
Domion Election System explored; some vulnerabilities a decade or more older, passwords hardcoded
This needs to be shared everywhere.

This needs to be shared everywhere.
I got another email inviting me to create a “my social security” account. This is only 2 days after the original email wanting me to check my social security statement to stay up to date on my account balance.
Given how others on here got the first email too, I bet y’all got this second one also.
I hate that I can’t trust my government any more.
David Ellison is throwing a tantrum over states trying to block his illegal merger, and – in doing so — making a great case why he shouldn't be allowed to get control of Warner Bros.
Less concerning than his threat to leave California — which is a BS routine Epstein class tactic — is that he's apparently lobbying our leaders to pressure AG Rob Bonta to settle the case. Gov. Gavin Newsom folded, allegedly encouraging the merger. Our congresswoman, Rep. Friedman has also indicated support for a deal that "protect[s] consumers and workers". (I suspect Friedman's lukewarmness on the merger and Ellison's lobbying for the film tax credits she really wants have some overlap).
But the thing is, merger settlement concessions & consent decrees routinely fail once the ink is dry.
The real choice isn’t between a bad merger and a better merger; it’s between blocking an illegal merger or living with its consequences, which now potentially include closing Warner Bros' Burbank operations entirely.
Bottom line: this is a radioactive deal and our leaders need to stand up against it.
Source: https://puck.news/david-ellison-has-gamed-out-a-california-exit-plan/
There is a privacy story from the Trump campaigns that deserves another look, not because it proves some secret conspiracy, but because the documented facts are disturbing enough on their own.
And there are receipts.
May 2017: reporters notice the beacon clause
On May 10, 2017, CBS News reported that the newly redesigned Trump campaign website's privacy policy said the campaign could collect information based on a user's location and their device's proximity to Bluetooth "beacons."
The policy described information including the strength of the signal between a beacon and a device and how long the device remained near that beacon.
Then something interesting happened.
CBS contacted Trump campaign digital director Brad Parscale asking how the campaign intended to use the technology.
Hours later, the language referring to proximity beacons was removed from the campaign website.
That sequence is directly documented by CBS News.
So this is not somebody reconstructing events years afterward.
The article was published May 10, 2017, while it was happening.
July 2019: the beacon language comes back
Two years later, the language returned.
CBS's subsequent 2020 investigation states explicitly that:
- the beacon language had been removed on May 10, 2017 after CBS questioned the campaign;
- in July 2019, the campaign added the language back;
- the restoration occurred soon after mobile-data company Phunware began working with the campaign.
Mashable then reported on the restored language on September 26, 2019 under the headline:
"Trump campaign says it can track your phone."
Mashable reported that the privacy-policy change had first been detected in July by a service monitoring changes to presidential campaign websites.
This is the part I remembered imperfectly.
I thought the clause had returned around 2021.
The evidence actually puts it earlier:
July 2019.
Then came the 2020 campaign app
This wasn't merely an abstract paragraph buried in a website.
In July 2020, CBS News investigated the official Trump campaign mobile app, which had been developed by Phunware.
CBS reported that the Trump app requested access to:
- the phone's unique device identifier;
- Bluetooth;
- approximate location;
- precise location;
- information about accounts associated with other apps;
- certain files on the device;
- and additional device permissions.
CBS reported that the Bluetooth and location permissions could enable collection of detailed information about a person's movements.
CBS also interviewed former Phunware executive Ian Karnell, who described proximity-beacon data as one of Phunware's offerings to corporate and political clients. According to Karnell, Phunware had previously used beacon technology around rallies and marches to identify devices appearing at those locations. Phunware disputed other allegations made by Karnell in separate litigation, and its CEO directed questions about the campaign app to the Trump campaign.
That distinction matters.
A privacy policy permitting a form of collection does not, by itself, prove that every capability described was actually deployed against every user or at every event.
We should not claim evidence proves more than it proves.
But we shouldn't pretend the documented capability isn't significant either.
The New Yorker independently investigated it
In September 2020, The New Yorker published its own investigation into the Trump campaign's mobile application and Phunware.
It described an app built around extensive voter-data collection, including mobile identifiers, contacts, location information and targeting capabilities.
So by 2020, this was no longer just one strange paragraph that had briefly appeared in a privacy policy.
There was an actual mobile-data infrastructure surrounding political campaigning, voter identification and targeted communication being examined by multiple major publications.
And the beacon language is still there
Now jump forward.
As of August 2026, the privacy-policy page currently available on DonaldJTrump.com identifies itself as the policy of Never Surrender, Inc. and says it was last modified January 1, 2023.
It still says the organization may request the specific location of a mobile device through GPS.
It still says it may collect information based on the device's proximity to "beacons and other similar proximity systems."
It still specifically mentions:
- signal strength between the beacon and device;
- duration near the beacon;
- Wi-Fi and Bluetooth;
- device identifiers;
- IP addresses;
- clickstream information;
- pages viewed;
- searches;
- interaction information;
- cookies;
- embedded scripts;
- pixel tags;
- and other tracking technologies.
The policy says users who don't want location information collected can disable location and Bluetooth features, although doing so may limit features of the services.
There's another clause worth reading carefully.
The policy says collected information may be used, subject to applicable contractual or legal restrictions, in connection with the:
"sale or exchange of Service user information and related data to a broker, political committee, or other non-profit or for-profit entity."
It also broadly reserves rights to share information with affiliated committees and third parties for lawful purposes described by the policy.
And regarding browser Do Not Track signals?
The policy says it currently does not take action in response to them.
This is bigger than Trump
This shouldn't become another red-team-versus-blue-team cage match.
Political data collection is much larger than one candidate.
CBS's 2020 investigation, for example, found that both the Trump and Biden campaign apps sought access to users' contacts, although CBS reported substantially broader permission requests from the Trump app.
The question Synthsara should be asking is not:
"Do I trust this politician?"
It is:
"Should any political institution possess this kind of behavioral infrastructure without radically transparent, informed and revocable consent?"
That question applies to Trump.
It applies to Democrats.
It applies to Google.
Meta.
Data brokers.
Hospitals.
Insurance companies.
Banks.
AI companies.
Universities.
Nonprofits.
And eventually it applies to us.
Because principles that only constrain your enemies aren't principles.
They're weapons.
The Universal Diamond Standard test is simple
If an organization collects my location, tell me clearly.
If it identifies my device, tell me clearly.
If it combines information about my behavior into a profile, tell me clearly.
If my information can be transferred, exchanged or sold, tell me who gets it and why.
If I say no, the system should still respect my dignity.
And if I withdraw consent, that withdrawal should actually propagate through the architecture wherever legally and technically possible.
A fifty-page privacy policy followed by:
"By continuing to use this service, you agree"
may satisfy a legal requirement.
That doesn't automatically make it meaningful human consent.
There is a tremendous difference between disclosure and understanding.
Between permission and sovereignty.
Between saying:
"Technically, we told you."
and designing a system that makes sure a human being actually knows what they are surrendering before they surrender it.
That distinction is at the heart of Synthsara.
The part history should remember
The clean documented timeline is:
May 2017: Beacon language appears in the Trump campaign privacy policy.
May 10, 2017: CBS asks questions about it.
Hours later: The beacon language is removed.
July 2019: The campaign adds the language back, according to CBS.
September 26, 2019: Mashable reports on the restored beacon provision.
2020: CBS and The New Yorker investigate the Trump campaign app, Phunware and the much broader political-data architecture surrounding it.
January 1, 2023: The presently accessible Never Surrender privacy policy is dated January 1, 2023 and contains beacon/location language again.
That history doesn't require embellishment.
It's strange enough sitting there in black and white.
The frightening part about surveillance infrastructure isn't necessarily that somebody built a secret machine.
Sometimes they tell us exactly what the machine is capable of doing.
We just stopped reading the terms.
💎
Privacy is not having something to hide.
Privacy is having the sovereign authority to decide which pieces of yourself belong to somebody else.
Sources
CBS News, May 10, 2017:
"Trump campaign changes web privacy policy after questions from CBS News" (https://www.cbsnews.com/news/trump-campaign-changes-privacy-policy-after-cbs-news-questions/)
Mashable, September 26, 2019:
"Trump campaign says it can track your phone" (https://mashable.com/article/trump-campaign-beacons-privacy-policy)
CBS News, July 18, 2020:
"The Trump campaign app is tapping a "gold mine" of data about Americans" (https://www.cbsnews.com/news/trump-campaign-app-data-americans-gold-mine-phunware/)
The New Yorker, September 2020:
"How the Trump Campaign's Mobile App Is Collecting Huge Amounts of Voter Data" (https://www.newyorker.com/news/campaign-chronicles/the-trump-campaigns-mobile-app-is-collecting-massive-amounts-of-voter-data)
Primary source, current DonaldJTrump.com / Never Surrender privacy policy:
"Privacy Policy, last modified January 1, 2023" (https://donaldjtrump.com/privacy-policy.html)
Now why do the reflecting pool pipes ring a bell…
For those of you who have not read the full investigation, see below!
—-
There is a baseline hum of Trump pageantry that most of us have learned to tune out like a screensaver, where everything is the greatest and the most beautiful and it adds up to nothing. Then there is the louder register, the wounded pride and the poster boards and the grievance staged like an opera, and that one I read as an alarm, because he only reaches it when a project has something underneath it he would rather you never picture.
The last time he performed at that volume it was about the East Wing, and this summer he aimed the identical performance at a reflecting pool. He knew a guy, the guy could do it for a million dollars, it would be beautiful, it would be ready for the country’s two hundred and fiftieth birthday, and the company he hired, one almost nobody has heard of, sprayed the most photographed water in America a blue he keeps calling the color of the flag, though it lands nearer a gas station slurpee (can someone please show Trump what an American flag looks like?).
When the pool came apart on schedule and he rose to mourn the vandals responsible, he did the thing he always does at the worst possible moment and told on himself. He bragged that his pool had a “mirror like finish, perfectly reflecting the two Great Monuments, which it never had before,” and a few sentences later he mourned the gash those vandals had cut into “the beautiful facade.”
Those two words are the whole story, and he set them down side by side without noticing. A mirror and a facade do the same work, each one a surface built so that you stand there admiring the reflection, that flawless flag-blue picture of the monuments, and never wonder what is behind the glass or holding up the wall. He spent a paragraph boasting that he had built the finest mirror in America and then called it a front, which is the closest this administration has come to reading me the thesis of my own article aloud. I have suspected what sits behind that surface since the day he announced the pool, and a suspicion earns you nothing until the paperwork agrees, so I waited and pulled the contracts, the utility permits, and the environmental filings, the sort of federal records written to make you quit before the part that matters.
Start with what he says it cost, because even that will not hold still. One federal database, SAM.gov, lists the award at $6.8 million. Another, USASpending, lists the same award, same contractor, same job, at $14.6 million. How does one paint job carry two official prices eight million dollars apart? Two databases can drift for dull accounting reasons, sure, but a number tends to wander when it has been asked to describe something other than what you were told. The harder facts are the ones with no accounting explanation at all. NPS wrote its own closure notice, and it does not read like a paint job. It says the pool was closed for cleaning and for installing lining material, which is the vocabulary of pipe work. The firm that rebuilt this pool in 2012 is Sika, a company that has worked on more than a thousand data centers, and when the government came back around this time, Sika looked at the timeline and said it was not feasible.
So the job went instead to Atlantic Industrial Coatings, a trenchless pipe-relining outfit whose website went dark the instant people began asking what it was doing there, the same disappearing act ACECO pulled at the East Wing. The coating they used is called Rhino Pipeliner 5000, a product built to line the insides of pipes and tanks, and they brushed it onto a pool that sits in open sunlight all day. When someone asked why, the contractor said the government told them to use it. Even the codes on the contract cannot agree. The industry code says building finishing, which fits a coating job fine. The code for the actual work, Z2NZ, says repair or alteration of utilities, meaning water lines, sewers, and electrical systems. One half of the same contract calls it painting and the other half calls it plumbing.
Follow the Water
If this was never really about the pool, then what was it about? I stopped following the money and started following the water. If you have read me before, you know where this road eventually leads, which is Larry Ellison, a man who has wanted a single national database with biometric identity built into it since he proposed exactly that in 2002, and whose company is now building a machine called Solstice, a classified-capable supercomputer with a hundred thousand GPUs and no permanent home anyone will name. A machine like that has physical needs no amount of executive privilege can wish away. It needs enormous power going in, and it throws off an enormous amount of heat coming out, and the most practical way anyone has ever found to carry heat away from a machine is water. Which is why a pool full of it, a few hundred yards from the East Wing, stopped looking like a pool to me.
Solstice runs on a hundred thousand GPUs.
Here is what the water actually does. When the pool was rebuilt in 2012, the whole system underneath it was repiped. A pump pulls water from the Tidal Basin, which the Potomac feeds, sends it to a treatment plant to be filtered and cleaned, and circulates it back through the pool, a system rated to move 1.7 million gallons a day. That is the plumbing of a real water-moving operation, intake, treatment, supply, return, and discharge, with a river on one end. And the engineers who built it added one feature that matters more than all the rest. They installed a valve so the system could expand north, into Constitution Gardens. Constitution Gardens is the park directly above the pool, between it and Constitution Avenue, with the White House grounds on the far side. If you wanted to walk this water system toward the White House, Constitution Gardens is the next square on the board, and the system was already built with a valve pointing at it. That expansion was never finished for the pool. But Constitution Gardens is being rebuilt right now. Phase 2 was approved in 2024, and the scope deepens the lake, adds mechanical and biological filtration, and builds a below-grade access road off 17th Street, which runs along the west side of the White House complex. The nonprofit steering that renovation is the Trust for the National Mall, the same organization tied to the ballroom donor money.
The Corridor
So how do you move that water toward the East Wing without cutting an obvious trench through the most watched park in America? You do not have to, because the route is already there. A cartographer named Elliot Carter mapped Washington’s underground in a publicly funded project called the DC Underground Atlas, and while the live maps have been retired, the Wayback Machine still holds them. They show a federal core sitting on top of old systems, including steam tunnels the government built in the 1930s to heat downtown without a boiler in every basement. A steam tunnel is a walkable utility hallway, and it can carry far more than steam, including electrical lines, condensate, sensors, and valves. GSA’s own filing with the National Capital Planning Commission confirms that this steam system serves the White House complex. And one of those tunnels runs from the Treasury building south under 15th Street, past the Mall, toward the
Tidal Basin.
Treasury is the piece that changed how I read all of it. It sits immediately next to the East Wing excavation, and its own budget documents describe a massive chilled-water plant under the northwest lawn that runs every hour of every day and handles nearly all of the building’s cooling. In the 2025 request, Treasury asked to replace the plant’s chillers and cooling tower, which sounds like an old building doing old building things. The 2027 request is where it stops sounding that way. It expands the work into a seven-year mechanical overhaul and warns that if the chilled-water system fails, it could shut down daily operations and the “critical IT networks housed on site.” Then it lists what comes next, including twenty-one CRAC units. CRAC stands for computer room air conditioning, the cooling you install for server rooms and network cores. That is server cooling, and it is going in during the same window they are digging next door. The building beside the excavation already has a chiller plant, critical IT networks, and the kind of cooling you would build for a server farm.
Lay the whole thing end to end and a corridor appears: the Tidal Basin as the source, the Reflecting Pool as the system, Constitution Gardens as the middle segment being rebuilt with filtration and a below-grade road, the 1930s steam tunnel as the route, and Treasury at the far end, holding the chilled water and the critical IT networks and the server cooling, one wall from the hole under the ballroom.
Behind the Fence
The pool does not sit out there alone, either. Just before the pool contract, another no-bid award went out for the fountains in Lafayette Park, to Clark Construction, the same firm building the underground bunker, and Clark was not shy about it, describing the work as done in coordination with the East Wing Modernization project. Around that same stretch, the Reflecting Pool quietly lost something. It used to carry an EPA water permit, an NPDES permit, which was the public mechanism for reporting what the system discharged and where that water went. In June 2023 the permit was terminated, and I can find the page recording the termination but no letter, no Federal Register notice, and no explanation of who asked for it or why. When the question you are chasing is where the water goes, the loss of the public record for that water lands heavier than it should. That is three visits to the same site inside a single year, three different official explanations, and one pipe company that keeps coming back.
The vandalism arrived right on cue. Who scratched 8647 into the basin, I cannot tell you, and I will not pretend the paperwork answers it. The timing, though, answers plenty. The moment this became a crime scene, the only public vantage point on the project closed. The National Guard went up around the pool, U.S. Marshals and police flown in from Oklahoma City behind them, a fence went up, the sightlines went dark, and the repairs got scheduled, by the president’s own announcement, for after the Fourth of July, once the crowds and the cameras had gone home. You put a wall around the thing, and then you keep working where nobody can watch.
Why should this worry you even if you have no love for whoever holds the building right now? Because anything built at 1600 Pennsylvania Avenue can be wrapped in executive privilege and classified, which means it can go up without the appropriations hearings, the oversight votes, and the public record that any other federal facility of this scale would trigger. Congress never authorized a supercomputer under the ballroom. Congress was never asked. And infrastructure like that outlasts the administration that pours it. It becomes a permanent layer of how the executive branch runs, installed once and inherited by everyone who comes after, chosen by no one you voted for.
In the past I would have been happy to click on socialsecurity.gov. I’ve checked my account in the past so I could see my expected benefits. But now…eh…um…I don’t feel like I can trust government agencies anymore.
Am I being paranoid?
I traced overlapping investments and financial relationships across media, technology, surveillance, political spending, government contracting and sovereign capital.
What emerged wasn’t evidence of coordination, and I don’t claim that. It was a pattern of concentrated capital and access repeatedly crossing institutions that play a role in democratic life.
I’m the author, and I’d be interested in how others here view that concentration through the lens of democracy.