There is a new substack circulating from This Will Hold alleging that an NSA whistleblower has claimed the NSA audited the 2024 election and found Trump did not win. I've received several inquiries on my thoughts on this (and I'm cited) so I wanted to offer this 🧵 for those that are interested. 1/ The NSA does not conduct post election audits. Period. It does not have the authority to access either voting systems or ballots. Elections (in 2024) were run entirely at the state level (though the Trump administration is making chilling moves to insert the feds into election administration). 2/ There is no world in which the Biden Administration would have ordered the NSA to access voting machines and ballots, and that wouldn't have caused a huge uproar and become very public very quickly. For the most part, election officials guard their election equipment very closely 3/ ...and know that the NSA has no jurisdiction to examine election systems. This is why, despite common misconceptions, the DHS did not do an audit of the 2016 election even though it established that Russian intelligence did try to access and attack 4/ thedailybeast.com
www.thedailybeast.com
...election infrastructure. This is also why, in 2020, when Trump sought to seize voting equipment, he was advised that the federal government could not do so. 5/ cnn.com
www.cnn.com
Not only would the Biden administration not have had the authority to direct the NSA to conduct an audit, it certainly would have become publicly known very quickly. This claim is just unbelievable. Regarding the other claims in the This Will Hold Substack...6/ The author claims that the approval of an Engineering Change Order (ECO) to a certain version of ES&S software is the open back door necessary to rig elections, and she cites an article written by Andrew Appel and myself to support this, but there are several facts that undermine this claim. 7/ The ECO cited is only for EVS 6.5.0.0, a version of ES&S software that is very new, and as a result, very sparsely in use. This Will Hold appears to assume that one ECO impacts all ES&S equipment, but that's not the case. More importantly, the premise of the supposition regarding the ECO is that 8/ ...voting systems in use are regularly and effectively hash tested, and therefore a back door like this would be necessary to be able to infect the system with malware and not be detected. But, as pointed out in the article Andrew and I wrote, hash testing is poorly done and ineffective. Further, 9/ ...ES&S has instructed election officials to just ignore mismatched hash tests. So I don't see the need for this ECO, (which was only applicable to a very small slice of the electorate), to hide malware. If no one is going to look for the malware, you don't really need to hide it. 10/ Additionally, really good malware will just evade hash testing. And this is more generally my concern with the theories offered by the This Will Hold substack. There seems to be an assumption that the systems are adequately secured, so theories are offered explaining how the systems could...11/ be manipulated to evade existing protections. But I think that's the wrong assumption. We know these systems are inadequately secured and vulnerable to exploits. 12/ blog.citp.princeton.edu
blog.citp.princeton.edu
We know that some of them STILL are using wireless modems that connect them to the internet. 13/ politico.com
www.politico.com
We know that insider threat - the possibility that a corrupted vendor employee or election official could allow physical assess to machines - is the number one risk, and yet it's hand-waved away and deftly ignored. 14/ brennancenter.org
www.brennancenter.org
And possibly most important, before the '24 election, voting systems and proprietary software were improperly accessed by Trump allies, enabling potential bad actors to develop stealth, sophisticated attacks that could evade pre-election testing and be launched...15/ pbs.org
www.pbs.org
with minimal access. So while I don't find the theories offered by This Will Hold very persuasive, that does not equate to suggesting that we have evidence that the election was secure - to the contrary - we have evidence that the software and systems were compromised before the election. And 16/ we have reviewed the post-election audits in the swing states and found that they were mostly insufficient to provide evidence that affirms the computer generated results, which will be released soon, stay tuned...