CommuteAir took down a 2019 copy of the US No Fly List, after a researcher said they found it on an unsecured server and that it had 1.5M+ entries, many aliases
One of the most sensitive U.S. government documents was left online. — An unsecured server discovered by a security researcher …
What distinguishes the report is that the exposed material was a 2019 copy held by an airline and included more than 1.5 million entries and aliases. It highlights the security burden created when highly sensitive government-derived lists move into operational systems outside their original custodian.
First-order effects
CommuteAir removed the exposed 2019 list after the researcher’s report, ending public access to that server copy.
People and organizations represented in the list face exposure of identifying entries and aliases from a dataset described as highly sensitive.
Second-order effects
The earlier DHS takedown of an unsecured watchlist makes other holders of government-derived screening data more likely to review public-facing servers and retained copies.
Airlines and travel-system vendors handling screening-related records face greater pressure to inventory backups and access controls, not just protect live databases.
Third-order effects
Repeated exposures of watchlists, airport data, and intelligence files point to a governance problem centered on proliferating copies of sensitive records across operational infrastructure.
If the pattern persists, security accountability will increasingly hinge on how agencies and contractors control retention and hosting of derived datasets, rather than on the original list alone.
The trend: Sensitive government and travel-security data is becoming harder to govern as operational copies and backups spread across third-party infrastructure.
NEW: The federal No Fly List was exposed on an open server discovered by a security researcher last week. The list, which was being stored by the US airline CommuteAir, contained over 1.5 million rows of data including names, aliases, & birth dates. https://www.dailydot.com/...
The entire US no-fly list - with 1.5 million+ entries - was found on an unsecured server by a Swiss hacker. Besides the fact that the list is a civil liberties nightmare, how was this info so easily accessible? We'll be coming for answers. https://www.vice.com/...
The list includes names and birth dates and more than 1.5 million entries, but many of those entries are aliases that all reference the same person. https://www.vice.com/...
A Swiss hacker writes about how easy it was to find an airline's open server and finding a very interesting file on it: NOFLY.csv, a 2019 copy of the @TSA no-fly list, with roughly 1.5 million entries. https://www.dailydot.com/... https://twitter.com/...
Asking as an alum of the “No-Fly List”: Is it still largely the names of Muslims, progressive pols & political dissidents? #NoFlyList https://www.vice.com/...
“Located by Swiss hacker known as maia arson crimew, the server, run by U.S. nat'l airline CommuteAir, was left exposed on the public internet. It revealed a vast amount of company data, including private information on almost 1,000 CommuteAir employees.” https://www.dailydot.com…
It's an old one from 2019 and the person who found it is being responsible and not just posting the list, but the airline has confirmed. @PeteButtigieg, call your office. Again. https://twitter.com/...