From the analysis linked in TFA:
"The automated query can be based on: * Identity information included in the application or in travel documents, such as name, date of birth, national ID number, and/or * the fingerprint of an individual."
Sounds like they could send requests to that computer system just based on publicly available information on a person like name and date of birth, even if the person never applied for a visa or tried to enter the US.
They probably could, but if done on a large scale, they are likely to be detected.
Only the people who travel to the US should be included in this farce and vice versa the other way…
It changes the nature of the scheme quite a bit
Well, a national ID number isnt usually publicly available info, even if it can be obtained by the US government through illicit means.
But yeah, it does sound that way, but certainly not clear cut to me what the situation is. I.e. does the agreement involve clauses about what to do if this is abused? Do we have a way to detect if theyre using this on non-travellers? Etc.