Thread Konnech and Elections / Original thread

I'm gonna post my articles as they were first published, in full naive, dorky, eager beaver…

Original posts. Original order. Sources and media stay with them.

By Gus Quixote

December 29, 20233 posts8 source URLs11 archived media items
Back to threads
01December 29, 2023Gus Quixote3-post record
I'm gonna post my articles as they were first published, in full naive, dorky, eager beaver form, all here on X.

August 18, 2022
"What Does PollChief Have To Do With Me?"
A story that isn't anything you clicked into this thinking about.

>https://t.co/t84uCsjzoQ

Imagine with me, if you can:

The year is 2022. Midterms are swiftly approaching with no shortage of nuclear-bomb-sized revelations of ever-growing scandals in the Department of Justice’s negligence and lop-sided application of justice to elections, insurrections, subversive attempts to overthrow duly elected government, social activism, kompromat, espionage, all continuing to pile onto the Bureau’s already speckled history. Twenty-one months following the hotly contested 2020 Presidential election, there is still a growing collective of election skeptics. There is also no shortage of citizen journalists working feverishly to pull back the curtain on our election processes for the Public, toward reestablishing trust and integrity in the system that has long been broken.

Among these citizen journalists is none other than @KanekoaTheGreat, a writer who has compiled an impressive resume of exposes and analysis over the past several years, and has also earned a loyal following that rivals many of the mainstream’s most notable writers. Kanekoa’s latest offerings have focused on a company called Konnech - a small business specializing in election management software based in a quiet Michigan township. You can check out Kanekoa’s work in exploring the Konnech company here:
>https://t.co/AJ1t0yf9pa

There is still to date no direct, legal evidence of machine manipulation in any American elections [since has changed]. So after learning a bit about Konnech, it stands to offer the question:

Why care about a small business that writes election management software?

For some insight, let’s shift focus momentarily.

Okta is a very successful company founded in 2009 with a reputation in secure data authentication. Their services are run exclusively on Amazon Web Services or AWS. AWS owns and operates massive data facilities globally that process an enormous swath of data on the internet as a whole. Despite Okta’s wild success story, it has not come without their share of issues. They’ve experienced multiple data breaches in recent years, but have reported minimal setbacks and seem to have been able to respond to these incursions effectively.

>https://t.co/ozj6COm60I.
3 source links
02December 29, 2023Gus Quixote3-post record
2/
"What Does PollChief Have To Do With Me?"

Why bring Okta and their success in data authentication into a discussion about elections that many people still claim were corrupted by nefarious behavior? Not because of what you may think.

The Los Angeles County Registrar-Recorder/County Clerk website provides an election management system diagram that maps what appears to be a plan for implementing a future election system, based from the page’s title, “EMS Future State v15” found at:

>https://t.co/UTVSbhBpPO

This diagram, highlighted in yellow, shows “OKTA,” “PollChief,” “Data Integration,” and “County API Gateway”. In red, “EMS,” or Election Management System. Also note the legend in the bottom left corner and the color-coded representations displayed by the boxes in their diagram.

PollChief is the software developed by Konnech and covered in Kanekoa’s previous piece. All data processed through the whole of the Election Management System is routed through the PollChief software, which is subsequently sent to “OKTA” for “SSO” and “MFA” - “Single Sign-On” and “Multi-Factor Authentication” protocols. While this is an authentication process that happens millions upon millions of times daily, it also lends an apprehension a bit above that of ordering overpriced, amber-colored Edison bulbs for the living room.

This offers a new lens through which to observe some notable hacks from recent history. The list is more extensive than I care to waste your time and my keyboard for, but I’ll leave an example of a very public one that occurred around the same general time as the 2020 elections. This breach also happened to a company that uses Amazon Web Services as does Okta (our focus today):

>https://t.co/8l11X3LgZa
2 source links
03December 29, 2023Gus Quixote3-post record
3/
"What Does PollChief Have To Do With Me?"

So now we have learned that a customer of AWS can set up a “backdoor” into anything also connected to AWS and implant code into already existing software gradually over time, making it virtually undetectable? Who else have we learned uses Amazon Web Services?

Correct. Okta.

Refer back to Los Angeles County, where Konnech’s “PollChief” software seems planned to be used in the future. If you notice “County API Gateway”, it would suggest that all of the data held by the County administration would be accessible through EMS, PollChief, all the way to the Okta data portal. The portal uses AWS, which we previously established has been “backdoored” during the SolarWinds breach without any real intrusion into their software at once. The real possibility exists, evidenced by the SolarWinds attack, for a complete compromise of every vote, poll worker and their personal data, and the whole of election procedure in general that would be managed using Okta authentication services, with or without any actual incursion into the system itself. This is a glaring vulnerability for normal, everyday Americans.

It leaves me with one nagging business question after learning all of this: If Okta has such a stranglehold in the data authentication industry, then who is their competition in such a seemingly niche service?

Answer: A Chinese company called Authing.

>https://t.co/1OOOxrSYK9
>https://t.co/kVzJYRh301
>https://t.co/uXOzw14lTa

There have been multiple statements from state and federal officials addressing their investigations into the 2020 election and “unfounded” claims of digital manipulation.

Not one of those statements have approached acknowledging the existence of this vulnerability, to which most experts agree there is no guarantee of preventing.

Is it time for us to demand they to disclose everything they found, being that they have consistently reported no areas of “legitimate concern”?

Is it time to demand that every group involved in our most sacred tradition — the cornerstone of “democracy” — tangibly prove to the American citizens that what happened to SolarWinds could and never did happen to our elections?

Much more to come…

ARTICLE: https://t.co/t84uCsjzoQ
4 source links
Search the receipts

Start typing. Articles, threads, authors, and collections are all in the same file.