Cyrus Farivar’s Freedom of Information Act request revealed that the federal government retains extensive passenger name records, including full credit card numbers stored without encryption. This practice highlights a critical security failure, as sensitive financial data is transmitted and kept in plain text, violating basic cybersecurity standards and creating significant risks for public data exposure. Furthermore, the investigation indicates that Customs and Border Patrol retains these records far longer than their stated five-year policy, with some data dating back to 2005. This discrepancy suggests a lack of adherence to retention limits and raises serious concerns about the scope of government surveillance and the extent to which private travel details are preserved indefinitely without adequate oversight or transparency. This case is highly relevant to open data because it exposes how government agencies handle, store, and potentially misuse personal information obtained from private sector transactions. It underscores the urgent need for strict data protection standards in public records and demonstrates how transparency mechanisms can reveal systemic security vulnerabilities and privacy violations within state surveillance infrastructures.
Source: techdirt.comPublished on 2024-07-28