed and angry that I question the honesty and integrity of our military personnel based on the actions of just two people. That’s exactly the right reaction. It’s no different whether I suspect people based on military service, race, ethnicity, reading choices, scuba-diving ability or whether they’re flying one way or round trip. It’s profiling. It doesn’t catch the few bad guys, and it causes undue hardship on the many good guys who are erroneously and repeatedly singled out. Security is always a trade-off, and in this case of “data mining” the trade-off is a lousy one.
Comments
And as for "profiling", I am all for giving everybody the same once-over necessary for security. If that cannot be done, then some rational basis for determining a subset of the population for the afore mentioned "once-over". Pretending that there is some sense to shaking down 80 year-old grandmothers in an airport so to be able to "justify" talking to that single 20-something male with a one-way ticket is beyond political correctness, it is suicidal stupidity. And yes, he is likely to have a muslim name. I hate to point out the blindingly obvious, but 100% of the terrorists that are trying to blow our planes out of the sky are arab muslims. Again, pretending that this is not the case is suicidal stupidity.
Was Richard Reid an "arab muslim"? In some ways, yes, in some ways no. Would the profiling have caught him?
We're all reacting to the worst terrorist attack on US soil, and we need to react to it, but have we forgotten about the second worst terrorist attack on US soil? It was Timothy McVeigh. Would he have fit any of the profiling? Why do we think the next attack won't be from someone more like McVeigh?
The article references is remarkably content free. His claims that data mining and profiling are ineffective are not backed up with data or facts.
There are good reasons why racial profiling (muslim implies terrorist, black implies drug smuggler) is counter productive, but its not clear that data mining is the same as racial profiling. And in this case while he's specifically denouncing data mining, he makes implications that data mining is racial profiling by anecdotally enumerating the ethnicities of several terrorist. Yet he offers nothing that links data mining to racial profiling.
So, no I don't agree with the premise that "Terror Profiles By Computers Are Ineffective". They may or may not be, but he doesn't effectively make any case.
In his book, Schneier talks about unintended consequences of security measures. Privacy abuse is a disturbing consequence of these data mining programs. What data is being collected? Who has access to the data being mined? How secure is it? No really, how secure is it? How secure are the data mining algorithms? If terrorists can figure out what you're looking for, how likely will you be able to find them?
What if I end up being identified as a potential terrorist? How do I avoid getting hassled every time I try to fly? How do I question the logic that got my name on the list? Maybe the "data mining" software thought I was suspicious because I registered a scatological domain name ;-) How would I know? What if the decision to consider me suspicious was based on incorrect information? How could I question it or have the information corrected?
I'd rather that money be spent on hiring more people checking passports than on data mining technology.
--bob
- The Papers of Ben Franklin
It is true that the military has training-- but it's also true that any of that training includes instilling the most basic, fundamental patriotic values of all in the trainees.
In terms of metrics used for this kind of security, well, yes it's very difficult to deal with a problem where you have a few people willing to die for their cause. While (ex-/)military are also willing to die for a cause, in many cases having actually risked it, they're on the completely opposite side of the likelyhood spectrum, at least further from the side terrorists are on than the rest of us in the middle.
Talk about security through obscurity. Put me on the plane with the veterans. Who was it that said, if you fought for your country, your vote should count twice?
Profiling is a necessary evil, a crude risk evaluation tool. Is computer-based profiling better ? Well, compared against what ?
Richard Reid, for instance, did fit a profile. A Middle Eastern man with a brand new passport, no luggage and a one-way ticket paid in cash should definitely raise alarm bells. It doesn't follow the next one will, of course, but a Richard Reid should not get on a plane. Assuming Paris CDG security profiled passengers at the time, one could argue the fact that he did somewhat nails the profiling coffin. I don't know.
In the end, I think better profiling has a lower priority than basic security. When TSA agents can still get guns, pipe bombs or knives through security at Logan Airport, and the only consequence for the screeners involved is to get a remedial class, I must say profiling hassles are rather low on my radar screen. First things first. Before telling me how you're going to spot that anonymous terrorist in the crowd, please make sure you find the weapons and explosives in the luggage...
Add a comment: