JFK Displays Actual Wait Times Using Beacons That Monitor Mobile Phones
blipsystems.com
blipsystems.com
Blip, you make me laugh. You know this will raise privacy concerns and say the sweet nothings that placate the general public, but inspire no confidence in people who know what those words mean.
I'm not here to say that as a JFK traveler I'm unhappy with the privacy considerations. I just want to point out you're pretending your design is good on privacy when simple tweaks would show the security minded you gave half a shit. I don't mind this monitoring if it is limited to the uses described, your maneuvering simply makes me giggle.
A MAC may not be in whatever bucket you're calling "personal" but is certainly more personal than "non-personal" implies. Encryption is effectively a "we're doing it right" buzzword to the general public. What are your authorized uses for the data? What's your KMI? What data minimization techniques are employed? Do you purge old records? Replace the MAC with an identifier that can't be tied back to MAC once the target has left the line? Hash MACs on entry in a way that is both time-costly to bruteforce and results in a different hash every day?
I think the idea is a great one, it's unfortunate there isn't a better way (that I can think of atm) to do it, or like you said just some transparency on what they do with it. As simple as: "At the end of each day the encrypted mac addresses are completely erased from our system."
Seems like they do keep the info though, it says the Cincinnati airport kept it and used it for data analysis. In the end, I think this kind of thing most people will be okay with foregoing a bit of privacy for.
Edit: Interesting article on mobile MAC addresses down the comments: https://news.ycombinator.com/item?id=10097882#up_10098108
> The BlipTrack solution ... detects Bluetooth or Wi-Fi devices in “discoverable” mode
That doesn't make either situation okay for privacy-conscious people like you and I, but I personally feel like MAC address tracking is a relatively minor concern when it comes to privacy.
"It's 30 minutes, my kid has time to go buy a snack and eat it before we go through security."
"No, don't use the bathroom yet, the line looks long but it's only a 5 minute wait."
"I really hate airports, but it's a little less frustrating when I can see the wait time."
"The taxi line is 20 minutes long, maybe it's worth taking the subway instead."
etc.
Presumably the TSA managers will be rated based on their wait times, and therefore accountable when they're too lazy to staff the right number of people.
Last week I almost missed my flight at Oakland because they had everyone funneled through a single scanner. Two scanners were idle because they were "short staffed". That's not an accident or bad luck. That just means the manager was too lazy to do their job correctly.
There were a lot of people on this flight who were connecting on to other cities. We landed just barely in time to catch the last flight of the day to many of those cities, but most people had to be rebooked since that wasn't their original flight.
So we get off the plane and about two hundred of us need to be rebooked, and we get to the counter to discover a grand total of three people working there. To process two hundred people. Who all needed fast service. For a problem that anyone could have seen coming literally a day in advance.
A lot of people unnecessarily spent their nights in hotels rather than with their families that night, because nobody looked at what was going on and said, we should bring in some more people for this.
But yes, I'm sure it's all about bad incentives. Whoever takes the hit for overtime staffing doesn't also take a hit for hotel vouchers, even though it probably would have been cheaper overall for the airline to staff up and get people on their flights. (Not to mention the benefit of pleasing your customers.)
Follow the money, and all becomes clear.
Removing uncertainty provides for a better end user experience
> With this data, JFK is able to display accurate wait times to reduce passenger frustration and to notify staffing if areas in the terminal are becoming congested, so staff can identify and rectify bottlenecks before they escalate.
If you're confused about the first part, there is research that shows waiting for an unknown amount of time causes more anxiety than if the wait time is known. See e.g. http://davidmaister.com/articles/the-psychology-of-waiting-l...
https://www.nytimes.com/2012/08/19/opinion/sunday/why-waitin...
It's extremely practical, too. There is a lot you can do based on that number. For security, if the wait is extremely long and your flight is soon, you can try to plead your case to the security people. They'll often let you jump the line if your flight is departing soon, so yes, you can actually say "I guess I'll hurry." The information is available even if you're not in line, so you can plan accordingly.
For customs, you can't do much about your own situation, but you can tell people who are waiting for you how much longer you expect to be.
http://articles.latimes.com/2003/sep/29/nation/na-facescan29
Each passenger can be given a smart card along with the boarding pass (or embedded in the boarding pass). The sensors could merely check for the smart card at certain points and determine how long it took for the passenger to clear security, etc. The airline can then collect the smart card back just before boarding when they scan the boarding pass. Seems like a simple solution that would work without much privacy concerns.
> When a device passes the sensors, its non-personal unique ID, called a MAC address, is recorded, encrypted and time-stamped. By re-identifying the device from multiple sensors, travel times, average speeds, dwell times and movement patterns become available.
Aren't MAC addresses spoofed on most phones now?! I didn't expect a system like that to still be usable.
As for spoofed on phones, maybe if you have root. But i doubt it comes spoofed out of the box (at least i have never heard of such a thing).
This all sounds pretty good to me. Short-term tracking like this is useful and not very invasive. The randomization will still defeat long-term invasive tracking, like a store recognizing you from past visits and building up a database of your individual activity from that.
And of course you would only need a sample of passengers with static MACs for this to work.
Isn't that quite contradictionary?
Yep. It sure is. Know how spammers that don't run afoul of the CAN-SPAM act get really salty when you call their spam spam? The is the same sort of wordsmithing. By arguing that this identifiable information doesn't fall into the the "personal" bucket, they want the public to think what they're doing is A-OK.
They use weasel language to suggest following a standard of what "personal" data is means everything on the "not-personal" side is perfectly normal operation the consumer doesn't have to worry about. All while trying to derive as much personal information as possible from the not-technically-personal data.
Obviously any place where there are large groups of people would be a target for attacks of this kind.
On a separate note, the TSA really pisses me off. Consider that UPS saves millions by not taking left turns. Removing or adding very small inefficiencies at a very large scale has tremendous cost implications. I don't think these security lines add much security and I think they do that task at a much higher cost than most people think.
Have we? Maybe US passengers have been taught that better than elsewhere, but we don't really know due to the lack of hijackings to test that theory.
And internationally, of about a dozen hijackings post 9/11 only two I think have seen the hijacker get subdued by passengers - in one instance probably because there happened to be six police officers aboard; in the other instance it was a lone hijacker with a nail file...
Incidentally, despite 9/11, the odds of surviving a plane hijacking are still very high - the persons running the highest risk of getting killed in a hijacking are the hijackers. As it happens, 9/11 did not result in a string of copycat hijackers - most hijackers appears to still plan to survive the hijacking.
Since I'm old, I remember the decades during which we were taught to cooperate completely with hijackers. Of course this was always bad advice, as was eventually made clear even to the idiots on TV. It seems possible that if no terrorism "expert" had ever appeared on TV, 9/11 could have gone very differently.
That said, things like taking your shoes off, taking your laptop out, removing belts, etc. really slow down the xray machine line.
I assume that's to prevent targeting concentrations of foreign tourists.
I have no idea. To me, by far the most dangerous part of flying is the queue at the TSA checkpoints, especially at airports with particularly large checkpoints (I'm thinking EWR and probably ORD). I think some airports address this (SEA, MSP, JFK...maybe) by spreading out the checkpoints among smaller groups of gates to keep the volume of people at those checkpoints down. This is just my speculation, however.
I'd be curious to see how checkpoints have evolved over the last 14 years in terms of design and efficiency.
If a plane goes down, it's reasonable to expect that everyone on board will die. It's less reasonable to expect that the blast radius of a device that was sufficient to down an aircraft would be sufficient to encompass an equivalent number of people in the security line.
We can sit around and come up with thousands of possible attacks scenarios with less than 1% of the security that goes into preventing airplane hijackings. But that doesn't really matter. Airport security is primarily a political item, both responding to political pressures and fears, while generating entirely new ones.
You know, fight the cause rather than the symptom :-)
Read the article, was disappointed. It's still interesting tech though.