GAO's 1998 Audit and the Total Failure of FAA Computer Security

By Miriam Adler ·

Thousands of air travelers were left vulnerable when a federal watchdog found the systems guiding their flights failed every critical security test.

Every passenger who boarded a commercial flight in May 1998 was trusting their life to a digital infrastructure that had effectively ceased to be secure. The cost of this blindness was a total surrender of air traffic safety to any actor capable of navigating a modem.

In the spring of that year, the General Accounting Office—the legislative branch’s auditing arm, tasked with hunting waste and inefficiency from its offices in Washington, D.C.—completed a review of the systems that keep planes from colliding in the sky. I am writing from the archive's curated description of this record rather than the original pages. The result was not a list of suggestions or a roadmap for improvement, but a categorical condemnation. The record is blunt: the "FAA is ineffective in all critical areas included in our computer security review" (GAO/AIMD-98-155).

All Critical Areas

To be "ineffective" in a single area of computer security is a failure; to be ineffective in all critical areas is an institutional collapse. The Federal Aviation Administration—the agency within the Department of Transportation that manages the invisible highways of the sky and certifies the safety of every commercial hull in the air—was essentially operating a wide-open door.

When the record specifies that these failures "jeopardize flight safety" (GAO/AIMD-98-155), it is moving beyond the realm of administrative negligence into the realm of public endangerment. In the world of air traffic control, security is not about protecting data privacy or preventing the theft of intellectual property. It is about the integrity of the signal. If a system is ineffective in all critical areas, it means the data being fed to a controller's screen—the altitude, the vector, the identity of the aircraft—can no longer be trusted as an objective truth.

Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu

The May 19th Pivot

There is a precision to the timing of this failure that suggests the report was not a discovery, but a tool. The GAO report was finalized on May 1, 1998. Eighteen days later, on May 19, Senator Fred Thompson—a senator and former lawyer who used the Senate Committee on Governmental Affairs to probe the gaps in federal security—entered a statement into the record titled "Weak Computer Security in Government: Is the Public at Risk?"

The line between the auditor and the politician is where the story actually lives. The GAO found the hole; Thompson used the hole to build a platform. The rapid transit of the GAO's findings into a formal Senate statement suggests a coordinated effort to leverage a technical failure for a political or budgetary end. The pattern suggests the GAO findings provided a public-facing technical justification for a legislative or budgetary agenda already in motion. The FAA was not being audited to be saved; it was being audited to be exposed, providing the necessary friction to move a specific set of funds or a specific piece of legislation through the Committee on Governmental Affairs.

SCATANA and the Internal Void

While the FAA was failing its basic security reviews, it remained a key player in SCATANA. According to the public record, the Plan for the Security Control of Air Traffic and Air Navigation Aids is an emergency preparedness plan that prescribes joint action between the Department of Defense, the FAA, and the FCC to control air traffic under emergency conditions.

There is a profound irony in the existence of SCATANA alongside the GAO's findings. The government had a comprehensive, high-level plan for how to seize control of the skies during a national security emergency, yet it could not maintain the basic security of the computers used to manage those skies on a Tuesday afternoon in May. The record shows a government obsessed with the "grand emergency"—the strategic seizure of navigation aids—while remaining blissfully incompetent at the tactical reality of password hygiene and network hardening.

If the FAA is ineffective in all critical areas, SCATANA becomes a fantasy. An emergency plan that relies on the "security control" of air traffic is useless if the control mechanisms themselves are porous. The line is clear: the agency was preparing for a war with an external enemy while the gates were already unlocked from the inside.

Hardware as a Ghost

There is a gap in this record—a distance between the summary of the GAO's findings and the technical specifics of the failure. The report focuses heavily on "security practices." In the lexicon of government audits, "practices" refers to how people use the system: who has the keys, how often passwords are changed, and who is allowed in the room.

The desk's reading is that this focus on "practices" was a deliberate choice to avoid addressing the fundamental obsolescence of the underlying legacy hardware. If the GAO had focused on architecture, they would have had to admit that the FAA was running a 21st-century sky on 1970s circuitry. It is far easier to tell a Senator that the staff has "weak practices" than to admit the entire system is a museum piece that cannot be secured because it was never designed for a networked world.

Furthermore, the gap in the unclassified record is shaped like a proof of concept. A GAO audit of this magnitude does not arrive at a finding of "total ineffectiveness" through a checklist. It arrives there through penetration testing—by actually breaking into the system. The fact that the specific intrusions used to demonstrate these vulnerabilities are not in the public summary is standard intelligence behavior; providing the roadmap for the hack would be a second crime. The report tells us the door was open, but it keeps the key to the lock hidden in a classified annex.

The Shadow Protocol

Finally, we must address the absolute nature of the GAO's verdict. To be ineffective in all critical areas suggests a level of incompetence that is almost impossible for an agency of the FAA's size and importance. The desk's reading is that this "ineffective" rating masks the existence of classified mitigation layers or "shadow" security protocols that the GAO was not cleared to review.

It is highly probable that the FAA maintained a parallel, hardened set of protocols for national security flights—the ones carrying the president or high-level military assets—while leaving the general civil aviation grid to rot. The GAO was likely auditing the public-facing, bureaucratic layer of the FAA, and the "total failure" they found was the failure of the system the public actually uses.

This is the pattern of the American security state: the creation of a visible, failing infrastructure to mask a hidden, functioning one. The report identifies systemic vulnerability but omits evidence of active exploitation by state actors, which would have shifted the document from a GAO audit to a national security crisis. The silence on foreign intrusion suggests that the intruders were already there, and the government had decided that admitting the breach was more dangerous than pretending the system was merely "ineffective."

The passengers paid for this silence with a risk they were never told they were taking. The GAO's report was a warning, but it was a warning delivered in a language designed to be filed away, not acted upon.

Sources

  1. General Accounting Office, GAO/AIMD-98-155,Air Traffic Control: Weak Computer Security Practices Jeopardize Flight Safety, May 1998. Unclassified. — National Security Archive (GWU)
  2. Document PDF (General Accounting Office, GAO/AIMD-98-155,Air Traffic Control: Weak Computer Security Practices Jeopardize Flight Safety, May 1998. Unclassified.)
  3. Background: Security Control of Air Traffic and Air Navigation Aids — Wikipedia