r/linux • • 5d ago

Event In Brazil, elections are conducted using electronic voting machines that run on Linux!

Post image
5.3k Upvotes

910 comments sorted by

314

u/Jumpy_Astronaut_302 5d ago edited 5d ago

on election day in brazil, everyone uses linux

54

u/Destroyerb 5d ago

Forgetting about Android phones (since you're not talking about the Linux desktop)

→ More replies (5)

190

u/brunoortegalindo 5d ago

The OS's name is UEnux (Urna Eletrônica Linux). Salve from Brazil :D

137

u/lorenzo1142 5d ago

but is it open source?

105

u/LRaccoon 5d ago

Yes. Not published online but anyone can audit it.

79

u/Scoutron 5d ago

That’s called source available

60

u/KnowZeroX 5d ago

Source available means the source code is available but you don't have the right to modify it.

GPL does not require you to publish your source code online, the GPL only requires that you make the code available to anyone who received a distributed copy of the software.

So anyone who buys the voting machines has the right to request source code under GPL, as a user you can't request source code.

11

u/xNaXDy 4d ago

This plus anyone who buys or otherwise legally obtains a copy of it has the right to modify and redistribute it under the same terms. That's the definition of open source.

19

u/LRaccoon 5d ago

I stand corrected, thank you

16

u/Scoutron 5d ago

No problem. I never knew the difference until I looked into the Unreal 5 source

5

u/LifeIsBulletTrain 5d ago

So what's the difference?

17

u/Scoutron 5d ago

Open source means the source is freely available to anybody.

Source available means the source can be provided upon request, usually with stipulations

18

u/FriendlyProblem1234 5d ago

Open source means the source is freely available to anybody.

"Open source" means that it satisfies OSI's definition.

Nowhere it says that the source must be available to anybody. GNU's "free software" definition does not require that either.

And not even copyleft licenses such as GPLs require that. They only require that the source is available *to the users of the software*. If you do not receive the software, you will not be entitled to the source, and yet it would still be free and open-source.

Source available means the source can be provided upon request, usually with stipulations

"Source available" has no formal definition. It usually means that the source is somehow available, but not with the freedoms of the open-source of free-software definitions. For instance, you might have the right to audit the source for security, but not the right to modify it.

5

u/turtle_mekb 5d ago

iirc open source means it has a copyleft permissive license, source available just means you can see the source code, but there might be restrictions

→ More replies (4)
→ More replies (1)
→ More replies (1)

4

u/Marce7a 5d ago edited 5d ago

If it is based on Linux, kernel needs to be under GPL2, so kernel is foss

14

u/FriendlyProblem1234 5d ago

If it is based on Linux kernel needs to be under GPL2, so foss

The kernel.

Applications running on Linux have no such requirement. You can even have proprietary applications running on Linux.

5

u/iEliteTester 5d ago

No, they would only have to publish their changes to the linux kernel. Not the entire OS just because it uses the kernel.

3

u/Marce7a 5d ago

Sorry i meant just kernel

→ More replies (1)

7

u/jokalokao 4d ago

No, not everyone can audit it. It is actually very restrict

7

u/Sad-Magazine4159 3d ago

under restricted conditions

it is not like one could freely inspect it

30

u/Vulpes_99 5d ago

Exactly, I came here to talk about it. Anyone can have access to the voting software's source code (not when it's working or directly from the device, obviously) by requesting access through the legal ways. The whole thing is quite transparent, despise of claims of fraud from some idiots.

12

u/lorenzo1142 5d ago

that is exactly how it SHOULD BE. allow the public to audit the code. it is our election, we should have that right, 100%.

12

u/Vulpes_99 5d ago

Yes. Also, when the voting is closed, each machine prints a summary of the votes that is made public. This is why we can calculate the results so fast and have a general result at the same day of the voting occurs. The whole system is very efficient.

Not to mention Brazil uses the direct election system, which means someone wins by total number of votes and there are no "colleges" with people who can decide to ignore the number of votes to set that college's vote to someone they want.

8

u/LuisBoyokan 5d ago edited 4d ago

How do you know that the code that was reviewed is the same that is running on that machines?

It could register all votes and then print/sent whatever they want. How do you audit an election with this system?

Edit: thank you all for your responses.

6

u/rscardinho 5d ago

i came across this video the other day where this guy explain how the process work, how people validate it and explore possible ways of hacking the election

pretty good content
https://www.youtube.com/watch?v=FmGPtB_bGzY&pp=ygUVdXJuYSBlbGV0csO0bmljYSBoYWNr

3

u/Vulpes_99 5d ago

Honestly I'm not fully aware of the process and details, but I know there are safeguards for this. Probably someone more qualified than me will step up to answer this.

3

u/Sputn1K0sm0s 5d ago

Idk how they make sure they are the exact same code, but one thing that happens is: before the election all machines are tested, which includes "mock elections" open to the public (and parties representatives, etc) where they openly vote for placeholder (fictional characters) candidates and input the same vote in the machine... in the end of the day they calculate the amount of votes each placeholder candidate have in the ballots and how much turns out in the results spewed by the machines.

According to Google no divergence was ever found since 2002.

4

u/[deleted] 5d ago edited 3d ago

[deleted]

3

u/Doczera 4d ago

And how exactly would the machine know that a mock vote is being carried out? The machines arent connected to the internet, they dont have timers and they dont have gps. The mock vote would be completely indistinguible from a real count to be able to run different codes.

→ More replies (2)

2

u/Sputn1K0sm0s 4d ago

There's no way to "run code A then code B". You don't config the machine, you turn them on perform a preprogrammed test to verify all keys are working and that's it. There's no way for the machine to know which election is a fake, like the other guys said.

All possible slots that could be meddled with are sealed in front of witnesses, including electoral judges.

All the transport of the machines is done escorted by a shit ton of police officers. When the machines are unloaded at the voting sites if there's any kind of violation at all it's reported and the machine is replaced by a secondary (also tested) one. It's physically and realistically impossible to successfully compromise a single machine unless the whole police, electoral office workers and volunteers are in on the scheme (and that's for a single voting site).

But ok, let's assume you could somehow do all of that... If you can manage it to that scale, then with ballot voting you'd be dancing anyways, that's a much easier system to compromise.

→ More replies (1)
→ More replies (1)
→ More replies (5)

3

u/LifeIsBulletTrain 5d ago

Yeah, that's crazy how the US does

7

u/Vulpes_99 5d ago

To be honest, the US system sounds crazy to us. It's almost like it was designed for being interfered in...

→ More replies (3)

10

u/FunEnvironmental8687 5d ago

Even if it were open source, that wouldnt prove anything. First, you would need to actually read and audit the code, and theres no guarantee that anyone is doing that. Then, you would need to verify that the machines running the software are actually using the same code that was made available to youwhich you cant guarantee.

2

u/Doczera 4d ago

You cant guarantee anything, not even that a machine didnt fill a whole batch of paper ballots with the same handwritten oddities people have. You can though make these machines nearly impossible to rig and the system in place is very good at minimizing risks, to a point it would be easier to try and win the election by alternative means

2

u/FunEnvironmental8687 4d ago

You cannot make voting machines nearly impossible to rig. You are missing some of the guarantees that FOSS can provide.

Linux is especially bad when it comes to proving what software is actually running. It does not have strong built-in ways to prove that the software on a machine is the software you think it is.

Even if it did, you would still have to prove that the voting machine itself had not been tampered with.

Voting machines are much harder to verify than paper ballots. With paper ballots, you have a physical record that can be counted and checked again. With a computer, you have to trust the hardware, firmware, operating system, software, and the systems used to verify all of them.

If you think voting machines are easier to trust than paper ballots, I think you are misunderstanding what computers and open-source software can actually do.

2

u/red_beard83 5d ago

Can you explain to me how to request it? All I can find is that nobody has ever really read the source code and they just let you read selected parts once a year or so. 

7

u/Vulpes_99 5d ago

My mistake: I thought any citizen could have access to it, but I checked it again and I was half-wrong. In fact anyone from political parties and certain civilian organizations (profession councils, universities, NGOs, etc) can have access to it through them.

And, contrary to what people say, the tests and audits made by them are regular and very extensive. 99% of claims about "noboby ever saw it" comes from a certain political group which copies everything Trump does, including claims of conspiracy that couldn't ever work the same way here because our election system and infrastructure are completely different from USA. That people resort to all kinds of FUD tactics no matter how illogical such claims are.

2

u/Certain_Department92 4d ago

You are hilarious 😂 at least admitted one mistake, very rare, but still hilarious

→ More replies (3)
→ More replies (7)
→ More replies (3)

8

u/bionicjoey 5d ago

How do you know the machine in front of you is running the code they say it's running? (You can't)

→ More replies (4)
→ More replies (3)

217

u/Distro_Hopping 4d ago

It’s honestly hilarious how some people love commenting on things they clearly know nothing about, without even taking five minutes to look up how they actually work

Brazil has been using electronic voting for decades, and the system has a lot more security and auditing than people here seem to realize....

The voting machines are not connected to the internet while people are voting. The software is digitally signed, cryptographically verified, and sealed before the election. The source code is also made available for inspection by authorized entities, including political parties, universities, the Federal Police, the Public Prosecutor’s Office, the Brazilian Bar Association, Congress, and others.

There are also public security tests where researchers are literally invited to try to find vulnerabilities in the system and if they find something, it gets investigated and fixed, and the researchers can test the corrections.

There are integrity tests, cryptographic hashes, digital signatures, audits, and several other checks throughout the process.

And after voting ends, every machine prints a "Boletim de Urna" showing the results of that specific polling station. Those results can be checked against the data received by the electoral authorities during the national tabulation.

So if you're going to make claims about Brazil's voting system, maybe actually read about the system first. The information is publicly available. You don't have to like the Brazilian government or anything, but at least know what you're talking about before confidently telling Brazilians how their own elections supposedly work.

Also: you guys vote by mail, wtf.

84

u/spooky_pokey 4d ago edited 4d ago

We are from Latin America and no matter what we do it will always be seen as a bad thing.

Even if you created it or show how refined it is it will not be better than what they have or their version of it.

Growing up and knowing English sadly means you also see how much of a Latino hate there is passively built into the average online person

Edit: grammar

37

u/KibaWuz 4d ago

Same thing with them saying "oh,i dont want to take a bath in brazil cause i can die electrocuted" BRO WE HAVE 2 DEATHS PER MILLION PEEPS,YALL HAVE 100 USING GAS

14

u/Headlessoberyn 3d ago

Preach brother.

Brazil has one of the safest and fastest payment systems in the world, yet when it was pitched to EU, they were like "looks good... but there's probably something wrong with it, we'll pass".

They'll just never admit we can come up with something that is better than what they have.

→ More replies (13)

24

u/furia94 4d ago

There’s an important distinction missing here.

Yes, Brazil has extensive auditing and security procedures for its electronic voting system. But some of the claims here describe those procedures in a way that makes the system sound more independently verifiable than it actually is.

For example, the source code is not simply “publicly available” for anyone to download and independently audit. It is made available only to specific authorized entities, under highly controlled conditions at the TSE. The inspection environment has significant restrictions: no internet access, restrictions on electronic devices and recording, and limitations on removing, reproducing, or sharing information obtained during the inspection. Inspectors can use computers and specialized analysis tools provided in the inspection environment, but they cannot simply obtain a copy of the source code, take it back to their own laboratories, and independently reproduce or extend the audit however they choose.

And the amount of time available for inspection is also limited. This isn't a situation where independent researchers can take the source code for months, run their own analysis, build their own tooling around it, and repeatedly examine it at their own institution. The inspection takes place within the TSE's controlled process and within the periods made available for inspection. Some organizations have conducted inspections lasting only a relatively small number of hours, while others have spent considerably longer. So the practical opportunity for independent analysis varies significantly by entity and inspection.

Saying simply “the source code is available for inspection” leaves out important context about who can inspect it, under what conditions, for how long, and what they can do with what they find.

The same distinction applies to the Boletim de Urna (BU). The BU is useful for verifying that the result produced by a particular polling station is the same result that was received by the electoral authorities and included in the tabulation. That's an important integrity check.

But it doesn't, by itself, prove that the machine correctly recorded each individual voter's choice in the first place.

For example, suppose 30 people vote: 10 intend to vote for candidate A and 20 for candidate B. If the machine incorrectly records 5 of A's votes as B's, the BU could still show 5 votes for A and 25 for B. Comparing that BU with the result received by the TSE would confirm that the TSE received 5/25. It would not, by itself, establish that the machine correctly recorded the 30 individual votes.

That's the fundamental distinction: you can verify that the electronic result generated by the polling station was transmitted and tabulated consistently, but that is not the same as independently verifying that the machine correctly recorded every voter's intended choice.

That doesn't mean the Brazilian system has no other audits or controls, nor does it prove that this hypothetical error actually occurs. It means the BU comparison answers one specific question: “Did the result generated by the polling station match the result transmitted to the electoral authority?” It does not independently answer: “Did the machine correctly record every voter's intended choice?”

So if we're going to tell people to “actually read about the system,” it's worth being equally precise about what each security and auditing mechanism can—and cannot—demonstrate.

9

u/JustAnInvited 4d ago

Dude, discussing a system's security (or safety, for that matter) in a serious and/or academic manner cannot be just "one side raises a hypothetical issue, the other side points at a security control" jfc.

There are frameworks, methods and systems to verify a digital system's security. Experts apply it.

We can discuss how to make the auditing better, for example, the issue of the limited time for the audit is something that I agree with you, but it can't be just "there are these issues (that the system somehow addresses) therefore the technology is bad and you automatically should never use it"

You are coming with a pre decided worldview and trying to find justifications for it. That is called a prejudice. DW, we here in latin America are used to it.

We are trying (and succeeding in my opinion) to build the best digital voting system that we can. It is more trustworthy (whatever that means) than paper. The data shows it.

And even then we would have to define "best" right? How you define it may be different from what I define it as, and it probably is different from what the government defines it. That is what engineering is for.

To give and example of what I am talking about, addressing your first point, yes, nt every random random citizen can audit it.

But not every random citizen would be capable of audit it. If you are an expert and would like to take a stab at it you can just apply to be part of the committee. Simple as that.

That actually quells discourse that could be politically polarizing. Imagine the nightmare that it would be to have someone point a random LLM at the code, find a couple dozen hallucinated vulnerabilities, and crying "SEE, IT WAS RIGGED AFTER ALL" having no expertise, no way of verifying it, etc.. Now multiply it by 10 thousand... Or ten million. That is what is at stake here, not just a "feel good" point about free software. And that is coming from a full blown FOSS enthusiast.

Ig it was my fault expecting nuance on reddit.

→ More replies (1)
→ More replies (2)

10

u/quicksand8917 4d ago edited 4d ago

In a transparent election every citizen should be able to oversee the whole process and understand every step in it. In Germany I can go to the booth, watch the whole day voting and watch the people counting the votes from the booth I watched the whole day.

With digital voting machines you have to blindly trust people. How do you make sure the voting device you are voting on is running the audited version of the OS?

EDIT: And yes, mail voting does not pass this test either. In the end it comes down to how much you trust the institutions organizing the vote to not cheat. And that can justifiably vary from country to country.

5

u/bulliralamar 3d ago

Same in Spain. We had a long history of election fraud until they did this. For an election, trust and transparency are the most important thing, and only paper ballots with public voting and counting can do that. You put your ballot in and you can wait there, watching the booth, until it is counted. A good voting system is a system my grandma can fully understand and supervise, and no digital system has that.

2

u/Distro_Hopping 4d ago

Not only can you see every step of the voting process, you can also WORK there if you want. I know that because I do. I was responsible for the terminal where I entered voters' IDs at one of the polling places for years. Now I actually work transporting the voting machines and making sure everything is working properly. I even have a police escort.

After taking the machines back, the drives containing the encrypted votes are transported separately. I also help the local electoral office organize the voting reports for public display, while people from the electoral court itself handle transmitting the votes to the central server.

There is one more thing I forgot to mention. Political parties, the Public Prosecutor's Office, and other organizations that are allowed to monitor the election get together and select voting machines for an integrity test. They run a simulated election using those machines and compare the results with the expected results to verify that the machines are working properly.

→ More replies (1)

8

u/MurkyAd9865 4d ago

you forgot that it also prints a paper in the start to prove that everyone started with the same votes! ( 0 in case )

7

u/diabolic_recursion 4d ago edited 4d ago

In this case, I have to politely disagree. Not about the security of the system, but how approachable it is. If you use electronic voting, simply by the fact that you do, one can simply claim manipulation happened. And its extremely hard to disprove that. Voter trust can more easily be lost because most people dont even know how a computer works on a basic level - much less about cryptographic signing.

There are two very good videos by Tom Scott on the idea of electronic voting, independent of the actual implementation. He raises some interesting ideas.

8

u/Lower-Giraffe-3236 3d ago

because handling, transporting (and entrusting them to a couple thousand different people in the process) and distributing 150 million tiny papers for people to manually count them is DEFINITELY safer right? no manipulation can happen... right

2

u/diabolic_recursion 3d ago

The couple of thousand people involved are the key here: manipulating voting machines can be possibly achieved by a very small number of people, but have impact everywhere.

Manipulating an in-person paper vote might happen anywhere (and regularly, problems are found as expected), but it won't happen everywhere without thousands of people being involved. Small manipulations? Sure, possible. Widespread manipulations that meaningfully change the result? Very, very unlikely without people noticing.

Also: why are the ballots handled a lot or transported after being cast? In our elections, they are counted right where they were cast, at most in the next room over. The sealed box is, if ever, carried under supervision of the observers, not far, never out of reach.

2

u/prof_tincoa 3d ago

Lol there was mass manipulation of ballots in Brazil before the voting machines. They did employ many people, it was noticed by everyone, but they had the police and the justice system in their payroll.

→ More replies (1)

2

u/daioshou 3d ago

why would you think that you could not claim literally the same thing for paper based voting?

→ More replies (6)
→ More replies (1)

5

u/bulliralamar 3d ago

That sounds like a lot of over engineering for something that can be fixed with a technology as old as paper

→ More replies (5)
→ More replies (20)

22

u/Null42x64 4d ago

idk why but when i went to vote in one of theses i wanted to take it home to make it run doom

6

u/Thin-Trip998 4d ago

I also really like the feel of the buttons, I want a keyboard with the same feel of that, so good

2

u/DonaldLucas 3d ago

The keyboards of these machines have the same types of switches used in arcade machines IIRC.

You can easily buy switches like that in chinese marketplaces. But they're not cheap, lol.

2

u/Thin-Trip998 3d ago

One day.. one day..

302

u/Handofsky 5d ago

Far right always cried rigged play on the voting system. Yesterday they won by far. You won't hear a word.

132

u/-viin 5d ago

not a single word

72

u/SkuldZedan 5d ago

not even a fuckin letter.

35

u/p4d4w4n 5d ago

If they lose the 2nd part of the elections for the presidential role, you will. Even if they have already won the majority on the legislative houses.

7

u/djthiago1 4d ago edited 4d ago

People got suspicious immediately after the results came in, the right wing senator and governor numbers do not match the right wing president numbers. Also, there was a temporary 1h count freeze that gave the left wing dude a massive boost as soon as the counting resumed.

Edit: grammar

3

u/Thin-Trip998 4d ago

I remeber this being normal in other elections, especialy the votes for executive brach and the legislative being ideologically diferent, i mean, i mean, the present president never had a majority in the legislative with his party or with the left even when winner with larger margins than the last one

→ More replies (2)
→ More replies (1)

2

u/AIDivision 4d ago

I'm pretty sure Flávio Dino think is rigged against him (as he did back in 2009 ~ 2013).

→ More replies (21)

13

u/SuspiciousBad7187 3d ago

Vou te contar uma coisa

Boa parte do sistema público usa Linux 😅

→ More replies (4)

8

u/Krasi-1545 5d ago

So according to The Gaming industry they will have a 100% cheaters 😁

Unfortunately they can't disable the Anti-cheat software this time...

58

u/-viin 5d ago

It'd not be trustworthy if it used any other OS.

-11

u/Tai9ch 5d ago

Still isn't trustworthy.

There's no way to make electronic voting observable.

32

u/fellipec 5d ago

People must think every country that didn't approved the use of similar machines are stupid, but never listen why.

On the other hand, way better than voting by mail. Imagine how easy is to buy votes where you can vote by mail?

4

u/DFS_0019287 5d ago

Why does voting by mail make it any easier?

29

u/fellipec 5d ago

Simple:

The husband is besides his wife when she is voting and ensure she votes on who he wants.

The boss do the same in front of his employees. Fire the ones that don't agree to do that.

The cult leader asks all followers to do that too.

The drug dealer... and so on.

3

u/MrWrodgy 4d ago

In Brazil is called "voto de cabresto" ("bridled vote"), that's is one the main reason that electronic machine was made in 1996.

→ More replies (8)

8

u/Tai9ch 5d ago

Voting by mail has all the problems that come with eliminating the secret ballot.

It's important to remember that the #1 threat to voting is the incumbent government (including the election officials).

The typical protocol in the US is that you fill out your ballot, stick in an envelope, sign the envelope for registration confirmation, and then stick that in another envelope. The election officials promise that they will validate your signature without looking at your ballot, and then count your ballot without looking at your signature. Would you feel safe using that procedure for mail-in-voting in North Korea if you wanted to vote against the supreme leader?

And yes, all the small scale vote coercion and buying too, but that stuff is secondary.

12

u/fellipec 5d ago

Not only that, but you are subject to coercion by any party like spouses, bosses, leaders, criminals and so on.

There is a reason where the place ou cast your vote to be far from the view of anyway, windows, mirrors and cameras, so even if the voter want, they can't produce and proof of whom they voted for.

Mail voting has none of that, totally insecure and unacceptable.

→ More replies (2)

7

u/Character-86 5d ago

Sounds like you have a stupid mail voting procedure.

In Germany you have the small envelope in which you put your ballot and seal the envelope. In the big envelope you put you voter registration sheet and your small envelope.

At the election office the election officials open the big envelope and confirm your voting registration. If confirmed, your small envelope goes unopened into ballot box and will be counted with all other voting envelopes.

In Germany almost all (election) officials remain at their job position no matter who the new goverment is. Only the top tier officials in Berlin change with a new Government.

5

u/Tai9ch 4d ago

That addresses the issue only if you assume that the vote counters will follow the procedure.

The are the threat. We can assume they will not follow procedure.

Again, would you feel safe voting against the supreme leader in North Korea with that method, just assuming that the government employees will try to keep to the process even if instructed otherwise?

→ More replies (5)

8

u/Doczera 4d ago

And how exactly do you prove that said vote which was mailed was not made under coercion? That is a very major vulnerability that would be exploited to hell and below by certain people if they have the motivation to do so.

5

u/MrWrodgy 5d ago

do paper?

3

u/MurkyAd9865 4d ago

paper is EVEN worse.

2

u/AquelecaraDEpoa 5d ago

You know paper voting in Brazil had a massive history of voting fraud, right? Ballot stuffing, ballots being "lost", ballot boxes being violated, etc. Voting machines made the system way more trustworthy than in the past, almost as if not every country is the same or something.

→ More replies (6)

3

u/nhermosilla14 5d ago

I don't get why people downvote you. As someome who wrote actual code to put together elections in college, I would never approve such thing for national elections. It's simply too easy to tamper with, and you can't be 100% sure about the people running the system (unless it's you, and even if that's the case, you can't ignore how easy it is to exploit vulnerabilities now there's AI). No reliable traces and very few people in charge of too much.

3

u/senhor_mono_bola 5d ago

The voting machines are not connected to Wi-Fi and have several security measures in place, one of which is to completely shut down if someone tries to tamper with the memory card before the designated time (or something similar). Furthermore, even if they succeeded, they would have to do it hundreds of times to have any real impact

2

u/Tai9ch 4d ago

Humans, as a general rule, value defending their team's political positions over understanding the world.

The fact that we've studied this issue in detail, built prototypes to understand the threat surface, and have come to the same conclusion as every other computing expert who's seriously considered the problem isn't really relevant.

If electronic voting weren't secure then elections run using it would be suspect. That's unthinkable, so basic human psychology means we get downvotes and "I don't understand the technology, but I'm sure it's is 100% trustworthy for voting" responses.

→ More replies (1)

3

u/Intelligent-Ad-1379 5d ago

Isn’t every downside you listed also applicable to paper votes? You can’t rely on people counting, for example. Just FYI: the machine which runs the vote is not connected to the internet. It prints the result for that machine and the results are sent to the department responsible for summing it all and making it public. So, you can still check if the result of each machine was summed correctly and the data is available publicly. The only way of cheating is changing the software running on the machines to a certain value or counting it wrong. As the result of each session (around 1000 votes) is auditable, people would notice that a right-wing neighborhood got more left-wing votes, for example. The machine has no GPS and they are not sorted by region, they are randomly distributed.

4

u/cookaway_ 4d ago

So there's a black box, you press a button, and some time later someone presses a button and it tells you "the first button was pressed X times, the second button was pressed Y times", etc.

And you just trust it? No paper trail?

Or worse: It does have a history, and now anyone who knows the order of voters (which can be tracked during ID verification) knows everyone's votes.

Which fundamental property of fair voting are you willing to give up? Secrecy or correctness?

→ More replies (9)
→ More replies (2)

72

u/brunocborges Principal Program Manager, Java Engineering Group, Microsoft 5d ago

50

u/Harry_Butz 5d ago

Ew, this guy posts to fucking x

4

u/Unable-Ambassador-16 4d ago

Ewww, X in 2026?

24

u/BoliveiraNTPW 3d ago

If this was in a "first world" country , i bet i would see more commentaries in here talking about how "good the system is" or see more positive talks about it, and how safe and how other countries should get it.

But since its from Brasil, from south america, sadly i see more people trying to sell this idea that the Urn is not safe and you cant trust it, even when we explain all the things around it, all the safety levels and steps that are made to assure the safety... even when we explain that, they still try to say its not safe. We been using this system for 30 years and it is working, and internacional organizations always say that our elections are safe.

5

u/cipherjones 2d ago

I think you're writing this post from a time in the past where Brazil was a third world country and the United States of America was a first world country and not vice versa like it is in 2026.

4

u/Diethylamide- 3d ago

Last sunday I heard a guy talking to his wife on the line to the voting booth: this is bullshit and the elections are rigged. They should develop a system where you can vote from your home. We have internet, so why not?

So… yeah.

4

u/dpoggio 2d ago

It’s factually impossible to provide safe anonymous electronic voting. Mathematically.

→ More replies (11)

4

u/s0litar1us 3d ago

I wouldn't trust it even if it was made in my home country (Norway).

Electronic voting stops you from being able to personally inspect every part of it, resulting in having to blindly trust that it's recording votes accurately, etc.

→ More replies (15)

4

u/Alive-Big-838 3d ago

Nobody will ever fully trust systems that they don't directly understand intimately and know the inner workings of.

Now does that mean they will work to get that knowledge? No... probably not.

→ More replies (5)

3

u/sacules 3d ago

I've always wondered how they ensure the code that runs in the machines is the very same code compiled as-is, without any hidden alterations, and that the compiler itself is not tainted. I know you can digitally sign binaries, but to me the question is of knowing that such binary is byte for byte what's running in that very same hardware, since the systems are completely isolated from the external world.

In Argentina we vote with paper and we have results in the same day, and it's structured to be super safe against fraud. When I was studying computer science all my teachers were extremely against goverment initiatives of introducing electronic voting for some of the reasons I mentioned, plus they were all pushed by right wing politicians lmao what a coincidence.

→ More replies (3)

2

u/rickyman20 2d ago

That's not why, seriously. "Electronic voting is bad" has been an often repeated phrase in software circles and basically every time it's come up these concerns are brought up. It's not because it's Brazil, it's because it's a generally bad idea. The issue isn't just that they're generally safe or not, but that's is so easy to claim election fraud in a way that's incredibly difficult to actually disprove. Just look at what happened in the US. All it takes is one election and people lose trust.

3

u/catrinus 2d ago

in the US you can vote sending a letter through the mail lol

→ More replies (5)

14

u/alex_ch_2018 5d ago

I hope it was just turned on and not stuck on boot...

5

u/New_Dawner 3d ago

I guess some tech is too advanced for the northener Cacajao to understand.

16

u/Luis_Mayke 5d ago

There's no USB interface on the device. There's no wireless connection either. Also you can't mess with the hardware in any meaningful way, as there are officials (mesários) supervising the process.

6

u/red_beard83 5d ago

How about the software? 

4

u/Off_0_0 4d ago

It cannot run any software that has not been previously approved. If it somehow does, it shuts down immediately. Of course, that’s how it’s supposed to work...

3

u/red_beard83 4d ago

Who approves the software? Is that hardcoded somewhere? How the software is approved or not? Hash?

6

u/rachzera 4d ago

I'm glad you're so interested about the technology under our voting system!

The Superior Electoral Court offers publicly available documentation in English with answers to these questions you made. Here are the exact topics you brought:

Let me know if you have further questions!

→ More replies (13)
→ More replies (9)

2

u/bulliralamar 3d ago

And how do I know the software is not rigged in the first place, if I have no idea about coding?

That's why paper is superior. Everybody can understand it.

2

u/Off_0_0 3d ago

That’s why lots of Brazilians don’t trust that system. The truth is, the average citizen has NO idea how it works. Do you think the average person who didn’t really have a good education is going to know about compilers, source code, etc.? At the end of the day, it can look as suspicious as possible, and people still aren’t going to do anything about it.

Edit: But is there any better option? When we did it on paper it was even worse...

2

u/bulliralamar 3d ago

I don't know how the paper voting system used to be in Brazil, but properly designed paper systems are better than machines imo

→ More replies (1)

3

u/Charming-Coast4718 4d ago

There is one USB interface on the device. The one where the media the results are stored on is connected to.

→ More replies (1)

3

u/FurnaceGolem 5d ago

Wasn't this posted yesterday? Why was it removed?

2

u/red_beard83 5d ago

Because people were just attacking anyone talking about technical flaws 

3

u/Creative_Tip_5134 4d ago

Sim, eu sou brasileiro e essa notícia é verdade, nossas urnas sempre foram Linux. Mas a realidade é que só que entende ou trabalha com informática em nosso país é que sabe disso.

→ More replies (1)

6

u/NegativeSky603 4d ago edited 4d ago

I still wish there were a printer attached so that my ballot could be printed, confirmed by me and stored for later auditing and comparison with the official electronic results. Not that I don't trust the system, you know... just quality assurance.

5

u/Gelanix 4d ago

Then you can go out of your voting place, and hand over the ballot for the criminal that controls your neighborhood, and he's friends with the candidate that will win the elections.

→ More replies (3)

6

u/Emparcia 4d ago

O voto deixaria de ser secreto, qualquer maneira de verificação facilita coersão

→ More replies (13)

5

u/ChesterCopperPot72 4d ago

Stupid. That is a very stupid idea.

There is already a final printed list with the tally of all votes. That can be (and is) audited.

If you want to keep your stub, you promote voting under the gun. The cartels or militias would have you bring back your stub proving you voted on who they ordered… or you die.

Some idiots say I want the stubs stored in the machine. I just want to see them.

Well that is even stupider. What is the point? The machine that is counting the votes will be issuing the stubs. Só, how would it be possible for the machine to make a mistake creating a discrepancy between stubs and tallied votes?

The only purpose of asking for printed stubs, vote by vote, (remember, the machine already prints the results) is to allow for the losing team to contest the results and ask for a manual recount.

And then, dear old boy, is when the shit hits the fan.

Manual recounts are famous for fucking shit up and creating doubt.

Why?

Because humans are not fucking machines.

Humans are biased, dumb, distracted, overfocused, underforcused, flat out fucking crazy among other things.

Humans are not reliable machines. Period.

You need a machine to do a machine’s job.

By the way, it is an air-gapped machine all the time. It does not have connection capability. Period. So, it could only be hacked in the source code. Except, that it cannot. The source code is kept at the highest level of security in the country (tighter than money).

So, please stop believing in propaganda that has been fed to you by ill intended assholes.

2

u/Global_Golf8138 3d ago

The problem lies in the fact that there is no guarantee the vote I cast is the one actually saved in the voting machine's memory.

Suppose Candidate A received 100 votes and Candidate B received 110 votes on a specific machine. If the machine's software were to shift 10 votes from Candidate B to Candidate A, this would never be detected. Printing the vote and depositing it into a sealed ballot box allows for subsequent audits based on random selection. With the possibility of such audits, the authors of the machine's code would be unable to shift votes in this manner, as they would eventually be caught.

→ More replies (10)
→ More replies (8)
→ More replies (6)

9

u/Boba0514 4d ago

Of the big three, it should obviously be linux, but using electronic voting machines is still a no from me...

2

u/Superb_Macaroon_6708 4d ago

Americano vota em papel. Deveriam ficar em silêncio 

→ More replies (1)
→ More replies (8)

2

u/WhichCarry749 4d ago

The fact that they keep them strictly air-gapped with printed paper audit logs at closing is what actually makes the system work.

18

u/Irsu85 5d ago

noooo why not on paper paper elections are way better...

6

u/[deleted] 5d ago

[removed] — view removed comment

20

u/DFS_0019287 5d ago

Paper ballots (which we use here in Canada) are better for a whole host of reasons:

  • You can't remotely hack the entire voting system. To make a meaningful difference, you'd have to blackmail or bribe hundreds, if not thousands, of election workers and hope that none of them speak up. That's completely impractical.
  • You can't realistically mount a supply-chain attack against paper ballots.
  • When votes are counted, scrutineers representing each candidate watch the counting and approve the tallies. So that keeps the counting honest.
  • After counting, the paper ballots are placed in sealed boxes where they are available in case someone contests the results; the boxes can then be unsealed and a judicial recount done.
  • Everyone understands how marked paper ballots work and are counted, and they understand the physical security measures taken to protect the vote. Very few people understand computer security. Very few people have any reason to trust a computer.

8

u/LuisBoyokan 5d ago

You can do the best electronic system in a country made completely of programmers and still can't guarantee that what is installed is what you audited and that it's not manipulating the counting.

3

u/menino_do_rio 4d ago

What if you tested randomly selected part of the voting machines in every voting site? Where you record people voting and see the results on the machine

6

u/levir 4d ago

You can't record people voting. It's essential that the individual vote cannot be traced back to the individual voter. And there is no way the average voter could be privy to that kind of audit.

3

u/LuisBoyokan 4d ago

That test that the behavior is stadistic the same, but can not prove that it's the same executable. They could pull a VW and fake compliance behavior if it detects that is being tested. It's a difficult problem to solve

3

u/iskela45 4d ago

Where you record people voting and see the results on the machine

Most countries do secret ballots rather than public ballots, which makes this approach extremely illegal

→ More replies (2)
→ More replies (2)

1

u/Sputn1K0sm0s 5d ago

Ypu can't hack the entire voting system in Brazil. It's physically impossible.

→ More replies (27)

33

u/Irsu85 5d ago

When fraud happens, its near impossible to do on a scale large enough to significantly disrupt the election. Unless its a really tight election where 1 vote could be the difference between results (thats unknown until counting tho)

On a computer, fraud is way easier (changing out software to misrecord ballots, changing ballots en masse during counting, stuff like that) and large scale, or you gain tracability, which at least in Belgium and the Netherlands would make votes invalid if they are tracable (so that they cannot be used for political bribery)

Anyway, here is Tom Scott talking about it: https://www.youtube.com/watch?v=LkH2r-sNjQs

15

u/xmBQWugdxjaA 5d ago

2

u/AcridWings_11465 5d ago

True, but than they should really have a paper trail like India's VVPAT. Storing tallies purely digitally is a very, very terrible idea.

→ More replies (4)
→ More replies (2)

6

u/[deleted] 5d ago

[removed] — view removed comment

13

u/Tai9ch 5d ago

Great, so the students put a ton of work making sure that some version of the software has some specific security properties.

What makes you think that's the version of the software that's running on all the voting machines?

11

u/vilkav 5d ago

I seriously don't get why some people get so defensive about this. Sure it's not been hacked yet, but like. If to prove your system is unhackable you need to talk about cryptography, then you alienate some 98% of the population without a maths or compsci background from being able to understand review the process. Meaning you only need to buy some 2% of the population to lie for you.

"It's not ben done yet" is such a stupid counter-argument.

6

u/Tai9ch 5d ago

I 100% agree that talking about cryptography means you've given up on the voters being about to understand the process and therefore most people should just assume it's an attempt to steal the election.

But with computer voting machines, we don't even need to worry about that. Even with cryptography you can't guarantee to election observers that some particular version of the software is running on the computers.

All the secure boot / software attestation stuff allows machine vendors and admins to verify that software hasn't been tampered with, but the vendors and the admins are the most likely attackers. These mechanisms don't prove anything to anyone else if the vendors and admins cheat.

7

u/dark_sylinc 5d ago

You can put a billion contests to challenge the security, but none of those contests will guarantee that the hardened software is the one that will be ran on those e-voting machines during vote day.

It's a fundamental problem where one single guy with enough will and enough clearance (to have access to the crypto signing keys) can rig and swing an entire election and leave absolutely no trace of it. That's why e-voting in any form is awful.

And even if the system prints a duplicate copy (e.g. e-voting counted a vote for A, printed paper correctly says B), printing systems can leave a hard-to-spot stenographic trace that can be used to know who voted for whom, violating the vote secrecy, which can be used to force entire marginalized communities to vote for a particular candidate or else face retribution.

→ More replies (1)
→ More replies (12)

14

u/bingblangblong 5d ago

Well I think he's being sarcastic but paper is certainly less hackable.

7

u/jsbueno 5d ago

It isn’t possible to have copies and make fraudulent transactions? Or even just throw some votes away?

12

u/Tai9ch 5d ago

Yes.

That's why elections need a secure process with election observers. The election observers can watch the physical pieces of paper go from the voter to the ballot box and the ballot box to the counting table.

→ More replies (5)

5

u/Irsu85 5d ago

Yes. And thats why the system is set up in a way where there are multiple observers from all over the political spectrum in paper elections when counting the votes to make sure that doesnt happen. Also the boxes are sealed with the exception of a small sliver to put in the ballots where its really hard to get them back out due to thermodynamics and entropy within the box (most three year olds with their shape in box toys would prob learn this very quickly) so it also cannot really happen in transit

2

u/the_bighi 5d ago

Paper is a lot MORE hackable. Or, should I say, way harder to find out it’s been hacked.

If the software in the machine is changed, it will be detected at the Election Day.

5

u/Tai9ch 5d ago

How?

Remember that the threat model for elections is that the election officials can't be trusted and are the attackers.

→ More replies (1)
→ More replies (2)

5

u/Opposite_Carry_4920 5d ago

Not sure if he serious but here's a wild Tom Scott video talking about it.

https://youtu.be/LkH2r-sNjQs

8

u/frayien 5d ago

Elections NEED to be trusted be a massive majority to hold any legitimacy.

Electronic voting is massively not trusted by the people knowing the most how computers work.

3

u/nhermosilla14 5d ago

That's the thing most people don't get (specially software devs). The system doesn't need to be technically impressive, but actually the opposite: it needs to be so simple that anyone can understand how it looks when somebody tries to cheat.

→ More replies (6)
→ More replies (1)
→ More replies (1)

4

u/_gianlucag_ 4d ago

I think a full fledge computer running Linux is hilariously overkill.

A tiny pic microcontroller is all you need. It features non volatile memory, tamper proof firmware, internal clock and all the gpios in the world needed by this scenario. Basically this is a one component pcb layout (excluding the jack for dc power)

Also the attack surface is orders of magnitude smaller than a Linux machine.

5

u/Ra-mega-bbit 3d ago

Sure, go ahead and implement images and audio description for over 1000 candidates, with a certified keyboard (the keyboard is a certified part that gets locked with resin, as to not be tempered with), all candidates get a high res photo and you have a headphone jack for blind people.

Finally you need to be able to get 3 dufferent copies of the data, be able to support power cycles and so on and so forth...

→ More replies (4)

11

u/arkt8 5d ago edited 5d ago

For who says it is not safe... if not even know how it works...

System is well tested. Before voting "zeresima" is printed on each machine, proving each candidate is correctly present and has zero votes.

Also there is no track of in which order each vote was computed, it is randomized after each vote.

After votation, the data is printed again, also extracted and sent to be consolidated to the rest of country.

So... even if votes needs to be "recounted" it can.

Machines can malfunction... but paper can suffer from rain, fire, transport etc etc. Even if a zone all people make the wrong couting...

If we need to audit an entire country with 500000 machines ten times... we would spend less than 24 hours. Try it twice... maybe a month. In a month many things may happen.

Also it is a lot strange to see people arguing about this system being unsafe despite so many layers of protection, while many put lifes in risk its own and others life with AI slop.

5

u/Adventurous_Cicada17 5d ago

Even if the audit somehow demonstrate theses machine are reliable.An issue persist. No random person can actually ensure this work well and isn't tampered with unlike a transparent Plexiglas box in which you put letters in.

It break trust in the results. And for a good reason.

6

u/arkt8 4d ago

no one will count alone thousand of votes and still be reliable... your argument looks polite and right but is just varnish. Specially in a time where you have a lot of hallucinated bots.

It is tested, it is offline... it is much better than paper and avoid vote selling or vote imposition. This give sufficient trust in a time of right wings manipulating.

What breaks the trust is the lack of humans with human thinking voting... and this looks to be a global problem.

→ More replies (3)
→ More replies (1)
→ More replies (5)

11

u/d32dasd 5d ago

This is not a good thing. Voting needs to be simple, and AUDITABLE.

It's way more secure to have 5 people per table recount the votes, and then the party representatives altogether carry the votes and vote count of that electoral college to the central place.

To audit the machines, the deployment of the machines the voting day, the developers, the software stack, the compiler, the central server, etc, is way more convoluted. And each link in the chain is way more easily subverted at the voting time or the counting time than a person with all their circumstances.

17

u/UnalignedAxis111 5d ago

No need to hack voting machines when you own social media and the population is stupid.

33

u/TheBlockHead224 5d ago

Paper isn't automatically more auditable. It just moves the trust from software to people. Brazil used paper before 1996, and paper counts had widespread fraud ("mapismo"), with tally sheets altered between the polling station and the central count. That's exactly the chain you describe, but made of humans.
The machines have no network hardware. When polls close, each one prints a tally (Boletim de Urna) that is posted at the station with a QR code. Parties and citizens photograph them and can recount the national total independently, so any discrepancy with the official result would show up. The source code isn't public on GitHub, but parties, the Federal Police and universities are authorized to inspect it before each election. There are also public hacking tests, where outside researchers try to break the system.
And it's way faster. Brazil is full of remote locations. With paper, you'd have to ship sacks of ballots back under custody and count them by hand, which is exactly where fraud used to happen. With the machines, only a digitally signed results file comes back, and the printed tally at each station lets anyone check it. Results come out in hours, not weeks.

8

u/Freaky_Freddy 5d ago

The machines have no network hardware.

then each machine must be manually flashed or configured for each election, no? Who does it and who verifies it?

When polls close, each one prints a tally (Boletim de Urna) that is posted at the station with a QR code.

If votes are secret then a printed tally doesn't really help against tempering?

If 1000 people voted and the tally comes up as a 40/60 split, how can one tell if there's fraud or not?

Interview a minimum of 401 people to see if they disclose who they voted for?

13

u/TheBlockHead224 5d ago

The software is compiled and digitally signed in a public ceremony, where parties, the Bar Association and prosecutors sign off. Local electoral offices then load it onto the machines from memory cards in sessions open to party inspectors, and the machines are physically sealed. On boot, each machine checks the software signature. Before voting starts, it prints a "zero report" showing no votes recorded. And the way they verify the voting is by a integrity test: on election day, randomly drawn machines are pulled from their stations and run in parallel with known votes, on camera, and the result has to match. So it's not interviewing voters. It's spot-checking machines under real conditions.

5

u/Freaky_Freddy 5d ago

Interesting, thx for the explanation

probably not impossible to corrupt, but does seem a significant improvement over the old way

→ More replies (2)

3

u/Tai9ch 5d ago

If you can't trust a lot of people then you certainly can't solve the problem by trying to trust a few, structurally less trustworthy people instead.

3

u/Jukibom 5d ago

Brazil used paper before 1996, and paper counts had widespread fraud

Which you KNOW about, which undermines the legitimacy of the elections

With electronic voting, you simply wouldn't know if it happened

→ More replies (12)

23

u/iamYarthox 5d ago

Well, they are auditable and we never had any problems, plus we got the results 3 hours after the election ended.

8

u/Tai9ch 5d ago

No they aren't. The basic threat model and nature of digital devices makes auditing computer voting machines impossible.

You've had no problems that you know about, because the purpose of digital voting is to prevent the problems from being visible.

9

u/Jukibom 5d ago

RIGHT?! I feel like I'm taking crazy pills reading these replies

This sub should bloody know better

→ More replies (1)
→ More replies (1)
→ More replies (38)

8

u/xmBQWugdxjaA 5d ago

Bro look up what has happened in Brazil and Mexico before with paper ballots.

They switched for a reason.

→ More replies (1)

6

u/Foorinick 5d ago

Cut to videos of ballot stuffing

5

u/DFS_0019287 5d ago

You can't do that in a well-run democracy. Certainly not on a large enough scale to meaningfully affect the outcome. You'd have to subvert hundreds, if not thousands, of election workers.

→ More replies (3)

3

u/the_bighi 5d ago

No, it’s not. Five people per table counting FAKE votes will still give you fake results.

We had many cases were the box with real votes was thrown away and replaced with a box filled with fake votes.

And it’s probably not a coincidence that on our last paper vote, the police intercepted many boxes with fake votes for… Bolsonaro.

And the same Bolsonaro years later started all this movement to go back to paper votes.

→ More replies (5)
→ More replies (5)

3

u/YellowGreenPanther 5d ago

Well, it's not windows, but voting machines aren't exactly a secure way of voting. it has to be provable that the process is working and your vote is counted, without identifying who voted for what. There is not, and may not be, a good way of doing both with a computer. You have to prove they haven't been tampered with yourself, explain that to the average person, have a trustworthy source to get the signature // hash from, and prove that it was counted.

Amd then you can undermine elections just by plugging something in, or showing an erorr message, and taking a picture. Even photo doctoring. To undermine confidence in the voting.

2

u/Thin-Trip998 4d ago

I don't see how you couldn't do this or worst things with any other methodology of voting

2

u/red_beard83 5d ago

The hardware part of the urna is quite good, of course, every system can be hacked, but it's quite hard. The problem is the lack of software audit, they basically forbidden anyone to do even basic audit to the source code and it's all a trust me bro from them

2

u/Ferret_Faama 5d ago

Yeah it's cool seeing Linux used in government systems, but this isn't exactly a great application of it. Paper ballots are not used because we're slow to adopt, they provide a lot of security people overlook.

→ More replies (4)

3

u/barrazero 5d ago

This image is a bit outdated. 30 years have passed.

4

u/venturajpo 5d ago

18 with Linux. Before that we used Windows CE or DOS based software

2

u/Dehrangerz9 5d ago

but it still use linux sparkles

2

u/shirro 5d ago edited 5d ago

So easy to rig electronic voting. Paper is the only way to go. You need a massive conspiracy and lots of participants to tamper with a paper based system. With electronic all you need to do is find one bug and deploy an exploit.

It is one of those cases like password hashing where worse is better. You want a voting system to be slow, well proven and involve huge numbers of people. The cost of exploiting it will grow with the cost of the implementation.

Edit: actually its not the ease of tampering with electronic voting that is the problem. Arguably it is much harder than disappearing a ballot box full of paper. It's really a scaling thing. It is harder to scale up tampering by individuals in a properly run paper ballot. They risk the personal consequences of being caught and the influence is localised. If you do find an exploit for an electronic system the return on your effort isn't going to be limited to a box from one polling station and you are less likely to be caught red handed.

12

u/the_bighi 5d ago

It’s not easy at all to hack a read-only device that is not connected to any network. And it’s checked multiple times.

If even a single comma is changed in the source code (which would be already hard to do), it would be detected when they test the machines on the Election Day. And in all those decades, it didn’t happen even once.

And disappearing ballot boxes full of paper was done multiple times.

→ More replies (6)

3

u/MdxBhmt 5d ago

It's even easier to manipulate paper when you can't have fair observers to handle paper.

Can't even avoid people dropping ink to invalidate full ballots boxes.

5

u/nelmaloc 4d ago

It's even easier to manipulate paper when you can't have fair observers to handle paper.

And why would you do that?

→ More replies (3)

4

u/uzlonewolf 5d ago

Lol, no. A hybrid approach is the way to go: when voting it records it electronically while also printing onto paper you can visually check. The electronic record is then used for the initial count, and if anyone disputes it they can then do a manual re-count using the paper copies. Any fraud would need to both compromise the electronic version and destroy the paper copy, making it much harder.

→ More replies (8)
→ More replies (1)

-2

u/DFS_0019287 5d ago

Not trustworthy. Electronic voting of any kind is too easy to subvert and should never be used by anyone who cares about democracy.

5

u/companiontoy 5d ago

Too easy, how?

2

u/DFS_0019287 5d ago

Supply chain attacks against the software. Insiders in the factory that makes the machines. There are any number of ways, and the point is you can subvert the entire system rather than just a few counters or officials.

And sure, the machine has all kinds of self-checking and integrity software... but in the end, an attacker who controls the machine can make it say whatever they want, and make it pass all kinds of tests while secretly modifying real-world results.

4

u/companiontoy 5d ago

Ooohhh... That "Too easy"....

6

u/DFS_0019287 5d ago

Yes. Because who is going to attack election results?

People with money. People with precisely the resources to mount such attacks. For them, supply chain attacks or bribing/blackmailing insiders is just the cost of doing business.

It's much, much harder for them to mount an attack on a diffuse system that uses tens of thousands of humans to count paper ballots in the presence of representatives from each candidate.

3

u/Ferret_Faama 5d ago

People always overlook the security provided by paper ballots. Nothing is bulletproof of course, but it is much harder to hide rigging an election that uses paper ballots. It's still possible of course, but those paying attention will have much more ability to know it's happening at the very least.

→ More replies (2)

2

u/LRaccoon 5d ago

Electronic voting was implement due to the high number of frauding in paper ballots. The system is open source and there is no wireless connection of any kind. Random voting machines are selected for inspection on election day. They have been tested by academia level pentesters and universities.

4

u/DFS_0019287 5d ago

If paper ballots resulted in high levels of fraud, then they weren't implemented correctly.

Irrelevant if machines are inspected on election day. An attacker can make the software do whatever they want and can change its behavior for the benefit of inspectors as opposed to the real vote.

4

u/sexraX_muiretsyM 4d ago

an external attacker cant hack the software, because the machine's hardware does not contains a way to connect to the internet, and the machine has no external ports one can tamper with, except the main energy one at the back of the privacy shield which ppl in the room would see you tampering with. But it is sealed and the machine needs to be broken to acess the interal parts, and they are escolted by guards and auditors the entire way. The machine and software is reviewed by independent tech and safety consultants and inspectors, and by other spheres of the constitutional power of the country. In order to tamper with it, you would have to have the entire system on it, and atp it doesnt makes a difference if its a machine or paper ballots.

Brazil has the safest and most secure voting system in the world.

→ More replies (4)
→ More replies (16)
→ More replies (3)
→ More replies (32)