Aug 31 2026

Airline reservations are still being used to target dissidents

Much of the public interest in the case of Samuel Tunick has focused on the charge — carrying up to a five-tear prision sentence — that  Mr. Tunick “destroyed property to prevent its seizure” by the government by giving Customs and Border Patrol (CBP) agents at the Atlanta airport a “duress password” for a smartphone Mr. Tunich was carrying when he returned from an international trip.

The phone seized from Mr. Tunick at the airport was running Graphene OS, an open-source variant of the Android operating system. When one of the CBP agents entered the password Mr. Tunick (under duress) provided, it wiped the phone’s user memory and reset the phone to a state as though the OS had just been installed.

The option to set a “duress password” that wipes the phone, in addition to one or more user passwords for separate user spaces, is a feature of Graphene OS intended to reduce the risk of coerced disclosure of data.

Mr. Tunick was arrested at the airport last December, but briefing on pre-trial motions is ongoing and no trial date is in sight.

This is an important test case on the issues raised by the “duress password”, the way it functions in Graphene OS, and compelled disclosure of passwords generally.

But there’s another concerning issue raised by the facts in this case: How airline reservations were used to target Mr. Tunick, in advance, for special treatment on arrival including seizure of his phone and pressure to disclose a password for the phone.

Mr. Tunick wasn’t singled out for “secondary screening” at random or because of anything he said or did or was carrying that appeared “suspicious” to CBP agents at the airport.

According to a report of a motion hearing in July, the transcript of which has not yet been released, CBP agents were sent an automatically generated email message before his flight got to Atlanta, alerting them in advance that a person in whom they had previously indicated an interest had reservations on a specific airline, flight number, date, and time.

Read More

Aug 30 2026

SFO evades criticism of its role in immigration enforcement

[Excerpt from illegal contract awarded by SFO to SITA in violation of the S.F. Sanctuary City Ordinance describes facial recognition hardware, software, and services paid for by the City and County of San Francisco, deployed by SITA on City and County property at SFO, and used to collect and transit mug shots of passengers and “permission to board” messages between airlines, the airport, and CBP/DHS, for purposes including immigration enforcement.]

At the San Francisco Airport Commission meeting on August 15th, a dozen members of the public (video, Mission Local, SF Public Press) called on the Airport Commission to comply with San Francisco’s “Sanctuary City” ordinance, which prohibits use of S.F. City and County resources — including airport property and funds — for immigration enforcement.

Another 35 people sent written comments to the Airport Commission on the same subject.

Many of the commenters, who included including supporters of Indivisible SF, Bay Resistance, and the Identity Project, among others, explicitly endorsed the comments of the Identity Project and our specific requests for action by the Airport Commission.

The Airport Commissioners neither discussed nor responded to any of our criticism. But the Director of SFO, Mike Nakornket, opened the meeting by trying to preemptively deflect our criticism with a mix of false, untested, inadequate, and unresponsive claims about the city’s actions and legal authority as the owner, landlord, and operator of the airport.

False: Airport Director Nakornket  claimed that, “SFO is not involved in the sharing of passenger information for immigration enforcement  purposes, which we understand occurs on a federal level between DHS agencies.”

But the Airport Director should know that this isn’t true.

Read More

Jul 31 2026

“Can SFO rein in the feds?”

As discussed in a feature article today by Clara-Sophia Daly on Mission Local, recent searches and arrests of passengers trying to board domestic flights at San Francisco International Airport (SFO) have prompted us to question what the airport has done, and what more it could and should do, to comply with city ordinances regulating use of surveillance technology and restricting collaboration with immigration enforcement.

The arrest of Iryna Gorb by ICE at SFO on July 22nd and the search of Nikolas De Bremaeker by the TSA (and/or by Covenant Aviation Security, the contractor that supplies most of the checkpoint staff at SFO) at SFO on June 10th, raise questions about (1) the technologies in use to flag passengers to components of the Department of Homeland Security (DHS) based on airline reservations, (2) whether equipment owned or operated by the airport is used to collect data passed on the DHS, (3) what, if any, limits are placed on warrantless access by DHS agents to airport premises, and (4) whether the policies of the airport, as put in place by the SF Airport Commission as an agency of the City and County, comply with city ordinances.

For both domestic and international flights, the DHS requires airlines to send information about all passengers and their itineraries to DHS components starting 72 hours before departure.  Reservation and itinerary information for international flights is sent to US Customs and Border Protection (CBP) and included in its Automated Targeting System (ATS). Information for domestic flights is sent to the Transportation Security Administration (TSA) through its Secure Flight system.

No airline is allowed to issue a boarding pass for either a domestic or international flight unless and until it receives an individualized, per-passenger, per-flight permission message from the TSA or CBP in the form of a “boarding pass printing result” (BPPR). The default in the absence of a favorable BPPR is not to allow them to fly. These fly/no-fly decisions are based on a black box of secret algorithms that incorporate list-based rules (blocklists) and other rules based on other known and unknown data.

Once such a data collection and  algorithmic control mechanism is in place, it’s easy to add lists or other rules to the algorithm or add recipients to the data stream.

What’s less well known is that the DHS doesn’t just use the information it gets from airlines to decide whether or not to allow you to fly. It can also use this information to generate “handling codes” instructing checkpoint staff to conduct special searches of your person and property, or to generate messages to other agencies that may want to arrange an “unwelcoming” party to intercept you at the airport, on departure or on arrival, to question, search, or arrest you – with or without a warrant.

We question the legality of many of these activities. Many of them have not yet been reviewed or approved by any court, and have little or no basis in law.

Airline passengers need to know that, legal or not, this is happening.

Travelers also need to know that, as we were the first to report last year (see here and here) and as was later confirmed by the New York Times and American Oversight, some of the most intrusive and legally questionable aspects of these systems of surveillance and control of air travel, based on reservation data from airlines, have in the last year been expanded from international flights to domestic flights. Air travelers should beware.

Read More

Apr 21 2026

D.C. Circuit Court of Appeals keeps U.S. citizen on “no-fly” list

In an interlocking pair of decisions issued the same day by the same panel (one opinion written by the same judge who dissented from the other), the U.S. Court of Appeals for the D.C. Circuit has denied U.S. citizen Saad bin Khalid any meaningful review of the U.S. government’s decision to blacklist him and prohibit him from air travel to, from, within, or overflying the U.S. or on U.S.-registered aircraft.

Having been harassed by FBI and other U.S. agents every time he entered the U.S. since he was 16 or 17 years old, Mr. bin Khalid now lives in Pakistan with his wife and children.

The dissent from one of the two opinions tries hard to tease out a hypothetical procedural pathway to judicial review of a no-fly order in some circumstances. But the practical effect of this pair of decisions is that Mr. bin Khalid will have to fly to Mexico or Canada, then enter the U.S. by land, every time he he wants to return to the country of his citizenship. He will have to repeat that process in reverse to leave the U.S. and rejoin his family in Pakistan.

The knotted logic of both decisions rest primarily rests on 49 U.S.C. § 46110(c), a facially unconstitutional law stripping U.S. District Courts of jurisdiction over TSA “orders” and allowing review by Courts of Appeal only on the basis of the one-sided and secret “record” selected by the TSA for presentation to the Court of Appeals, with no confrontation of witnesses or adversary fact-finding at any stage of the process.

As the dissent sums up the problem in the panel majorities’ logic:

The majority ultimately reads section 46110 to strip the district court of more jurisdiction than it confers on this court. That means that neither we nor the district court can review Khalid’s claims that the Center improperly placed him on the terrorist watchlist.

The Court of Appeals also upheld the Constitutionality of basing this “no-fly” decision in part on evidence provided to the court but not to Mr. bin Khalid or his lawyers, and in part on evidence supposedly relied on by the Threat Screening Center to recommend blacklisting Mr. bin Khalid, but disclosed neither to Mr. bin Khalid, his lawyers, the Court of Appeals, nor the Administrator of the Transportation Security Administration (TSA) who was nominally responsible for the “order” adding Mr. bin Khalid’s name to the more than a million mostly Muslim names  on the U.S. no-fly list.

This was based on a finding  that  the right to travel by common carrier is not a “fundamental” right, and that in today’s world, the ability to travel by land or sea — between, say, Pakistan and the U.S. — is an adequate substitute for air travel:

Khalid may continue to travel to, from, and inside of the United States by means other than airplanes. As a result, the TSA Administrator’s order maintaining Khalid on the No Fly List does not infringe a fundamental right.

Given the unlikelihood that the Supreme Court will choose to review, much less overturn, these decisions of the Court of Appeals, what can be done?

The simplest way to insure that people like Mr. bin Khalid get their day in court would be for Congress to enact the Freedom to Travel Act. This bill would address each of the reasons that the Court of Appeals denied justice to Mr. bin Khalid. It would (1) write explicit recognition of the right to travel into Federal law, (2) create an explicit cause of action for deprivation of that right, and (3) removing TSA orders from the restrictions on judicial review in 49 U.S.C. § 46110(c).

Mar 22 2026

Your rights when an airport checkpoint is staffed by ICE agents

Last December we reported on indications that the Transportation Security Administration (TSA) had begun passing on information from airline reservations to Immigration and Customs and Enforcement (ICE) to enable targeting of domestic airline passengers for seizure and deportation. Ten days later, our report was confirmed by the New York Times.

In January, it was reported that ICE planned to set up immigration checkpoints for passengers on jetways at Minneapolis-St. Paul International Airport (MSP). That hasn’t happened, but the possibility prompted us to review some of the legal issues it raised.

Now President Trump has announced that starting Monday, March 23rd, ICE agents will be assigned to take over some of the work of TSA checkpoint staff, further merging and conflating the unrelated functions of aviation security and immigration enforcement.

What are your rights, especially as an airline passenger traveling within the US rather than seeking to enter or leave the country, if a checkpoint at the airport is staffed by ICE agents instead of, or in addition to, the usual TSA staff or TSA contractors?

Read More

Feb 11 2026

First-hand reports confirm you can still fly with no ID

First-hand reports confirm that some people can still fly with no ID card or documents, despite a new scheme of the Transportation Security Administration (TSA) to extort an illegal $45 fee from each airline passenger who doesn’t have, or doesn’t choose to show, ID that the TSA deems to be “compliant” with the REAL-ID Act.

As long as they pay the $45 fee, travelers with no ID or with noncompliant ID have been treated the same way as before the the TSA began demanding the fee on February 1, 2026:

We’ve seen no report of the TSA stopping travelers without ID or without REAL-ID from flying, as long as a they have paid the illegal $45 per person fee.

The only apparent change since the imposition of the $45 fee on February 1 of this year is that instead of phoning the TSA’s ID Verification Call Center (IVCC) and relaying questions and answers verbally between the IVCC and travelers without ID, TSA checkpoint staff are now using a laptop or tablet app to receive the questions and send back the  answers.

The TSA has complied with none of the legal requirements for notice and approval of the information-collection app being used for questioning of travelers without ID. This leaves it unclear whether a human is still involved in fly/no-fly decisions about travelers without ID or whether this decision-making has been delegated to secret algorithms encoded within the app or at the central site that connects the app to Accurint.

We haven’t yet seen any reports of what happens if a traveler without ID or without REAL-ID who hasn’t paid the $45 fee or tries to go through a TSA checkpoint, or doesn’t leave when told to do so. Nor have we heard what happens if a traveler without ID exercises their right to remain silent when questioned about their Accurint file by checkpoint staff. We expect that they would be arrested by local police and/or assessed a civil penalty by the TSA. The Paperwork Reduction Act provides a “complete defense” against any such penalties, but raising that defense would be risky and could be expensive.

Feb 05 2026

CBP keeps its app for US visitors secret

Should a visitor to the US have to install and use a US government app that runs secret code to collect an unknown amount of data using any or all of their phone’s sensors, connects to other unknown data sources and recipients, and uses secret algorithms based on that secret dataset to “auto-deny” some ESTA applications to visit the USA?

We say no — and so does US law.

In December 2025, US Customs and Border Protection (CBP) announced that it planned to shift the Electronic System for Travel Authorization (ESTA) from a website to an app, greatly expand the range of data collected from ESTA applicants, and delegate authority to the app to “auto-deny” some applications.

CBP proposed no rules to govern the proposed “auto-denial” of ESTA applications. We can find no basis in any law for such an automated decision-making procedure. But CBP gave notice that it intends to seek approval for this new and revised app-based collection of ESTA information from the Office of Management and Budget (OMB).

According to the Paperwork Reduction Act (PRA), the request for OMB approval must be preceded by notice of the proposed collection of information, followed by a window of at least 60 days for members of the public to review and submit comments on the proposal.

PRA regulations at 5 CFR §1320.8(d)(2) require that this notice include a complete copy of the proposed collection of information or instructions on how any member of the public can obtain a copy, free of charge, and still have 60 days to review and comment on the proposal.

But CBP didn’t include a copy of the code or any other part of the ESTA app in any format in its notice in the Federal Register. As the 60-day notice-and-comment window runs out, CBP  still has not responded to our repeated requests for this information.

As we note in the comments we filed with CBP:

Since the day this notice was published in the Federal Register we have been diligently, but to date entirely unsuccessfully, attempting to request and obtain a copy of the proposed collection of information from the points of contacts specified in the notice.

This isn’t just a procedural error. The failure to provide valid notice denies us and all other members of the public the opportunity to provide informed comment on the ESTA app, which would require an expert review and audit of the source code.

As of now, we’ve seen none of the user interface screens of the proposed ESTA app; none of the PRA, Privacy Act, administrative appeal rights and procedures, and/or other notices (if any) provided to users of the app; none of the code specifying what data is collected, transmitted, and received by the app;  and none of the code embodying the algorithms and specifying the data they use as the basis for “auto-denial” of some ESTA applications.

The proposal for collection of more information and robo-adjudication of the equivalent of visa applications would be a bad idea even if PRA procedures were followed. We’ll have much more to say about these proposals if and when CBP provides us with proper notice and a chance to inspect the workings of the proposed new version of the ESTA app.

If you’re an Android and/or iOS app developer who might be willing to volunteer your expertise to help us analyze and audit the workings of the ESTA app, if CBP ever publicly discloses its code, please get in touch.

But as of now, because the  notice was plainly invalid, OMB can’t legally approve the CBP proposal.

CBP must either withdraw or abandon this proposal or provide a valid new notice, with a complete copy of the ESTA app including its source code, followed by a new 60-day comment period. If CBP submits this proposal to OMB without first doing this, OMB must reject it as being in clear violation of the PRA regulations.

CBP isn’t using the standard Regulations.gov system for submission of comments on this proposal. If you want to submit your own comments, send them by email by to CBP_PRA@cbp.dhs.gov by midnight EST Monday, February 9, 2026. Be sure to include “Comments to CBP re: OMB Control Number 1651–0111” in the subject line of your email message.

Jan 29 2026

TSA plans illegal ID and fee shakedown starting Feb. 1, 2026

For more than twenty years, we’ve seen a never-ending succession of lawless empty threats made by the Transportation Security Administration (TSA) and Department of Homeland Security (DHS) — amplified by airlines, airport operators,  and state driver licensing agencies — to prevent ticketed airline passengers from exercising their right to travel by common carrier if they don’t have or show ID or show state-issued IDs not certified by the DHS as “compliant” with the Federal REAL-ID Act of 2005.

To date, none of these threats have been carried out.

Now the TSA is threatening, yet again unlawfully, that starting February 1, 2025 it will prevent any traveler from passing through a TSA or TSA-contractor checkpoint at a US airport with no ID or “non-compliant” ID unless they (1) pay an illegal $45 per person fee and (2) submit to as-yet undisclosed new “identity verification” procedures that are likely to include illegal demands for additional personal information.

What will happen on February 1st  if you try to fly without ID, or without REAL-ID, and without paying the $45 fee or answering more questions? Will the TSA stop you from flying? If so, how can you challenge the TSA’s denial of your right to travel?

Read More

Jan 16 2026

ICE plans immigration checkpoints at domestic airports

Doubling down on the TSA’s illegal scanning of domestic airline reservations for immigration enforcement —  first reported here and later confirmed by the New York Times — Immigration and Customs Enforcement (ICE) plans to station its agents on jetbridges to question and “check documents” of travelers boarding flights at Minneapolis-St Paul International Airport  (MSP), according to a memo to airport workers leaked by a whistleblower.

Like almost all US airports with scheduled passenger service, MSP is publicly owned and operated. The Metropolitan Airports Commission is governed by a regional board whose members are appointed by the Governor of Minnesota.

The next meeting of the Board of Commissioners is scheduled for this coming Tuesday, January 20, 2026, at 1 p.m. in Room LT-3048A, Terminal 1, MSP Airport. (This location is inside the checkpoint! See instructions at the bottom of this page for public access.)

Minnesotans and others who travel through MSP (it’s a Delta Air Lines hub for flights to and from other places throughout the US) should show up and demand that the Board kick ICE out of all areas of MSP except the customs and immigration inspection areas for arriving international passengers. The airport could also post signs at terminal entrances and jetbridges advising US citizens that they don’t have to show papers or answer questions.

The airports commission and the state of Minnesota have a compelling financial interest in keeping ICE from harassing or kidnapping passengers changing planes at MSP, so that transit passengers won’t start avoiding routes via MSP in favor of other airline hubs.

A Metropolitan Airports Commission spokesman told Fox 9 News that , “Federal regulations provide federal agents with broad access to MSP Airport property. This includes access to … pre- and post-security areas in the terminals.” This claim was repeated in a press release posted on the MAC website.

We can find no such Federal regulation, nor would there be a statutory basis for one. MSP and other airports are under no obligation to consent to ICE agents’ presence on jetbridges for arriving or departing domestic flights, unless they have a warrant, issued by a judge based on probable cause, to search a specific location. MSP can and should revoke any agreement it has entered into with ICE by which it consented to such an ICE presence.

It’s unclear what authority ICE would claim for access to most airport property without consent of the property owner — the airports commission — or for detention of US citizens who stand mute in response to their questions or requests to show their papers.

In the past, as we’ve testified in other cities, the DHS has lied to airport operating authorities and the public about the extent of its authority to override local laws.

MSP is a major international airport, and international customs and immigration inspection areas at airports are considered “ports of entry” and the functional and legal equivalent of border crossings. But we know of no court that has applied this doctrine to boarding gates, jetbridges, or passengers on domestic flights between points within the US.

The Twin Cities are more than 100 miles from any international border, so the rest of the airport or the metropolitan region isn’t subject to the claimed border-area exception allowing domestic immigration checkpoints.

Even if boarding areas or jetbridges for domestic flights at airports that handle international flights were held to fall within that exception, case law on border-area immigration checkpoints is clear: U.S. citizens do not need to have, carry, or show any documents or answer any questions. They must be allowed to proceed after only a “brief” delay unless there is probable cause  to believe that they aren’t US citizens. Not showing ID is not probable cause, nor is not answering questions about citizenship or anything else.

“Administrative searches” of airline passengers are limited to searches for weapons, explosives, and other threats to aviation security — no citizenship or identity documents. TSA directives to its staff and contractors say that “screening may not be conducted to detect evidence of crimes unrelated to transportation security.”

The Constitutional rules for stops, searches, or questioning by ICE or any other law enforcement officers on jetbridges are, so far as we can tell, the same as those for pedestrians or passengers in cars (not drivers) on public rights-of-way:

  1. Police need reasonable articulable suspicion of a violation of the law to stop you at all, even briefly. To protect your rights, ask them, on camera, as soon as they stop you, “What is the reason you are detaining me?”
  2. You don’t have to show any papers.
  3. You have the right to remain silent. (In some states, but not others, you might have to identify yourself verbally, if you are legally stopped based on reasonable suspicion, but you don’t have to say anything else or show any papers.)
  4. You may not be arrested merely for failure or refusal to have or show ID.
  5. You may not be arrested or detained more than “briefly” without probable cause to believe that you have committed a specific crime.
  6. You have the right to film and record law enforcement officers.

To protect yourself against wrongful arrest based on automated facial misrecognition, keep your mask on as much as possible, especially at boarding gates and on jetbridges.

If you are prevented from boarding a domestic flight at MSP or any other airport because you decline to show papers or answer questions from ICE or other Federal agents, please get in touch.

Jan 15 2026

TSA extorts $45 from each air traveler without REAL-ID

screenshot: Step 3: Show your receipt to the TSA officer and follow their instructions

Today the TSA launched a flagrantly illegal new extortion program, TSA ConfirmID,  to collect $45 from each airline passenger who wants to fly without showing REAL-ID.

As of today, only the payment platform for this “ID verification” program is operational. If you want to fly without REAL-ID on or after February 1, 2026, a new TSA video instructs you to pay $45 each through the Pay.gov website, bring your receipt to the TSA checkpoint at the airport, “show your receipt to the TSA officer and follow their instructions”.

Payments are accepted by ACH transfer from a bank account, credit or debit card, Venmo, or PayPal.

What will the TSA officer instruct you to do at the checkpoint? The TSA says that:

TSA will then attempt to verify your identity so you can go through security; however, there is no guarantee TSA can do so. Please note: Using TSA ConfirmID is optional. If you choose not to use it and don’t have an acceptable ID, you may not be allowed through security and may miss your flight.

The TSA says that you “may” not be allowed through the checkpoint, not that you “will” not. And the TSA’s FAQ says that, “In the event you arrive at the airport without acceptable identification (whether lost, stolen, or otherwise), you may still be allowed to fly”.

What are the procedures for this “attempt to verify your identity”? What are the criteria for  whether or not the TSA will allow you to fly? We don’t know.

A TSA propaganda video released last week falsely claims that, “Everyone knows that when you fly you have to bring a REAL-ID or a passport.” In fact, 200,000 people a day fly without REAL-ID and without a passport. (Any passport of any country is considered REAL-ID.)

It’s unclear what will happen to travelers who show up at TSA checkpoints on February 1st without REAL-ID, or with no ID at all, whether or not they have paid the $45 per person “TSA ConfirmID” fee. See our FAQ about your rights and what might happen.

As we pointed out when the TSA announced this plan in December, no law authorizes this scheme. No law requires airline passengers to have, carry, or show any ID — as the TSA itself has consistently argued, at least to date, when the issue has been raised in court.

The TSA has promulgated no regulations for “TSA ConfirmID”, has published no Privacy Act notice for the information collected from travelers either when they pay the $45 fee or when they go through the TSA checkpoint, and has neither requested nor received approval from the Office of Management and Budget (OMB) for this collection of information, as is required by the Paperwork Reduction Act (PRA).

“TSA ConfirmID” isn’t mentioned in any of the Privacy Act notices for the TSA’s systems of records. Operation of a system of records by a Federal agency without first publishing a proper notice in the Federal Register is a criminal violation of the Privacy Act on the part of the responsible  agency employees:

Any officer or employee of any agency who willfully maintains a system of records without meeting the notice requirements of subsection (e)(4) of this section shall be guilty of a misdemeanor and fined not more than $5,000.

Presumably, data collected from individuals who pay the $45 “TSA ConfirmID” fee is passed on to the TSA and stored in some (undisclosed) TSA system of records. The TSA officers and employees responsible for that system of records are, as of today, criminals.

Even the payment platform for the $45 fee is in flagrant violation of multiple Federal laws. The Pay.gov payment site and TSA ConfirmID payment form display no OMB control number, as is required by the PRA.

The Department of the Treasury, which operates Pay.gov, says specifically that:

An agency may not conduct or sponsor, and a person is not required to respond to, a collection of information unless it provides notice of a currently valid Office of Management and Budget (OMB) control number. Among other things, a notice of the expected time burden is required…. Pay.gov provides services to Federal agencies. These services include the posting of agency forms. Required notices that accompany these forms are the responsibility of those agencies.

There’s a link from the payment page to a Privacy and Security Policy, but the linked page doesn’t mention the Privacy Act, the PRA, or an OMB control number.

Since the TSA hasn’t chosen to follow the law or disclose any of its plans, the only way to figure out the de facto “rules” is to reverse engineer them from travelers’ experiences.

If you show up at a TSA checkpoint on or after February 1st without REAL-ID, or with no ID, please let us know whether or not you paid the “TSA ConfirmID fee” and what happened to you at the cehckpoint..

Keep a copy and/or take a photo or screenshot or any printed or online forms you are asked to fill out. If the forms or user interface pages don’t include a valid OMB control number, you can legally ignore them without penalty.

Are you allowed to fly without REAL-ID? With no ID? Without paying the “TSA ConfirmID” fee? If you are prevented from flying, who stops you? What do they say is the basis for their action?

You have the right to film and record at TSA checkpoints. Please share your experiences so we can better inform future flyers without ID or without REAL-ID.