Wednesday, September 30, 2026

DOJ Sues Minnesota Over Gun Permit-to-Purchase Laws and Waiting Periods

The pistol and 9mm ammunition pictured are a stock image and were not identified as those used in the incident. iStock-944927264
Armed self-defense cannot wait on a government permission slip. DOJ is challenging Minnesota’s gun purchase-permit system and waiting periods as violations of the Second Amendment. iStock-944927264

On September 24, the Department of Justice took a huge step that could have major repercussions for gun control. The DOJ filed a lawsuit saying Minnesota’s firearm purchase permit and 30-day waiting period are unconstitutional.

Daniel Rosen, the U.S. Attorney General for the District of Minnesota, said:

“We are committed to protecting Minnesotans’ right to purchase firearms and we will not tolerate procedures that are wielded in a way that impairs that right.”

Assistant Attorney General Harmeet K. Dhillon of the Justice Department’s Civil Rights Division, said:

“Law-abiding citizens do not need government permission to purchase a firearm, and forcing a citizen who has already passed a background check to wait up to sixty days to obtain a firearm is intolerable under the Constitution.”

The suit is being brought against the state of Minnesota and the twin cities of Minneapolis and St. Paul. Minnesota’s original purchase permit law was enacted in 1977 but has been modified several times, most recently in 2025.

In 2023, the state expanded its waiting period from seven to 30 days, the same as the time limit for local police or the county sheriff to grant or deny a permit.

According to the DOJ, police in both Minneapolis and St. Paul routinely take more than the 30 days the law allowed and that wait times of up to 60 days are not uncommon.

Assistant Attorney General Harmeet Dhillon commented:

“The Supreme Court held that the home is where the need for defense of self, family, and property is most acute. When a person needs to defend their home, they need to defend it now, not thirty to sixty days from now.”

In June 2015, Carol Bowne, a Berlin, New Jersey hairdresser, was murdered outside her home. The killer was her abusive ex-boyfriend. Ms. Bowne had been granted a restraining order, but the ex-boyfriend violated the order a number of times.

Ms. Bowne had applied for a permit to purchase a gun. Like Minnesota, New Jersey state law allowed 30 days for police to either grant or deny that application. The day Ms. Bowne was murdered, it had been 42 days since she applied.

Minnesota does exempt citizens holding a valid permit to carry licenses. However, only about 8.2% of Minnesota adults have these licenses. This leaves roughly 4.2 million Minnesota adults vulnerable to police in two very blue cities.

The state attorney general’s office issued a statement in response to the filing:

“Given the recent, shocking, and tragic instances of gun violence in Minnesota, it is astonishing that the Trump administration is devoting its resources to attacking Minnesota’s police departments and the state’s common-sense background check laws. These laws, which Minnesota’s elected representatives passed democratically, are in place to ensure permits to purchase or transfer handguns and assault rifles are issued only to eligible purchasers. It should disturb every single Minnesotan that Donald Trump’s Department of Justice is trying to make Minnesota less safe.”

Perhaps someone should tell Keith Ellis, Minnesota’s Attorney General, about Carol Bowne.

As the old saying goes, it’s better to have a gun and not need it than to need a gun and not have it. And a right delayed is a right denied.

The most significant impact of the DOJ lawsuit is that it challenges the entire constitutionality of requiring a state-issued permit to purchase or possess a firearm. Such a requirement flies straight into the face of the Second Amendment.

The Second Amendment protects a preexisting right not only to self-defense but to armed self-defense.

With the ratification of the Bill of Rights in 1791 and the Fourteenth Amendment in 1868, neither the federal government nor a state government has the power to interfere with an individual citizen’s right to keep and bear arms. If the citizen subsequently misuses or abuses the right, the federal, state, and local governments have the necessary power to to bring the citizen to justice. That’s their job, not issuing permission slips.

Unfortunately, the Supreme Court fumbled the ball in NYSRPA v. Bruen. While the main part of Justice Clarence Thomas’ majority opinion was wonderful news for supporters of our civil rights, the first line of Footnote 9 was a setback.

Thomas’ failure to specify the ruling applied only to licenses to carry a handgun allowed a number of states to claim the court was blessing any type of gun permit.

“To be clear, nothing in our analysis should be interpreted to suggest the unconstitutionality of the 43 States’ “shall-issue” licensing regimes, under which “a general desire for self-defense is sufficient to obtain a [permit].”

“That said, because any permitting scheme can be put toward abusive ends, we do not rule out constitutional challenges to shall-issue regimes where, for example, lengthy wait times in processing license applications or exorbitant fees deny ordinary citizens their right to public carry.”

The DOJ can expect significant opposition; they have fired the first volley against a government that feels entitled to violate our rights by making it difficult, bordering on impossible, to exercise them in the way the Founders envisioned.

Minnesota is in the Eighth Judicial Circuit, which has a mixed record on Second Amendment issues. We could wish it were in the Fifth Circuit, but we can be glad it wasn’t in the Seventh Circuit. Or the Ninth.


About Bill Cawthon

Bill Cawthon first became a gun owner 55 years ago. He has been an active advocate for Americans’ civil liberties for more than a decade. He is the information director for the Second Amendment Society of Texas.

Bill Cawthon




from https://ift.tt/TdYUPn9
via IFTTT

FFL Direct: ATF Built a Real-Time Tap on Gun-Buyer Records

Illustration of FFL Direct sending purchaser information from a dealer’s electronic firearm records to an ATF tracing system.
The bound book stays with the dealer, but purchaser information can still reach Washington. AmmoLand News — AI-generated editorial illustration.

At the Briefing FFL Compliance Summit last week in Dallas, the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) walked industry professionals through a new way to answer crime-gun traces. The program is called FFL Direct. ATF billed it as a no-cost way to cut the burden on Federal Firearms Licensees (FFL) and to get serial-number hits back to the National Tracing Center (NTC) without a clerk, a fax machine, or a voicemail. The slides compared it with the older NTC Connect program and then showed, in working JSON, exactly what a request and a reply look like.

The pitch is operational. The architecture is more interesting than the pitch.

FFL Direct is an opt-in system. It is not a new statute. A shop does not have to turn it on. ATF issues production credentials only after the licensee signs a Terms of Service (ToS) Agreement. If a software vendor or other service provider sits in the middle, that vendor also has to sign the Rules of Behavior. Test accounts come first. The FFL works with ATF’s project team to build, test, and validate the connection. Only then do the two sides set a go-live date. That is the opposite of a midnight rule. It is also how infrastructure gets normalized: one cooperative agreement at a time, until the holdouts are the ones still answering traces by hand.

ATF’s own comparison slide is the cleanest summary of what changed. NTC Connect was limited to manufacturers, importers, and wholesalers. Those participants had to upload Acquisition and Disposition data and keep that upload current. FFL Direct is open to all FFL types. There is no copy and no upload of the bound book. ATF’s phrase on the slide is “set it and forget it.” It is a real-time solution. The records stay on the dealer’s side of a dotted line that ATF drew on the architecture chart and labeled “FFL Partner Data.”

NTC Connect vs. FFL DIRECT. IMG John Crump
NTC Connect vs. FFL DIRECT. IMG John Crump

That last point is the agency’s answer to the registry charge. The answer is technically true and politically incomplete.

How the API Works

The operations slide is a four-box diagram. On the left is the FFL Direct API Service inside ATF. It sends a request through a Request API. The request lands at the FFL partner, the dealer or the dealer’s recordkeeping vendor, which ATF describes as handling “Asynchronous Response Control, Query Handling, & Security.” That partner box talks to the dealer’s own data store. A Response API sends the answer back.

FFL Direct in operation. IMG screenshot NSSF.
FFL Direct in operation. IMG screenshot NSSF.
FFL Direct in Operation
FFL Direct in operation. IMG John Crump

The protocol is ordinary web plumbing. ATF transmits a trace request as a JSON file over HTTP with TLS. The FFL or its vendor writes a control layer that consumes that file and runs it against the electronic A&D book. If the serial matches, the system packages the matching disposition as a JSON response and returns it to the NTC. If it does not hit, the system sends a negative response: no record found.

Two connection types sit under that flow. A direct connection is one-to-one. The endpoint maps to a single FFL. A proxy or service-provider connection is one-to-many. One endpoint can answer traces for multiple affiliated licenses. Those requests carry an fflIdentifier field. By default, that field is the FFL’s RDS key. It can also be set to an internal identifier the vendor already uses. That is how a platform such as FastBound can sit in front of hundreds of shops without ATF opening a separate socket to every counter.

FFL Direct Connection Types. IMG John Crump
FFL Direct Connection Types: Direct & Proxy/Service Provider. IMG John Crump

To receive traffic, the partner has to expose a valid endpoint, complete an authentication grant, and return HTTP 200 on success. The sample request on the screen was not abstract. It carried a requestId, a traceId, a tracePriority, the serial number, manufacturer, firearm type, caliber, model, country of origin, importer, the FFL number and shipper name, an invoice number, a ship date, and the FFL Identifier.

In other words, the packet is not “give me everything you have on John Smith.” It is “here is this serial, from this prior FFL, on this invoice. Do you have the next disposition?”

Receiving a Trace Request. IMG John Crump
Receiving a Trace Request. IMG John Crump

The reply slides show both flavors of hit.

When the gun moved to another licensee, the JSON returns the manufacturer, serial, type, caliber, country, the disposition FFL number, the date, the business name, city, state, and the number of firearms in that sale. When the gun moved to an unlicensed buyer, the payload is the purchaser file: last name, middle name, first name, date of birth, address lines, city, state, county, ZIP, height, weight, and sex. The companion screen on that slide was a form view of the same fields, the individual information ATF would otherwise pull off a 4473 or a bound-book line.

Providing a Trace Response. IMG John Crump
Providing a Trace Response. IMG John Crump
Providing a Trace Response. IMG John Crump
Providing a Trace Response. IMG John Crump

A separate record type lets the FFL attach a file. The example on the screen was a Form 4473 sent as a PDF, base64-encoded, with a document type of “4473.” ATF described that attachment as optional supplementary documentation the licensee chooses to provide. Optional is the right word today. It also reminds us that once a pipe can carry a 4473 image, the only thing keeping that image off the wire is policy and the contract.

FFL DIRECT File Record. Can be used for any supplementary documents that FFL opts to include. IMG John Crump
FFL DIRECT File Record. Can be used for any supplementary documents that FFL opts to include. IMG John Crump

Several electronic bound-book vendors already have the hook. FastBound is the name most people in the room knew. Lipsey’s and other large accounts have been in beta. Dealers can configure the system not to answer instantly. Industry people who have seen live shops say many never touch that setting. The default is speed, which is the program’s entire point.

What the Trace Statute Already Says

None of this invents ATF’s tracing power. The Gun Control Act of 1968 authorized the National Tracing Center. 18 U.S.C. § 923(g) requires every licensee to keep acquisition and disposition records. Section 923(g)(7) requires the licensee to answer a trace request within 24 hours. If you miss that clock, ATF treats it as a willful violation that can cost the FFL their license. Traces are supposed to serve a law-enforcement agency in a bona fide criminal investigation. That limit appears in the statute, on ATF Form 3312.1, and in the eTrace agreements departments sign before they get a login.

Congress also tried to stop the next step. The Firearms Owners’ Protection Act amended 18 U.S.C. § 926(a). After 1986, ATF may not require FFL records, or any part of them, to be recorded at or transferred to a federal facility. It may not establish a system for registering firearms, firearms owners, or firearms transactions. The Tiahrt appropriations riders, renewed for two decades, further restrict how trace data can be released, used in civil cases, or treated as a public research file. Separate Brady Act and NICS rules require destruction of identifying information on allowed transfers and bar use of NICS as a registry of people who are not prohibited.

The distinction is real. It is also thinner in an API world than it was in a filing-cabinet world.

A registry is a list the government keeps. A query network is a list the government can reach. If the major vendors ship the endpoint as a default feature, ATF does not need the whole book in West Virginia to get book-like results. It needs a roster of live endpoints and a serial number. Out-of-business records in OBRIS are static images. FFL Direct talks to a book that is still being written. Every successful JSON response is also a government record of a disposition, name, address, date, serial, assembled on ATF’s side of the call even if the source file never moves.

The individual-purchaser example on the Dallas screen is the part that should end the word game. The system does not return “a dealer’s abstract inventory code.” It returns the person. Height, weight, sex, and street address are not required to prove that a serial existed. They are required to identify who took possession. That is the function of a trace. It is also the raw material of a list.

This ATF Is Not the Problem

It would be lazy to treat the Dallas briefing as a secret plot. The current operational case is not fake. After-hours traces punish small shops. A clerk squinting at a carbon copy produces worse data than a serial match against a clean electronic book. Priority traces that now take a day can, in theory, come back before the investigator hangs up. Director-level statements this year have repeated the same line: traces exist for criminal investigations, and ATF does not maintain a searchable registry of lawful owners.

Take that as good faith. Good faith is not a control.

An anti-gun administration does not have to seize every bound book on day one. It has to inherit a network that already knows how to ask and already knows how to answer. Three quiet shifts would do the rest.

First, “opt-in” becomes “expected.” Demand letters already exist for shops that miss the 24-hour window. Trace response is already on the list of revocation-class violations. A guidance memo that says failure to implement available electronic response may be evidence of willfulness would not need a new statute. Inspectors do not have to order the API. They only have to treat the holdouts as the problem.

Second, the query widens. Today the packet is a trace ID, a priority code, and a serial tied to a prior FFL and an invoice. Tomorrow the same endpoint can be asked to accept a different payload if “investigation” gets a sloppy reading, if a later rule redefines the trigger, or if a service provider is already standing in front of a thousand licenses and the political appetite for “just one more field” arrives.

Third, the answers accumulate. Even if ATF never hosts the book, it hosts the replies. Index those replies by purchaser name instead of by trace number and the FOPA line about “no system of registration” becomes a dispute about file structure, not about function. The optional 4473 attachment on the slide is the same story in miniature. Optional documentation can become the complete file when the next administration decides the incomplete file is non-cooperative.

Software vendors will not rip out an API that ATF, Lipsey’s, and the bound-book platforms already run. Dealers who signed the Terms of Service will not enjoy being the last fax machine in the county. Political appointees turn over. Endpoints do not.

Friction is a civil-liberties feature. A process that takes a person twenty minutes forces someone to decide whether the request is worth the call. A process that returns a name, a date of birth, and a street address before the agent finishes a sentence invites the next use case. Databases sold as narrow and later used as broad are not a hypothetical. They are the standard biography of federal information systems.

What the Contract Should Say Before Anyone Signs

Opt-in only matters if the paper is written like a limited warrant.

The Terms of Service should lock the use case to statutory traces under § 923(g)(7) for bona fide criminal investigations. It should forbid bulk queries, name searches, and any request that is not tied to a recovered serial. There should be a requirement for a dealer-side log of every inbound call: time, trace number, serial number, and whether a hit was returned. It should let the FFL disable instant response without being scored as uncooperative. Also, it should say how long ATF keeps the JSON, who can see it, and whether the response file is indexed by purchaser. If a vendor is in the proxy seat, the Rules of Behavior should say the same things in writing, not in a slide deck stamped “FOR OFFICIAL USE ONLY.”

Vendors should make the dark setting the standard. “Built into most electronic bound books” is convenient for ATF. It is a default setting that a small shop will never audit. A dealer who wants the old 24-hour manual process should be able to leave the API off without breaking the rest of the software.

Congress already wrote the policy. FOPA said the records stay with the licensee. Tiahrt said trace data is not a public research file. The Brady framework said NICS is not a list of lawful buyers. FFL Direct does not repeal those lines. It builds a machine that can honor them or ignore them depending on who holds the keys.

Speed is a legitimate law-enforcement interest. So is the reason those statutes exist. A federal roster of who bought what is a political weapon. The current ATF can call FFL Direct an efficiency project and mean it. The next ATF that wants a registry will not need to invent one. It will only need to keep asking a question the industry already taught the servers to answer.


About John Crump

Mr. Crump is an NRA instructor and constitutional activist with more than 26 years of experience in networking and cybersecurity for major Fortune 100 companies. John has written about firearms, the Constitution, and cybersecurity, and has interviewed people from all walks of life. John lives in Northern Virginia with his wife and sons. Follow him on X at @right2bear, or at www.crumpy.com.

John Crump




from https://ift.tt/c6O4ZYN
via IFTTT

Tuesday, September 29, 2026

Newsom Signs 10 More Gun Control Bills in California’s Assault on the Second Amendment

Gun store wall stocked with handguns.
California Gov. Gavin Newsom has signed 10 new gun control bills including a training mandate that becomes effective in 2029. Credit: artas/iStock-1057967500

While hundreds of Second Amendment activists were in Dallas, Texas attending the 41st annual Gun Rights Policy Conference, California Gov. Gavin Newsom was busy in Sacramento, inking ten new gun control measures, including Senate Bill 948, which will require new gun buyers to take a gun safety class in order to buy a firearm, starting in 2029.

The legislation was authored by Berkeley Democratic Sen. Jesse Arreguín.

As stated in the legislation, “This bill would require an applicant for a firearm safety certificate, on or after January 1, 2029, to complete within the prior year a training course no less than 4 hours in length that, among other things, includes instruction on firearm safety and handling and live-fire shooting exercises on a firing range. The bill would authorize the Department of Justice to promulgate regulations and provide additional information for the implementation of these provisions.”

All ten bills are being misidentified as “gun safety laws” by Cal Matters, which noted that the California Rifle and Pistol Association considers the four-hour class requirement to be a “possible infringement on Second Amendment rights.” Coincidentally, CRPA President Chuck Michel was in Dallas, attending the Gun Rights Policy Conference.

In a news release, Newsom declared, “California has been a leader in gun safety because survivors, advocates, researchers, law enforcement, legislators and communities have continued to come together to turn hard-earned lessons into action. Today’s laws continue that work – using data, prevention and proven tools to help keep firearms out of dangerous situations and support communities affected by violence.”

Cal Matters quoted Emma Brown, executive director of the anti-gun Giffords lobbying group, stating, “California leads the nation in gun safety because its leaders work tirelessly to prevent violence and keep communities safe. The policies enacted today will save lives by closing loopholes and investing real resources in community violence intervention.”

Newsom’s office listed the bills signed by the outgoing Democrat governor:

  • Assembly Bill 1743 by Assemblymember Buffy Wicks (D-Oakland) — Firearms
  • Assembly Bill 1753 by Assemblymember Catherine Stefani (D-San Francisco) — Protective orders: firearms and ammunition: notice and procedures
  • Assembly Bill 1943 by Assemblymember Mike A. Gipson (D-Carson) — Pupil safety: notifications: firearms
  • Assembly Bill 1974 by Assemblymember Catherine Stefani (D-San Francisco) — Firearms: voluntary firearm storage program
  • Assembly Bill 2047 by Assemblymember Rebecca Bauer-Kahan (D-Orinda) — 3-dimensional printing blocking technology
  • Assembly Bill 2339 by Assemblymember Mike A. Gipson (D-Carson) — Firearms: prohibited persons
  • Assembly Bill 2378 by Assemblymember Jesse Gabriel (D-Encino) — California Violence Intervention and Prevention Grant Program
  • Assembly Bill 2636 by Assemblymember Blanca Pacheco (D-Downey) — Juveniles
  • Senate Bill 948 by Senator Jesse Arreguín (D-Berkeley) — Firearms: safety certificates
  • Senate Bill 1220 by Senator Melissa Hurtado (D-Bakersfield) — Firearms: prohibited persons

Newsom’s news release also touted the news that billionaire-backed Everytown for Gun Safety ranks California as No. 1 nationally for gun-law strength. There is no small irony here, as Statista shows California in 2024—the most recent year for which data available—logged the most murders of any state in the nation, racking up 1,782 slayings, based on FBI data.

Everytown also noted that 42 percent of firearms recovered and traced in California in 2025 originated from out-of-state dealers.

Mandated gun safety training as a prerequisite for purchasing and owning a firearm are seen by many to be the equivalent of an unconstitutional “literacy test” once required for voting in some states.

Newsom’s move came on the heels of the Department of Justice’s announcement it has sued the State of Minnesota, and the cities of Minneapolis and St. Paul, alleging that  Minnesota’s “permit to purchase” and waiting period regulatory scheme violate the Second Amendment.

“For Minnesotans who do not intend to carry in public, state law imposes a thirty-day waiting period. The lawsuit also challenges waiting periods in St. Paul and Minneapolis, where some citizens are forced to wait nearly 60 days,” the DOJ said in a press release.

“The Supreme Court held that the home is where the need for defense of self, family, and property is most acute. When a person needs to defend their home, they need to defend it now, not thirty to sixty days from now,” said Assistant Attorney General Harmeet K. Dhillon of the Justice Department’s Civil Rights Division. “Law-abiding citizens do not need government permission to purchase a firearm, and forcing a citizen who has already passed a background check to wait up to sixty days to obtain a firearm is intolerable under the Constitution.”

The announcement left some gun owners in Washington state wondering when the DOJ will take a similar action against their “permit-to-purchase” requirement, which they believe clearly violates both the Second Amendment and Article 1, Section 24 of the State Constitution. The Second Amendment prohibits infringement of the right to keep and bear arms. Washington’s RKBA provision says the right to bear arms “shall not be impaired.”


About Dave Workman

Dave Workman is a senior editor at TheGunMag.com and Liberty Park Press, author of multiple books on the Right to Keep & Bear Arms, and formerly an NRA-certified firearms instructor.Dave Workman




from https://ift.tt/vQErHl2
via IFTTT

Senators Demand DOJ Probe and Destruction of ATF’s 1.4 Billion Out-of-Business Records

ATF Form 4473 being scanned beside aisles of archived gun records, with a digitized copy displayed on a monitor
ATF’s out-of-business record collection contains more than 1.4 billion records, with roughly 92% digitized. This illustration depicts a Form 4473 moving from paper to a digital archive. AI-generated editorial illustration for AmmoLand News.

Eight U.S. senators are demanding that Attorney General Todd Blanche investigate what they call an illegal national gun registry built from the Bureau of Alcohol, Tobacco, Firearms and Explosives’ out-of-business records (OBRs). Those records now number 1,414,088,513.

The Sept. 24 letter, led by Sen. James Risch (R-Idaho) and sent to Blanche at the Department of Justice, also went to ATF Director Robert Cekada. Joining Risch were Sens. Mike Crapo (R-Idaho), Marsha Blackburn (R-Tenn.), Ted Budd (R-N.C.), Tom Cotton (R-Ark.), Steve Daines (R-Mont.), Cindy Hyde-Smith (R-Miss.), and Pete Ricketts (R-Neb.).

Gun Owners of America (GOA) and the senators treat the OBR holdings as a registry of guns and gun owners, not a passive archive.

“We write to alert you to an illegal national gun registry now containing 1,414,088,513 records of guns and gun owners,” the letter states. “These records, maintained by the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) at its Martinsburg, West Virginia facility, were obtained from out-of-business firearms dealers and include names, addresses, Social Security numbers, and the specific firearms purchased.”

The Three Demands

The senators argue federal law already forbids what ATF is doing and that Congress does not need to pass another statute before the executive branch acts. They cite the Firearm Owners’ Protection Act of 1986, which prohibits “any system of registration of firearms, firearms owners, or firearms transactions,” and annual appropriations riders that bar ATF from centralizing the records and searching them by name.
They urge Blanche to:

  1. Direct an immediate, independent investigation of ATF’s Martinsburg database;
  2. Order the prompt and verifiable destruction of any records maintained in violation of the 1986 Firearm Owners’ Protection Act and the appropriations prohibitions; and
  3. Ensure that any final rule on record retention fully complies with those same prohibitions.

“Congress has already spoken. The American people need executive action to enforce that law,” they wrote. “American citizens are entitled to exercise their Second Amendment rights without the federal government compiling searchable lists of their names and firearms. We ask for your decisive leadership to end this registry and prevent its expansion.”

Risch has separately pushed the No REGISTRY Rights Act, which would require ATF to delete existing firearm transaction records and block any future registry.

How the Records Grew

The letter notes that the White House has described the holdings as an “invasive database.” According to the senators, the count has grown from roughly 920 million records in 2021 to more than 1.4 billion today, about half a billion more in four years.

A 2020 leak obtained by AmmoLand News showed ATF processing more than 50 million gun records a year. Later that year, ATF told Congress it held more than 920 million records. That disclosure produced the No REGISTRY Rights Act and a string of appropriations-rider drafts. A 2026 ATF update put the current total well over a billion.

A 2022 GOA analysis found the database can be searched and filtered by make, model, and firearm type, which the group said would allow targeted lists of owners. When pressed, then-ATF Director Steve Dettelbach acknowledged ATF pays extra to have search functions stripped out of Adobe Acrobat.

Vice President JD Vance has framed the same collection as a back door to registration. “This database is ultimately a back door to a gun registry in this country,” Vance said on Fox News. “And if you look at what liberals have done in Europe, what they’ve done in Australia: once you allow a gun registry, you effectively allow the disarming of your citizenry. This is ultimately about destroying the Second Amendment.”

The senators also flag a pending ATF rule (RIN 1140-AA95) that would require dealers to keep transaction records for up to 30 years and then send them to ATF for another 30 years—what the letter calls “lifetime registration of every legal purchase.”

Cloud’s questions and ATF’s reply

The 1,414,088,513 figure comes from ATF’s response to Rep. Michael Cloud (R-Texas), who has pressed the bureau for a current count and for proof that decades-old records are needed for traces.

In that response, ATF said the National Tracing Center (NTC) “maintains OBRs and provides critical trace information to assist our local, state, federal, and international law enforcement partners when investigating crimes.” One example ATF used to justify keeping the files was the identification of the attempted assassin of Donald Trump in Butler County, Pennsylvania.

“The identification of the attempted assassin in Butler County, Pennsylvania, is merely one example of the critical work that the NTC carries out every day to help our law enforcement partners investigate violent crime,” ATF wrote.

According to ATF, traces using records more than 20 years old accounted for 10.35 percent of 623,654 traces in 2022. Traces run on records 10 years old or older but less than 20 years old accounted for 8.57 percent of all traces using OBRs. ATF also said OBRs are used to complete 51.39 percent of trace requests for guns purchased more than 20 years ago.

Cloud asked for concrete evidence that records older than 20 years are useful. ATF pointed to those percentages. The bureau wrote that crime-gun traces “consistently require the use of records from out-of-business FFLs that are at least 20 years old,” that NTC traces identified a first purchaser more than 75 percent of the time (75.2 percent in 2025), and that among successful traces the first-purchaser records were at least 20 years old 12.86 percent of the time, based on the annual average since 2017.

“Finding the crime gun’s first purchaser—even one from 20 years ago—is important lead information, as it gives law enforcement investigators a starting point for asking questions about the crime gun’s chain of custody,” ATF said. “Without these records, law enforcement would be denied investigative leads 12.86 percent of the time.”

ATF acknowledged the privacy concerns in Cloud’s letter and tied its proposed change to President Trump’s 2025 Executive Order on Protecting Second Amendment Rights, which directed the attorney general to review firearm and FFL rules. From that review came a proposed rule to replace indefinite retention of FFL records with a 20- or 30-year period for ATF Forms 4473 and acquisition-and-disposition records, and the same window for the OBR Center at NTC. Records are now kept indefinitely. ATF invited comments on the notice of proposed rulemaking.

Cloud also asked for a list of the “crime codes” ATF cited in an earlier reply. ATF did not provide them. It is unclear whether that was deliberate or an oversight. Those codes would show whether the traces involve serious violent crime or lesser offenses.

He also asked for a breakdown of the holdings. ATF’s Enterprise Content Management (ECM) system holds 912,184,571 images. That system digitizes ATF Form 4473s. Records converted from microfilm or microfiche to digital format total 397,009,400. Another 104,894,400 still await conversion.

What happens next

ATF continues to describe the Martinsburg files as a tracing tool, not a registry, and says name search is disabled. The senators say the size of the collection, the data on each record, the growth since 2021, and the pending 20- or 30-year rule add up to a registry in everything but name.

Blanche has not publicly answered the Sept. 24 letter. The senators asked him to investigate the database, destroy records they say are unlawful, and keep any final retention rule inside FOPA and the appropriations bans.


About John Crump

Mr. Crump is an NRA instructor and constitutional activist with more than 26 years of experience in networking and cybersecurity for major Fortune 100 companies. John has written about firearms, the Constitution, and cybersecurity, and has interviewed people from all walks of life. John lives in Northern Virginia with his wife and sons. Follow him on X at @right2bear, or at www.crumpy.com.

John Crump




from https://ift.tt/pn7VlG2
via IFTTT

Monday, September 28, 2026

Housing Authority Eviction Over Armed Defense Ignores Prior Court Rulings

Apartments in St. Louis, where resident Torrey Holliday faces lease termination after a defensive shooting
A housing authority’s lease termination notice after a defensive gun use. Original editorial illustration; the person and building depicted are not Torrey Holliday or Euclid Plaza. AmmoLand News / AI-generated editorial illustration.

“When public housing bureaucracy collides with basic human survival, common sense usually takes a hit. Torrey Holliday learned this lesson the hard way in St. Louis,” Grafana reports.  “After using a firearm to stop an armed robber who targeted him in his own apartment building lobby, Holliday didn’t receive support from his landlords. Instead, he got an eviction notice.”

Fox2Now St. Louis provides a photo of the eviction notice, which checks off “Criminal activity” as the reason for the wheelchair-bound victim’s eviction. Except that’s a bureaucratic kneejerk assessment, not that of law enforcement.

“Police and prosecutors looked at the exact same evidence and labeled Holliday a victim of a crime who acted in strict self-defense,” the  Grafana report explains. “Meanwhile, the St. Louis Housing Authority reviewed surveillance footage of the July incident, ignored the criminal charges against the intruder, and decided that defending your life constitutes a lease violation.”

If the Housing Authority had bothered to look before (metaphorically) pulling the trigger, they’d have known that discriminating against armed residents in public housing has been challenged before, with results in different jurisdictions showing the courts consistently frowning on it.

Back in 2019, in Doe v. East St. Louis Housing Authority, a case championed by the Second Amendment Foundation and the Illinois State Rifle Association, “A federal judge ruled … that the East St. Louis Housing Authority cannot deny, through rules and regulations, a tenant’s right to lawfully own a firearm.” Per US District Court Judge Phil Gilbert:

“Among whatever else, the Second Amendment protects the rights of a law-abiding individual to possess functional firearms in his or her home for lawful purposes, most notably for self-defense and defense of family.”

True, St. Louis falls under the United States District Court for the Eastern District of Missouri, while East St. Louis is under the United States District Court for the Southern District of Illinois. But that hardly means different rulings should be expected, particularly in light of other judgments, including:

In 2022 (Columbia Housing & Redevelopment Corp. v. Kinsley Braden), “the Second Amendment Foundation scored a victory in a ruling by a Tennessee Appeals Court panel striking down a gun ban by a public housing authority in the community of Columbia on the grounds it violates the Second Amendment, citing recent Supreme Court language in the case of New York State Rifle & Pistol Association v. Bruen.”

In 2023, SAF “won a permanent injunction against the Warren County, Ill. Housing Authority’s ban on the possession of firearms by residents or guests.”

And in 2024 (Hunter v. Cortland Housing Authority), “the court entered a stipulated permanent injunction blocking the firearm and social media censorship bans, removing lease prohibitions, and awarding $150,000 in attorney fees.”

The question now is, will Mr. Holliday challenge his eviction, and will he be backed by Second Amendment advocacy groups, or will the Housing Authority realize the error of its ways and do the right thing by reversing its decision and apologizing for its tyrannical arrogance?

Noting who runs the Board of Commissioners and the Leadership Team, with majority commission appointments serving at the pleasure of Mayor Cara Spencer, who as alderwoman defied state preemption and pushed for an open carry ban, looking for an easy way out seems overly optimistic.

As a frequent WarOnGuns contributer observed, “This is one of those ‘fait accompli’ government actions. They know it’s illegal, but by the time anyone can get a court to rule that, the troublemaker will already be in other lodging and unlikely to come back.”

Related Reading:


About David Codrea:

David Codrea is the winner of multiple journalist awards for investigating/defending the RKBA and a long-time gun owner rights advocate who defiantly challenges the folly of citizen disarmament. He blogs at “The War on Guns: Notes from the Resistance,” is a regularly featured contributor to Firearms News, and posts on Twitter: @dcodrea and Facebook.

David Codrea




from https://ift.tt/Mzv8gTn
via IFTTT

Congress Must Rein In ATF’s Billion-Record Gun Archive After Qilin Breach

Archived firearm transaction records and server room illustrating questions about ATF gun-record security after the Qilin breach
Qilin’s reported ATF leak concerned investigative files. The breach renews questions about how the bureau protects its separate out-of-business firearm records archive. AI-generated editorial illustration for AmmoLand News.

For thirty years, the same story has repeated itself inside the Bureau of Alcohol, Tobacco, Firearms and Explosives: Congress bars the agency from building anything that looks like a national gun registry, ATF quietly builds something that comes close anyway, and it takes an outside audit, sometimes a decade or more later, to catch it. A review of a Government Accountability Office (GAO) audit, ATF’s own internal technical manuals released under the Freedom of Information Act, and a 2022 report from Gun Owners of America lays out just how close, and just how poorly secured, ATF’s records empire has become. To be fair to the agency, most of the specific security holes exposed over the years have since been fixed. But several still exist, and the ones that remain go to the heart of whether ATF’s records can be trusted at all.

The numbers alone should stop every gun owner in their tracks. ATF’s Out-of-Business Records Imaging System, known as OBRIS, held roughly 297 million images as of 2016. By November 2021, according to ATF’s own letter to Congress, that number had ballooned to 920,664,765 records, with 865,787,086 already digitized. It has since grown past a billion records, according to new figures detailed in a separate report. That is not a filing cabinet. That is one of the largest repositories of firearm-owner-linked personal data anywhere in the federal government, and it keeps growing.

Then, The ATF Got Hacked

This report was largely finished when the story took an unplanned turn. On August 26, 2026, the Russian-speaking ransomware gang Qilin, a rebrand of the older Agenda ransomware operation with more than 2,200 claimed victims, posted ATF to its dark-web leak site, claiming to have broken into the agency’s systems. ATF confirmed the breach within hours. The Department of Justice designated it a “major incident,” the classification that triggers mandatory notification to Congress.

ATF’s line, delivered through Chief of Public Affairs Tanya Roman, was reassuring on its face. The compromised system was standalone and tied to the agency’s CALEA infrastructure, used to handle court-authorized communications intercepts in criminal cases. According to ATF, it was not connected to any other ATF systems, including case management, laboratory, or eForms systems, and there was no indication the incident had affected the ATF enterprise network or any other ATF system. In plain terms: not the same database at the center of this report. As of late September, ATF has not said it has any indication that gun-purchase records, Forms 4473, or the OBRIS out-of-business repository were touched.

That reassurance held for five days. On August 31, Qilin’s ransom countdown expired, and the gang briefly posted roughly 6.3 gigabytes of files before pulling them back down, plenty of time for reporters to see what was inside. According to CNN and other outlets, the trove included the names of criminal investigation targets, phone numbers, IP addresses, iCloud data, and Cellebrite phone-extraction dumps. It was drawn from cases involving armed robbery, arson, explosives, and homicide, with a heavy concentration of files traced to ATF’s Houston Field Division. By Monday, September 1, ATF’s public posture had softened from denial to agnosticism: the agency said it “cannot confirm the authenticity, nature, or scope” of what Qilin published. Nearly a month later, it has offered no fuller accounting.

No one has yet produced evidence that OBRIS itself, the over-a-billion-record repository at the center of this report, was part of what Qilin took, and this report won’t claim otherwise. But watch the shape of ATF’s defense: a “standalone” system, walled off, nothing to see here. That is the identical assurance ATF has given gun owners for a decade about OBRIS’s disabled name-search feature, a policy promise, not a demonstrated architectural fact.

Texas Gun Rights president Chris McNutt said in the days after the breach that gun owners are entitled to a full accounting, both of what was compromised and of what the federal government keeps on them in the first place. His group put the broader principle more bluntly: “The government cannot lose information it never collected in the first place.” Gun owners are now being asked to trust that the database holding a record of nearly every firearm ever sold by a defunct dealer is walled off any better than the system Qilin just walked into.

A Registry Built on Trust ATF Hasn’t Earned

Congress has tried to head this off for decades. The Firearms Owners’ Protection Act (FOPA) bars any new rule that would create a “system of registration of firearms, firearms owners, or firearms transactions.” A separate appropriations rider, renewed every year since 1978 and made permanent in 2012, bars ATF from spending a dime to “consolidate or centralize” dealer records. And a third rider specifically forbids ATF from retrieving out-of-business records “by name or personal identification code.”

ATF’s defense has always been the same: the records aren’t searchable by name, so it isn’t a registry. The Congressional Research Service repeats that position, describing the digitized records as images that optical character recognition can’t read and that can be pulled only to complete a firearm trace. But that describes how ATF says it uses the system, not what the system can do. The FOIA production obtained under request 2020-0802 tells a more complicated story. ATF’s scanning and content-management software for building OBRIS comes from IBML and OpenText, as documented in ATF’s own vendor manuals and work instructions. Those commercial platforms include optical character recognition, intelligent handwriting recognition, and full-text search. The documents don’t settle one question: whether ATF’s licensed installation includes those features, or whether they were left out or stripped away. ATF has never publicly answered it. The record does show that name search is turned off in the interface. Nothing in ATF’s own paperwork shows the capability was ever removed at the database level, or that it was never there to begin with. Gun owners are being asked to accept that uncertainty on faith. A policy is not a wall. A policy is a setting, and settings can be changed.

Caught Red-Handed — Twice

This isn’t speculation. GAO’s 2016 report, titled bluntly “ATF Did Not Always Comply with the Appropriations Act Restriction,” found that ATF had spent sixteen years, from 2000 to 2016, pooling out-of-business dealer records from its Access 2000 program onto a single server at the National Tracing Center, in direct violation of the anti-consolidation law. ATF’s own Chief Counsel had separately determined in 2009 that a program called the “Southwest Border Weapons of Choice” initiative illegally collected non-investigative dealer inventory data for two years running. It took ATF until March 2016, six and a half years after its own lawyers flagged the violation, to actually delete the data.

GAO went further: because ATF had no lawful appropriation to do any of this, the violation also triggered the Antideficiency Act, a law that requires an agency head to report the violation immediately to the President, Congress, and the Comptroller General. GAO found no evidence that the report was ever filed. Nobody was held accountable. The data just sat there until an audit forced its hand.

A Bug That Let Agents See What Policy Said They Couldn’t

Perhaps the most alarming finding in the 2016 report has nothing to do with policy at all; it’s a straightforward technical failure. ATF’s Firearm Recovery Notification Program is supposed to shield purchaser and dealer identities from agents who don’t need them. But when the eTrace 4.0 system rolled out in 2009, it shipped with a global print function that let any agent with basic access print up to 500 full purchaser records in a single batch — names included. ATF knew about the defect before the system ever went live. By the time GAO published its report seven years later, it still hadn’t been fixed, and ATF admitted it kept no audit logs showing whether, or how many times, agents used that loophole to pull data they were never supposed to see.

To ATF’s credit, it has since closed that hole. The print defect has been fixed, and the system now keeps an audit log of who accesses what.

But notice what the fix doesn’t do. An audit log only records what happens after it is switched on. For the years the loophole sat open, there is no record, and there never will be. ATF cannot tell anyone whether that gap was ever exploited, by whom, or how many purchaser names walked out the door. The agency shipped a privacy safeguard broken, knew it was broken, left it broken for years, and fixed it only after an outside auditor put it in writing. That is the pattern this report keeps finding: ATF fixes problems after they are exposed, rather than preventing them.

Paper Records Stacked to the Ceiling

It isn’t just the software. As of 2016, roughly 8,060 boxes of unscanned paper dealer records were piled up at the National Tracing Center in Martinsburg, West Virginia, nearing a 10,000-box limit that GSA itself warned could put the building’s floor at risk of structural failure. Overflow records ended up stored in outdoor shipping containers.

The digital side has improved, but only halfway. Records are now encrypted once they are inside ATF’s system. Getting them there is another story. Dealers can still email their records to ATF, and ATF still accepts them unencrypted. There is no requirement to encrypt the file and no secure upload portal. A closing dealer’s entire customer history, with names, addresses, and Social Security numbers, can still cross the open internet like a grocery list, and be protected only after it arrives.

That gap is ATF’s to close. Federal law requires dealers who go out of business to turn their records over to ATF. If the government is going to require dealers to hand over a lifetime of customer data, it must give them a secure way to do it. That means an encrypted upload system built for the job, with unencrypted email no longer accepted. Encrypting records after they arrive does nothing to protect them on the way in, and the way in is where they are most exposed.

The Mission Keeps Creeping

Even the boundary of what counts as an “out-of-business” record has proven elastic. Gun Owners of America’s May 2022 report, built substantially on the same FOIA release, documents that ATF has, through internal rulings and standing orders rather than any actual rulemaking, “strongly recommended” that active, still-operating dealers voluntarily ship records older than 20 years into the same Out-of-Business Records Repository, years before those dealers ever close their doors.

Fifty-two members of Congress raised nearly the exact same concern with the ATF in November 2021, citing the 2016 GAO report by name. ATF’s written answer brushed it off as old news about “a discrete situation.”

History suggests otherwise: an unreviewed data-collection program, run by internal memo instead of law, is precisely the pattern that produced ATF’s last two confirmed violations.

Not Just ATF: A Justice Department Pattern

ATF is not an outlier. Over the past four years, the DEA, the U.S. Marshals Service, and the FBI have all had sensitive systems breached. Each of them, like ATF, answers to the Department of Justice, and the details read like a dress rehearsal for what just happened to ATF.

DEA, 2022.

In May 2022, intruders used a local police officer’s stolen credentials to enter the DEA’s EPIC System Portal. EPIC is a DEA-led, multi-agency intelligence center, and ATF is part of it: a 2017 DOJ inspector general report documented ATF analysts working in its Firearms and Explosives Intelligence Unit and recorded 1,609 ATF queries of EPIC’s Law Enforcement Inquiries and Alerts system in fiscal 2015, most commonly for firearms investigations. At the time of that review, LEIA searched 18 law enforcement databases, including DOJ systems. The criminal complaint says Sagar Singh entered the portal with a stolen username and password and shared them with Nicholas Ceraolo; it also says some linked databases required separate credentials they did not have. KrebsOnSecurity reported that screenshots showed options to look up firearms and other property, and that a source said the login prompted for no second authentication factor. The public record does not establish that the intruders retrieved firearm-ownership records. What it does establish is troubling enough: criminals entered an intelligence portal used by an ATF-staffed center and exploited information from it to threaten victims. Both men later pleaded guilty and were sentenced to prison.

U.S. Marshals Service, 2023.

In February 2023, the Marshals Service discovered a “ransomware and data exfiltration event” that affected a “stand-alone” system. According to the agency, the affected system held law enforcement sensitive information, including returns from legal process, administrative information, and personal data on subjects of Marshals investigations, third parties, and certain employees. The hacked network belonged to a secretive unit called the Technical Operations Group, which provides surveillance capabilities to track fugitives. Officials determined that it constituted a major incident. The stolen files didn’t stay put: the data was put up for sale in March 2023 on a Russian-speaking hacking forum, and it resurfaced on the Hunters International ransomware gang’s leak site in 2024. It wasn’t the agency’s first failure, either. In a December 2019 incident, the Marshals accidentally exposed the details of over 387,000 former and current inmates, including names, dates of birth, home addresses, and Social Security numbers.

A “stand-alone” system. Surveillance data. A “major incident.” Three years before ATF, the Marshals Service used nearly the same words, and the data still ended up for sale on a Russian forum.

FBI wiretap network, 2026.

This year the FBI itself was hit, in one of its most sensitive systems. An inquiry into abnormal activity on the network the bureau uses to manage wiretaps and other surveillance work opened on February 17. The affected system contains data from electronic surveillance and personal identification information on subjects of bureau investigations, and senior Justice Department officials determined on March 23 that the intrusion was a “major incident”. The attackers got in through a vendor ISP connected to the FBI’s network, and the Wall Street Journal reported that investigators suspect Chinese government-affiliated hackers.

FBI personnel data, September 2026.

Only last week, the extortion group ShinyHunters claimed it had breached the FBI’s online jobs portal and stolen information on almost all FBI agents and job applicants. The FBI confirmed on September 26 that it is dealing with a “cybersecurity incident.” Journalists who reviewed a sample of 5,000 records found names, home addresses, phone numbers, dates of birth, and Social Security numbers, with some records including spouse and emergency contact details. The group’s price isn’t even money. ShinyHunters says it is holding the data while demanding the FBI withdraw a statement the bureau issued about the group in May.

The CALEA Thread

Look closely, and a common target emerges: surveillance infrastructure. ATF’s breached system was its CALEA intercept system. The FBI’s breached network manages wiretaps. And in 2024, China’s Salt Typhoon campaign compromised the networks of at least nine major U.S. telecommunications carriers and reportedly accessed the lawful intercept systems used by U.S. law enforcement. The systems Washington built to watch suspects have become the doorway foreign hackers and criminal gangs use to watch Washington.

The lesson for gun owners is straightforward. “Standalone” is not a guarantee, and a “major incident” designation comes after the damage, not before it. If the FBI, the nation’s lead cyber agency, cannot keep its own wiretap network and personnel files out of hostile hands, there is no reason to trust ATF’s over-a-billion-record, out-of-business repository as any safer.

The door that’s open right now. The threat isn’t just in the past. This past weekend, Citrix confirmed that two critical NetScaler remote code execution vulnerabilities are being exploited in attacks. NetScaler appliances are the gateways many organizations use for VPN access, load balancing, and user authentication, which makes them the front door to a network. Attackers exploited these flaws as zero-days before any fix existed. The first one lets an unauthenticated attacker run any command they want on the appliance, and it affects every NetScaler ADC and Gateway deployment, including those running the default configuration.

The warning signs came before the fix. Starting September 26, suppliers and security teams told NetScaler administrators to shut down their appliances after a private warning from the Dutch National Cyber Security Center. NetScaler is common enough across the federal government that CISA ordered every federal civilian agency to secure its vulnerable appliances by September 30. CISA also warned agencies that suspect a compromise to preserve forensic evidence before patching, because updating can erase the traces an attacker left behind. In other words, patching closes the door but doesn’t tell you whether someone already walked through it.

It isn’t a one-off, either. This is at least the third actively exploited NetScaler flaw since August. In late August, CISA gave federal agencies three days to fix another NetScaler vulnerability that attackers were already exploiting to plant web shells. Shadowserver counts more than 23,000 NetScaler instances exposed to the internet.

But the point stands. The same commercial gateway products sit at the edge of agency after agency, and every newly exploited flaw is a race between federal IT staff and attackers. Every system holding firearm-owner data sits behind a gateway like this one. How fast those gateways get patched, and whether anyone checks for intruders before patching, can decide whether a billion records stay walled off or end up on a Russian-language leak site.

DOJ’s Job, Not Just ATF’s

Every public statement about the Qilin breach so far has come from one office: ATF’s Chief of Public Affairs. That’s worth pausing on, because ATF doesn’t actually own its cybersecurity. Under the Federal Information Security Modernization Act (44 U.S.C. Chapter 35), the legal duty to protect an agency’s information systems sits with the head of the parent department, not the component bureau. ATF is a component of the Department of Justice. For information security policy, system authorization, and incident response, ATF answers up to DOJ’s Justice Management Division and the Office of the Chief Information Officer housed inside it, the office that is supposed to set the rules ATF’s IT staff follow and certify whether a system like the one Qilin broke into was secure enough to be plugged in at all.

That chain of responsibility matters for a second reason: “major incident” isn’t editorial color; it’s a legal trigger. Under OMB Memorandum M-25-04 and 44 U.S.C. § 3554(b)(7)(C)(iii)(III), an agency that designates a breach a major incident has seven days to notify the authorizing and appropriations committees of both chambers of Congress, plus, where personal data is involved, the House Committees on Oversight, Homeland Security, and Science, and the Senate Committees on Homeland Security and Governmental Affairs, Commerce, and Judiciary, and to loop in its own Inspector General. That clock is a department-level obligation. Coverage of the breach describes ATF as coordinating with DOJ on the response, but none of it quotes an independent DOJ statement, only ATF’s public affairs office speaking for both.

There’s a reason to wonder whether DOJ is the reassuring voice gun owners should want here. A 2024 DOJ Inspector General audit of JMD’s own information security program, the same office chartered to set the security bar for ATF and every other component, found weaknesses in four of the nine FISMA domain areas it tested, plus a gap tied to a congressional letter on telework security vulnerabilities. That’s the department’s central cybersecurity apparatus failing its own checkup, years before Qilin got near ATF’s servers. Meanwhile, the public list of OIG reports on ATF runs to 121 and counting, heavy on firearms-trace management, dealer inspections, and recordkeeping, but nothing in that list resembles a dedicated audit of the bureau’s network security or FISMA compliance. ATF’s paper trail has been picked for over thirty years. Whether its digital perimeter has ever been tested with the same rigor is, on the public record, an open question.

There’s a reason to wonder whether DOJ is the reassuring voice gun owners should want here. The DOJ Inspector General’s most recent audit of JMD’s own information security program covered fiscal 2024. JMD is the office chartered to set the security bar for ATF and every other component, and the audit found weaknesses in two of the nine FISMA domain areas it tested, plus a vulnerability left unresolved from the year before. That’s the department’s central cybersecurity apparatus falling short on its own checkup, two years before Qilin got near ATF’s servers. Meanwhile, the public list of OIG reports on ATF runs to 121 and counting, heavy on firearms-trace management, dealer inspections, and recordkeeping, but nothing in that list resembles a dedicated audit of the bureau’s network security or FISMA compliance. ATF’s paper trail has been picked apart for over thirty years. Whether its digital perimeter has ever been tested with the same rigor is, on the public record, an open question.

What Needs to Happen Now

Until late August, none of the sources reviewed for this report documented a proven external hack of ATF’s firearms database, and this piece still won’t claim that OBRIS itself has been breached. But the Qilin incident proves the underlying fear isn’t hypothetical. ATF’s systems can be broken into. The agency’s first instinct is to insist the damage is contained to a walled-off corner. And the public is left to take that on faith until a leak site forces a fuller accounting. The same pattern has now played out at the FBI, the U.S. Marshals Service, and the DEA. This is not one agency’s bad luck. It is a Justice Department problem.

ATF deserves credit where it has earned it. When GAO auditors came in, the agency accepted the findings rather than fighting them, and it has addressed several concerns honestly. The eTrace print loophole has been closed, and the system now logs who accesses purchaser records. Dealer records are encrypted once they reach ATF’s system. ATF deleted the illegally consolidated Access 2000 data and the Southwest Border inventory data. The current ATF has also been open with AmmoLand News, answering questions directly instead of hiding behind boilerplate.

So let’s be clear about what this report is and isn’t saying. Today’s ATF is not the problem. The problem is the ATF that comes after it. Administrations change, and directors change with them. A future president hostile to gun owners would inherit everything described in this report. That includes a repository with over a billion records, built on software with full-text and handwriting search already installed. Name-search is blocked by a setting, not by the architecture. Record intake has expanded by internal memo rather than by rulemaking. The whole system rests on the agency’s promise that it will never be used as a registry. Those safeguards can be undone by the people in charge. A hostile ATF wouldn’t need to build a registry. It would only need to switch one on.

To be fair, ATF didn’t invent this repository on its own. Federal law, 18 U.S.C. § 923(g)(4), requires a dealer who goes out of business to turn their records over to the government, and ATF is the agency that has to receive them. That’s exactly why this can’t be left to ATF alone. The agency can make the system more secure, but only Congress can decide whether a billion records need to sit in one federal building at all. Technical and legal fixes have to happen together.

That’s why the time to act is now, while the agency is cooperative and the fixes can be made in good faith rather than forced in a fight. Protections that depend on who holds office aren’t protections. They must be built into the system and written into law, so no future administration can quietly reverse them, and no outside hacker can exploit them. Congress should demand answers on seven fronts:

    1. Full disclosure of the Qilin breach. ATF and DOJ should say exactly what Qilin obtained, and whether any technical pathway ever connected the compromised CALEA system to OBRIS, A2K, or eTrace. “Standalone” should be demonstrated, not asserted
    2. An independent technical audit of name-search. Someone outside ATF should confirm that name-search is disabled at the database level, not just switched off in a menu. A setting that can be turned off can be turned back on.
    3. A secure, encrypted upload system for dealer records. If the law requires dealers to surrender a lifetime of customer records, ATF must give them a secure way to do it. It should stop accepting unencrypted emailed records, so dealer data is protected in transit and not only after it arrives.
    4. A public accounting of access. ATF should disclose who has access to a database now with more than a billion records, and what background standard they had to meet to get it.
    5. A hard stop on records expansion outside rulemaking. ATF should stop quietly expanding what records it accepts, including its push for active dealers to send in records older than 20 years, outside the rulemaking process the law actually requires.
    6. A department-wide security review. The DOJ Inspector General should conduct a dedicated FISMA audit of ATF’s own network, and a broader review of why DOJ components keep losing sensitive data from systems described as “standalone.” That review should cover the Marshals in 2023, the FBI’s wiretap network and personnel data in 2026, and now ATF.
    7. Revisit the law that created the repository. Congress wrote the out-of-business records requirement, and Congress can change it. At minimum, it should decide whether decades-old records with no connection to any trace need to be kept forever, or whether they can be purged after a set period. It should also weigh whether records have to be centralized in a single federal repository at all. Tracing can work without the government holding a permanent, near-complete archive of who bought what. Every record that isn’t collected is a record no future administration can misuse, and no hacker can steal.

Thirty years of audits have produced the same conclusion every time: ATF says the records aren’t a registry, and then an outside auditor finds a program, a server, or a software bug that says otherwise. Today’s ATF has accepted those findings, fixed a number of them, and been more transparent than many of its predecessors. But that is exactly why this is the moment to finish the job. A database of more than a billion records will outlast any director and any president. The question isn’t whether gun owners can trust this ATF. It’s whether they can trust every ATF that comes after it, under every administration yet to be elected. The only safe answer is a system that doesn’t require that trust at all, one that can’t be switched on as a registry and can’t be broken into by the next Qilin. Congress has a cooperative agency and a narrow window. It should use both.


About John Crump

Mr. Crump is an NRA instructor and constitutional activist with more than 26 years of experience in networking and cybersecurity for major Fortune 100 companies. John has written about firearms, the Constitution, and cybersecurity, and has interviewed people from all walks of life. John lives in Northern Virginia with his wife and sons. Follow him on X at @right2bear, or at www.crumpy.com.

John Crump




from https://ift.tt/hwHegkJ
via IFTTT

The Holy Trinity of Second Amendment Law: Heller, McDonald, and Bruen

Supreme Court behind monuments engraved Heller, McDonald, and Bruen, with the Second Amendment and a safely holstered handgun.
Heller, McDonald, and Bruen form the foundation of modern Second Amendment jurisprudence. AI-generated illustration by AmmoLand News using OpenAI.

At this year’s Gun Rights Policy Conference, hosted by the Second Amendment Foundation, in Dallas, I heard District of Columbia v. Heller, McDonald v. City of Chicago, and New York State Rifle & Pistol Association v. Bruen described as the “holy trinity” of Second Amendment law. The phrase stuck because it perfectly captures how the three decisions work together.

Heller identified the right. McDonald applied it nationwide. Bruen gave courts the test required to enforce it.

For most of the twentieth century, gun-control advocates treated the Second Amendment as though it were a constitutional artifact—words preserved in the Bill of Rights but denied their ordinary meaning whenever an American entered a courtroom. Three Supreme Court decisions broke that fiction.

District of Columbia v. Heller established that the Second Amendment protects an individual right to keep and bear arms. McDonald v. City of Chicago held that the right binds state and local governments, not merely Washington, D.C., and the federal government. New York State Rifle & Pistol Association v. Bruen confirmed that the right extends beyond the home and ordered courts to judge gun laws by the Constitution’s text and the nation’s historical tradition, not by a judge’s opinion of whether gun control is useful.

Together, Heller, McDonald, and Bruen form the holy trinity of modern Second Amendment jurisprudence. One identified the right. One applied it nationwide. One gave it an enforceable test.

Heller: The Second Amendment Protects an Individual Right

Restoration of the Second Amendment began on June 26, 2008.

Dick Heller was a D.C. special police officer who could carry a handgun while working at a federal building but was denied permission to keep one functional in his own home. At the time, the District of Columbia effectively banned handgun possession and required other firearms in the home to be kept unloaded and disassembled or secured by a trigger lock.

In a 5–4 opinion written by Justice Antonin Scalia, the Supreme Court held that those restrictions violated the Second Amendment.

The Court’s central conclusion was unmistakable: the Second Amendment protects “an individual right to possess a firearm unconnected with service in a militia” and to use that firearm for traditionally lawful purposes, including self-defense in the home.

That holding demolished the gun-control movement’s preferred “collective right” theory. The phrase “the right of the people” means what it means elsewhere in the Bill of Rights: a right belonging to individual Americans. The prefatory reference to a well-regulated militia announces a purpose; it does not erase or narrow the operative command that “the right of the people to keep and bear Arms, shall not be infringed.”

Heller also recognized self-defense as the central component of the right and handguns as protected arms. The government could not prohibit an entire class of arms overwhelmingly chosen by Americans for lawful defense.

The decision further explained that the Second Amendment extends to arms “in common use” for lawful purposes. That principle remains central to challenges against bans on popular semiautomatic rifles, standard-capacity magazines, and other arms owned by millions of peaceable Americans.

Gun-control lawyers routinely seize on Heller’s statement that the right is “not unlimited.” That sentence is not a blank check for every restriction lawmakers can invent. Heller rejected interest balancing and declared that the Second Amendment itself is the result of the people’s decision to place the right above ordinary legislative preferences. The government does not get to balance an enumerated right away by repeating the words “public safety.”

Most importantly, the Court did not create a right in Heller. The Second Amendment codified a pre-existing right. Heller merely forced the judiciary to acknowledge what the Constitution had said since 1791.

Read the Supreme Court’s opinion in District of Columbia v. Heller.

McDonald: The Right Binds Every Level of Government

Heller answered whether the federal government and the District of Columbia could disarm Americans. It left an immediate practical question: Could a state or city do what D.C. could not? Chicago attempted exactly that.

Otis McDonald was a 76-year-old Army veteran who lived in a crime-plagued Chicago neighborhood and wanted a handgun to defend himself and his home. Chicago’s handgun-registration system made lawful handgun possession effectively impossible for ordinary residents.

On June 28, 2010, the Supreme Court answered in McDonald v. City of Chicago. Again by a 5–4 vote, the Court held that the Fourteenth Amendment makes the Second Amendment right “fully applicable to the States.”

Justice Samuel Alito’s controlling opinion concluded that the right recognized in Heller is fundamental to the nation’s scheme of ordered liberty and deeply rooted in American history and tradition. The plurality applied it to the states through the Fourteenth Amendment’s Due Process Clause.

Justice Clarence Thomas supplied the decisive fifth vote but argued for a more textually faithful route: the Fourteenth Amendment’s Privileges or Immunities Clause. His historical examination focused heavily on Reconstruction, when freedmen were routinely disarmed and left defenseless against private violence and hostile governments.

The right to keep and bear arms was never an indulgence reserved for the politically connected. It was understood as essential to citizenship, personal security, and the ability of Americans, especially those whom government failed or refused to protect, to defend themselves.

McDonald transformed Heller from a ruling aimed principally at federal power into a nationwide command. California, New York, Illinois, New Jersey, Hawaii, and every city and county within them are bound by the same Second Amendment as Congress and the District of Columbia. There is no watered-down state version of the right.

Without McDonald, the most aggressive state and local gun-control regimes would argue that Heller did not reach them. With McDonald, every level of American government must answer to the Second Amendment.

Read the Supreme Court’s opinion in McDonald v. City of Chicago.

Bruen: The Right Leaves the Front Door

After Heller and McDonald, lower courts adopted a two-step test that paid lip service to history before applying “intermediate scrutiny.” In practice, that second step allowed judges to uphold gun laws whenever the government claimed an important objective and offered studies, speculation, or legislative findings to support it.

The right existed on paper, but courts repeatedly deferred to the same governments accused of violating it. Bruen ended interest balancing.

New York required an applicant to prove “proper cause” before the state would issue an unrestricted license to carry a handgun in public. Ordinary citizens could not receive permission merely because they wished to carry a firearm for self-defense. They had to convince a government official that they faced a special danger beyond that confronting the general public.

On June 23, 2022, the Supreme Court struck down New York’s discretionary regime in a 6–3 opinion written by Justice Thomas. The Second and Fourteenth Amendments protect the right of ordinary, law-abiding citizens to carry a handgun publicly for self-defense. The Constitution does not confine “bear Arms” to one’s living room.

Just as important, Bruen rejected the lower courts’ two-step framework as “one step too many.” The Court announced the governing rule:

When the Second Amendment’s plain text covers an individual’s conduct, the Constitution presumptively protects that conduct. The government must then justify its restriction by proving that it is consistent with the nation’s historical tradition of firearm regulation.

That burden belongs to the government, not the citizen.

Judges may no longer ask whether a modern gun restriction seems sensible, whether lawmakers called it necessary, or whether the asserted public benefit outweighs the burden on armed citizens. The people completed that interest balancing when they adopted the Second Amendment.

Nor may the government satisfy Bruen by finding one obscure outlier law or by pointing to restrictions adopted long after the relevant constitutional period. History must reveal a genuine American tradition of comparable regulation. When an unprecedented modern law addresses a social concern that existed at the Founding but the Founding generation did not impose a comparable restriction, that absence is powerful evidence against the law.

Bruen did not prohibit objective “shall-issue” licensing systems, but it warned that licensing rules can still be unconstitutional when officials use exorbitant fees or lengthy delays to deny ordinary citizens the right to carry.

Read the Supreme Court’s opinion in New York State Rifle & Pistol Association v. Bruen.

How Heller, McDonald, and Bruen Work Together

The three decisions are strongest when understood as one constitutional structure:

Heller identifies the right: Individual Americans possess the right to keep and bear arms for lawful purposes, with self-defense at its core.

McDonald identifies who must obey it: Federal, state, and local governments are all bound by the Second Amendment.

Bruen identifies how courts must enforce it: Protected conduct is presumed constitutional, and the government must prove that its restriction fits this nation’s historical tradition of firearm regulation.

Remove any one of the three and the protection becomes incomplete. Heller without McDonald would leave state and local governments room to disarm their citizens. Heller and McDonald without Bruen would leave hostile judges free to balance the right into irrelevance. Bruen rests on the individual right and incorporation established by the cases before it.

Later Supreme Court decisions have discussed how historical analogues should be evaluated. They have not displaced this foundation. A historical analogue need not be a dead ringer for a modern law, but the government still must establish a relevant historical tradition. Policy preferences and judicial deference remain insufficient. The historical record, not a judge’s policy preference, remains the proper guide.

AmmoLand has repeatedly documented lower courts’ attempts to dilute Bruen, revive interest balancing under new names, or accept historical substitutes that would never survive serious scrutiny. That resistance shows that anti-gun states will continue to dismiss rulings from the Supreme Court.

The Second Amendment Is Not a Second-Class Right

The Constitution does not grant Americans the right to keep and bear arms. It recognizes and protects a right that predated the document itself. The final words, “shall not be infringed,” are a command to the government, not a suggestion.

As Supreme Court Justice Clarence Thomas recently said on a podcast, the Second Amendment assumes the people have the right to bear arms; it does not grant it.

Heller, McDonald, and Bruen did not deliver everything Second Amendment absolutists seek. Courts still tolerate laws that cannot be reconciled with the Amendment’s plain language, and governments continue testing how much resistance or delay they can place between citizens and their rights.

But these three cases changed the legal battlefield.

The right belongs to the individual. It binds every level of government. It applies inside and outside the home. When the right’s text covers the conduct, the government—not the citizen—must justify an infringement through the nation’s historical tradition.

That is the holy trinity of Second Amendment jurisprudence, and every gun owner should understand it.


About Duncan Johnson:

Duncan Johnson is a lifelong firearms enthusiast and unwavering defender of the Second Amendment—where “shall not be infringed” means exactly what it says. A graduate of George Mason University, he enjoys competing in local USPSA and multi-gun competitions whenever he’s not covering the latest in gun rights and firearm policy. Duncan is a regular contributor and editor-in-chief for AmmoLand News and is responsible for AmmoLand’s daily gun-rights reporting and industry coverage.Duncan Johnson




from https://ift.tt/JRUjZx9
via IFTTT