Aug 31 2026

Airline reservations are still being used to target dissidents

Much of the public interest in the case of Samuel Tunick has focused on the charge — carrying up to a five-tear prision sentence — that  Mr. Tunick “destroyed property to prevent its seizure” by the government by giving Customs and Border Patrol (CBP) agents at the Atlanta airport a “duress password” for a smartphone Mr. Tunich was carrying when he returned from an international trip.

The phone seized from Mr. Tunick at the airport was running Graphene OS, an open-source variant of the Android operating system. When one of the CBP agents entered the password Mr. Tunick (under duress) provided, it wiped the phone’s user memory and reset the phone to a state as though the OS had just been installed.

The option to set a “duress password” that wipes the phone, in addition to one or more user passwords for separate user spaces, is a feature of Graphene OS intended to reduce the risk of coerced disclosure of data.

Mr. Tunick was arrested at the airport last December, but briefing on pre-trial motions is ongoing and no trial date is in sight.

This is an important test case on the issues raised by the “duress password”, the way it functions in Graphene OS, and compelled disclosure of passwords generally.

But there’s another concerning issue raised by the facts in this case: How airline reservations were used to target Mr. Tunick, in advance, for special treatment on arrival including seizure of his phone and pressure to disclose a password for the phone.

Mr. Tunick wasn’t singled out for “secondary screening” at random or because of anything he said or did or was carrying that appeared “suspicious” to CBP agents at the airport.

According to a report of a motion hearing in July, the transcript of which has not yet been released, CBP agents were sent an automatically generated email message before his flight got to Atlanta, alerting them in advance that a person in whom they had previously indicated an interest had reservations on a specific airline, flight number, date, and time.

Read More

Aug 30 2026

SFO evades criticism of its role in immigration enforcement

[Excerpt from illegal contract awarded by SFO to SITA in violation of the S.F. Sanctuary City Ordinance describes facial recognition hardware, software, and services paid for by the City and County of San Francisco, deployed by SITA on City and County property at SFO, and used to collect and transit mug shots of passengers and “permission to board” messages between airlines, the airport, and CBP/DHS, for purposes including immigration enforcement.]

At the San Francisco Airport Commission meeting on August 15th, a dozen members of the public (video, Mission Local, SF Public Press) called on the Airport Commission to comply with San Francisco’s “Sanctuary City” ordinance, which prohibits use of S.F. City and County resources — including airport property and funds — for immigration enforcement.

Another 35 people sent written comments to the Airport Commission on the same subject.

Many of the commenters, who included including supporters of Indivisible SF, Bay Resistance, and the Identity Project, among others, explicitly endorsed the comments of the Identity Project and our specific requests for action by the Airport Commission.

The Airport Commissioners neither discussed nor responded to any of our criticism. But the Director of SFO, Mike Nakornket, opened the meeting by trying to preemptively deflect our criticism with a mix of false, untested, inadequate, and unresponsive claims about the city’s actions and legal authority as the owner, landlord, and operator of the airport.

False: Airport Director Nakornket  claimed that, “SFO is not involved in the sharing of passenger information for immigration enforcement  purposes, which we understand occurs on a federal level between DHS agencies.”

But the Airport Director should know that this isn’t true.

Read More

Aug 14 2026

DHS demands AAMVA’s national commercial driver database


The US Department of Homeland Security (DHS) has subpoenaed the American Association of Motor Vehicle Administrators (AAMVA) for a copy of all entries in the CDLIS national database of state-issued commercial driver’s licenses held by AAMVA. The administrative subpoena was issued August 11th and ordered AAMVA to hand over a copy of all records that were found in the CDLIS database any time in the last five years, by 8 am Monday, August 17th.

DOT says that “AAMVA operates the CDLIS database on behalf of the federal government; it is contractually and legally obligated to furnish the requested records at FMCSA’s direction.”

In response, a group of states led by Illinois has filed separate lawsuits in Virginia, where AAMVA is incorporated, against the DHS to quash the subpoena and against AAMVA and the US Department of Transportation (DOT) to enjoin AAMVA from complying with the DOT’s parallel demand for the same data.

US District Judge Anthony Trenga immediately issued temporary stays which prohibit AAMVA from complying with the subpoena and prohibit any actions by DOT to punish AAMVA for noncompliance with the DHS subpoena or DOT demand for CDLIS data. Initial hearings before Judge Trenga in both cases are scheduled for Thursday, August 20th.

We hate to have to say, “We told you so.” But in this case, we told you so.

The CDLIS database is the little brother for commercial driver’s licenses (for truckers) to the big brother SPEXS database for all driver’s licenses and state-issued ID cards. Like SPEXS, CDLIS is a national database of “pointer” records (including name, date of birth, state, license or ID number, and Social Security Number)  aggregated from information uploaded by state motor vehicle agencies but held by AAMVA or AAMVA’s contractors.

CDLIS (commercial license) and S2S (non-commercial license) pointer records are all stored in the same SPEXS database as part of AAMVA’s central site:

[Excerpts from AAMVA’s “SPEXS System Specification”]

We’ve warned repeatedly that once data is uploaded to AAMVA’s SPEXS database, Federal agencies could demand it from AAMVA in bulk. State authorities, most recently in California, have brushed off our warnings. But as conceded in declarations from the California Department of Motor Vehicles in one of the new cases, the California DMV has already been uploading CDLIS information about commercial driver’s licenses to SPEXS, and plans to start uploading “S2S” data about all California license to SPEXS in 2027.

The DHS is now seeking to obtain driver’s license data from every state, in bulk, through an administrative subpoena to AAMVA, for use for immigration enforcement, in exactly the manner and for the purpose we predicted and warned about.

AAMVA’s role is noteworthy and contemptible, although unsurprising.

AAMVA was sent a demand for the entirety of the CDLIS database on June 25th, but didn’t tell the states that had uploaded the data  in question about the Federal demand until almost a month later on July 23rd. State can’t count on prompt notice from AAMVA.

Even now, AAMVA isn’t  challenging the demand for CDLIS data. AAMVA is a defendant, along with the Federal agencies, in the lawsuits brought by states to protect their residents’ data against bulk disclosure to Federal agencies for immigration enforcement.

According to the complaints, the DHS and DOT have threatened to cut off all Federal funding for AAMVA, including funding for CDLIS itself (and presumably also SPEXS), if AAMVA doesn’t hand over the requested data. AAMVA depends on Federal funding, so it can’t afford to challenge Federal demands, making it in effect a captive proxy for the Feds despite being a nominally non-governmental private nonprofit corporation.

Presumably, the Feds will learn from AAMVA’s failure to challenge their demands for the data it holds. Next time, they’ll come back with a subpoena that includes a gag order prohibiting AAMVA from disclosing the subpoena to states that uploaded the data, so states will have no chance to file lawsuits like the ones filed this week.

The obvious next step after that would be a similar demand for SPEXS data about ordinary non-commercial licenses, probably as soon as California completes its planned bulk upload to SPEXS sometime early in 2027.

Officials in California and other states can no longer claim this isn’t possible.

State legislators need to act, now, to withdraw their states from SPEXS, before the DHS expands its data demands from the commercial licenses in CDLIS to all licenses in SPEXS.