What does an audit
actually prove?
Hardware, software, people and processes: what evidence supports evaluating election security from beginning to end?
Research and documentary analysis · ALAS TECHNOLOGY
A technical guide to hardware, software and the Brazilian electoral process, with illustrations, published studies and accessible sources. A nonpartisan analysis of facts and limitations, regardless of the government, candidates or outcome.
Hardware, software, people and processes: what evidence supports evaluating election security from beginning to end?
A complete assessment follows equipment, code, data, people and evidence through every transition.
TPS 2025 testing lasted five days. Preparatory inspection and institutional oversight have separate access windows.
TPS equipment is supplied by the organizer. Teams cannot freely select any unit from the deployed fleet for examination.
Oversight entities participate in selection, but tests do not follow every unit from preparation through the post-election period.
Teams produced technical findings. Their meaning depends on the target, conditions and version tested.
Models announced for 2026. Hardware, firmware and dependencies require explicit coverage by version.
Physical access, removable media, firmware and supply chains are attack surfaces. Feasibility depends on concrete conditions.
In the illustrated proposal, voters inspect the record through a window without handling it. It drops into a sealed compartment.
Broader access allows independent public and private teams to investigate beyond event-specific windows.
Hardware, software, people and processes: what evidence supports evaluating election security from beginning to end?
Illustration data: YOUR VOTE; 1; 2; 3; 4; 5; 6; 7; 8; 9; 0; BLANK; CORRECT; CONFIRM; DESIGN; Code + hardware; INSTALLATION; Signatures + custody; OUTCOME; Records + recount.
An ALAS TECHNOLOGY study: the same technical standards, regardless of the government, candidate or outcome.
This analysis is nonpartisan and unaffiliated with any government, party or candidate. Its criteria are independent of the election outcome.
The subject is the complete chain of trust. Independent research informs architectural assessment; rules help compare the available oversight powers with the tests needed.
Technical reading
This analysis is nonpartisan and unaffiliated with any government, party or candidate. Its criteria are independent of the election outcome.
The subject is the complete chain of trust. Independent research informs architectural assessment; rules help compare the available oversight powers with the tests needed.
Full references and caveats in the dossier below. Images identify sources by title.
ALAS TECHNOLOGY study / version 1.2
Documentary research and analysis by ALAS TECHNOLOGY, nonpartisan and unaffiliated with any government, party, candidate or electoral outcome. The focus is the entire ecosystem: hardware, software, people, operations and evidence. Independent research informs the security criteria; rules describe formal access. This is a documentary study, without direct inspection of machines or code.
The proposal is to release openly licensed code, history, dependencies and build instructions, alongside representative equipment for independent public and private teams. Supervised code access is not equivalent to an open project with continuous review.
Funding, documentation and effective access are needed to turn availability into coverage. Findings must be reproduced, fixed and retested; changes to electoral systems require versioning and change management.
Report ANT-2026-CM0TCREP attributes a Linux discovery to Claude, with human triage and a fix: CVE-2026-43074. The report dates its introduction to July 2025, so this example is not a decades-old flaw. Mozilla also confirms AI-assisted findings in Firefox. Separate reports concern older flaws in other projects; their age should not be attributed to the Linux case.
Evolving tools support periodic reassessment. They do not demonstrate a vulnerability in a particular voting machine without checking its version, configuration, access and exploitation conditions.
[35] [38] [39] [40]Permission does not prove effective access. Executing a test does not prove total coverage. Announcing a fix does not prove independent retesting. These are the criteria used in this dossier, applied to organizers, oversight bodies, suppliers and researchers. Political views or a source's prestige do not determine the validity of a finding.
| Information type | Use in this analysis | Verification needed |
|---|---|---|
| Rule or test notice | Identify formal permissions, restrictions and deadlines. | Minutes, approved and denied requests, access granted and execution reports. |
| Institutional statement | Record what the institution claims to have done. | Data, methods, versions, findings and technical documentation supporting the statement. |
| Research demonstrating an attack | Assess the property compromised under the published conditions. | Preconditions, target, version, materials, reproduction and comparison with the operational configuration. |
| Retest | Assess whether the known attack still works on the modified version. | Investigators' presence, test procedure, evidence, regression tests and variants. |
| Hypothesis or recommendation | Guide research and improvements. | Do not present it as a discovered flaw or an already implemented security measure. |
Access to equipment supplied by the organizer does not, by itself, establish independent selection from the operational fleet. Aranha and colleagues describe methodological restrictions and attacks that compromised security properties in the examined setting. Criticism of laboratory scope has a technical basis; its representativeness must be demonstrated. [2] [5]
Proposed independent assessment: define the eligible population, record exclusions, enable independent participation in selection, identify each unit and preserve its state before any test preparation. Document interventions, images and versions, personnel, transfers and access conditions. These are recommendations of this analysis, not procedures already verified as implemented.
When examining operational state, preparation that replaces software or deletes records may remove the very evidence sought. Reproducing an attack may require preparing a controlled environment. The report should state which objective was met and what was changed. A verifiable technical requirement is to track and limit interventions, rather than assume nobody previously touched the equipment.
Records generated by the same component may share the same fault. On a US AccuVote-TS, Feldman and colleagues demonstrated modifications with internally consistent records. This supports that threat class; it is not a finding in a Brazilian voting machine. [34] Software independence concerns the ability to detect changes to the outcome even when software fails. [13]
Limits of this review: the ten topics and the dossier were reviewed, with foundations rechecked against primary sources. ALAS TECHNOLOGY did not inspect equipment, reproduce attacks or verify execution at all precincts. Limits to documentary coverage remain identified. Publications alone cannot establish the complete operational reality.
The central criterion is the evidence produced, not an authority's declaration. Test rules state what may be tested. An engineering assessment asks which threats were examined, what conditions were reproduced and what conclusions the results support. Missing data in this dossier are marked as unverified, not as automatic evidence that a control is absent.
Feldman, Halderman and Felten analyzed the hardware, software and operation of a US AccuVote-TS. In the laboratory, they demonstrated attacks through physical access and media, with tampered records that remained mutually consistent. The study informs analysis of custody, propagation and record dependence; it did not examine Brazilian equipment. [34]
In Brazil, work by Aranha and colleagues provides evidence directly tied to the versions they tested. The 2017 account shows why keys, libraries and code loading must be assessed together. [5]
Research on reproducible builds examines reconstructing the same artifact from identified sources, instructions and environments. This makes part of the source-to-binary link verifiable. [35] [37]
The complete argument must also cover compilers, firmware, keys, installation and execution. Two identical builds do not prove program correctness; a signed image does not prove that its logic was sufficiently reviewed.
The scientific report Securing the Vote recommends assessing processes and outcomes, including registration, preparation, voting and publication, with audit data that enable reproduction and protect voters. It is a foreign methodological reference, not a measurement of Brazil. [36]
How to record each conclusion: target and version → threat → access obtained → method → reproduced result → fix → retest → limits to generalization. Useful categories: demonstrated, mitigated under test, threat hypothesis, not examined and insufficient data.
The matrix below is a proposed technical scope. It does not claim these procedures were performed in Brazil or that they are absent. Assessing implementation would require artifacts from every stage. There is no universal time frame derivable from line counts: effort depends on access, team, versions, tools and depth.
| Stage / asset | What to investigate | Evidence to require |
|---|---|---|
| Architecture and governance | Integrity, secrecy, availability, accessibility; external and internal attackers and suppliers; separation of duties. | Threat model, flows, responsibilities, acceptance criteria and assessors' conflicts of interest. |
| Manufacturing and components | Board revisions, microcontrollers, memory, debugging interfaces, peripherals and component substitutions. | Hardware bill of materials, batch traceability, independent model-specific inspection and test reports. Destructive testing may require dedicated units. |
| Firmware and boot | Root of trust, validation before execution, updates, rollback, maintenance interfaces and induced faults. | Versions, extracted images where authorized, negative tests, model coverage and update records. The root of trust also needs assessment. |
| Source and dependencies | Voting logic, parsers, transitive libraries, cryptography, memory and privileged modules. | SBOM, versions and provenance; reviews, static analysis, fuzzing and integration tests with documented coverage and failures. |
| Build, distribution and keys | Source-to-binary correspondence, compiler, build environment, key access, signatures and revocation. | Build recipe, artifacts and independent references, signing records, control by multiple responsible parties and third-party reproduction. |
| Voter registration and election configuration | Eligible voters, precincts, candidates, numbers and election rules; authorized changes and inconsistent data. | Change traceability, reconciliation against authorized sources, boundary tests and personal data protection. |
| Media generation and loading | Preparation workstations, media contents, accepted/rejected files and correct machine-to-precinct assignment. | Workstation and machine versions, verification results, minutes, exceptions and tests that reject invalid content. |
| Transport, storage and contingencies | Physical access, seals, storage, maintenance and equipment replacement; the interval between verification and use. | Identifiers, responsible personnel, timestamps, opening and replacement records; deviation handling and preservation procedures. |
| Precinct operation | Voter authorization, interface, secrecy, confirmation, accessibility, power, failures, recovery and operator behavior. | Operational tests, independent observation, turnout reconciliation, logs and incident handling without linking voters to their votes. |
| Counting and precinct output | Consistency of BU, RDV and logs; closing, reprinting, replacements and preservation of originals. | Locally collected result reports, signed files, incident history and origin identification. Internal consistency must be distinguished from independent evidence. |
| Transmission, servers and aggregation | Authentication, duplication, omission, rejection, processing, administrative permissions, databases and availability. | System inventory, reception and exception records, administrative audit trail and independent reconstruction of totals from authenticated inputs. |
| Publication, audit and challenges | Agreement between computed and published results; sampling criteria, discrepancies, escalation and correction. | Verifiable data, published methods, reproducible reports and, in architectures that provide them, independent voting records for outcome auditing. |
| Archiving, maintenance and disposal | Retention, forensic preservation, pending requests, subsequent access and data deletion. | Evidence inventory, hashes and custody, preserved copies, deadlines and proof of authorized disposal. |
End-to-end auditability: every transition needs an accountable party, reference and evidence. Logical inspection of every file, physical sample testing and statistical outcome auditing have different costs and scopes. The design must justify those choices and the residual trust in each component.
| Technical question | What the documentation supports | Evidence still needed |
|---|---|---|
| Frequency, access and duration of assessments. | TPS had eight editions between 2009 and 2025; institutional inspection is a separate channel. [22] [21] | Nominal access time does not describe effort, staffing or coverage. |
| Who defines the objects and selects the units? | TPS rules define the objects. During preparation and operational audits, entities participate in selection and random draws. [2] [1] | Choosing from a supplied set is not equivalent to independently selecting any fleet unit. Laboratory scope must be distinguished from operational representativeness. |
| Autonomy to select units and verify their preparation in TPS. | TPS uses TSE-supplied equipment within a defined scope. It does not give teams unrestricted removal of any operational machine for independent testing. Selections and draws in other audits are separate procedures. [2] [21] [1] | Testing equipment supplied for an event is not equivalent to selecting production units under independent custody. Provenance, preparation and fleet equivalence need verifiable evidence. This limits generalization; it does not prove prior equipment manipulation. |
| What do aggregation checks and post-election oversight cover? | Rules provide for checks at TSE and afterward. Comparing BUs examines correspondence between records and published results. [1] [20] | Demonstrate effective access, systems and versions examined, processing and permission tests, exceptions and independent reproduction of results. |
| Which flaws were demonstrated and how were they retested? | Investigators documented technical findings, including the 2012 and 2017 work. [4] [5] [6] | Publish versions, preconditions, fixes, independent reproduction and regression tests to assess how each flaw was addressed. |
| Which threats remain without internet connectivity? | Attacks through media, physical access and the supply chain do not require internet on the machine. [5] [28] | The feasibility of an attack class does not prove exploitation of a current model. |
| How can a physical record provide independent evidence? | A voter-verified, preserved record can support an audit independent of voting software. [13] [14] [15] | Verification, custody, secrecy, reconciliation, accessibility and auditing remain essential. |
Auditing encompasses distinct activities. The matrix separates vulnerability discovery, file verification, procedural observation and outcome validation. Actual powers depend on accreditation, the applicable instrument and the edition. [1] [2] [19] [21]
Article 6 includes parties, federations and coalitions; OAB; the Public Prosecution Service; Public Defender's Office; Congress; CGU; Federal Police; SBC; Confea; CNJ; CNMP; TCU; Industry System/System S entities; accredited Brazilian nonprofit oversight and transparency organizations; and accredited university IT departments. Entities may form consortia. The provisions for STF and the Armed Forces were repealed in 2023: the Defense Ministry's historical participation in 2022 must not be presented as a current entitlement in 2026. [1]
| Channel / participants | Capability or evidence | What it does not demonstrate |
|---|---|---|
| TPS/TPU · selected applicants | Controlled attacks on defined targets, under approved plans. [2] | Universal security, production coverage or coverage of excluded components. |
| Confirmation · finding authors | Repeating tests on modified versions. [2] | Absence of other flaws or regressions outside the test. Item 18.5 allows a TSE adjustment to be considered if the investigator is absent; that is not independent reproduction. |
| Code inspection · eligible entities | Reading and static analysis in a supervised environment; tools subject to usage rules. [1] [21] | It is not unrestricted public repository access. Extraction restrictions reduce external collaboration and reproduction. |
| Academic cooperation · partner institutions | Access and tests under the agreement. USP described access to equipment, code and binaries. [19] [27] | One team's access does not prove equivalent access for all. |
| Hardware and supply · target-specific assessments | Examine specifications, firmware, cryptographic boundaries and model tests. [2] [10] | Certifying a component does not certify the whole system, every unit or the manufacturing chain. |
| Build and signing · accredited oversight | Observe generation and record reference values for programs. [1] | Signing a program does not eliminate errors. Without independent reproduction, the compiler and environment remain in the trusted computing base. |
| Media generation and preparation | Check programs, correspondence and seals; sample-based verification. [1] [21] | It does not automatically cover every later custody transition. |
| Transport and storage | Track responsible personnel, seal numbers, opening events and replacements. [16] [17] | A seal with no observed discrepancy is not firmware analysis or physical proof that access is impossible. |
| Authenticity test | Compare programs against references at the selected precinct before voting. [1] | It does not exercise every logical path, all hardware or behavior during the rest of the day. |
| Integrity test | Compare known inputs from a test election with the output; a biometric variant exists. [1] [30] | It does not recount the real election. It depends on representative conditions and the selection method. |
| BUs and published data · citizen participation | Compare locally collected result reports against published results and reconstruct totals. [20] | It does not recover individual votes from a source independent of the machine. |
| Post-election · requests and forensic examinations | Data, logs, checks and preservation subject to justification and deadlines. [1] [16] [21] | It is not general permission for anyone to dismantle, possess or alter any machine. |
Independent review of execution would require minutes, requests, decisions, access logs, version inventories, chain of custody and location-specific reports. This dossier maps the mechanisms and their limitations; it does not certify execution at every precinct.
The researcher collects his work in the project Electronic Voting in Brazil (eVotingBR), including papers and presentations. This documentation enables assessment of technical findings and methodological criticism by participants in the investigations. [41]
| Contribution | Finding or account | Implication for auditing |
|---|---|---|
| 2012: secrecy | Recovery of vote order in the simulated election by exploiting pseudorandom generation used in the RDV. [4] | Verify secrecy protection, randomness sources and correlation opportunities. |
| 2017: software integrity | Keys embedded in code and unauthenticated libraries enabled injected code execution in the studied setting. [5] | Assess keys, media, loading and installation together; verify versions and fixes. |
| 2018: investigation conditions | In the interview, Aranha describes few days for a large codebase, supervision, restrictions on notes and personal equipment, and time spent preparing the environment and completing forms. [42] | Formal event duration overstates usable time when administration and setup consume part of the window. Effective effort must be recorded. |
| Você Fiscal: study published in 2016 | Photographs of result reports were compared with published results. For the 2014 experience, the authors report coverage of 1.6% of reports and 4.1% of votes. [43] | A citizen check of transmission and publication with measured coverage. It does not reconstruct every choice from a record independent of machine software. |
In the same 2018 interview, Aranha noted that development continued between testing and the following election. Engineering inference: confidence in a version must be reassessed when code, dependencies or configuration change; this requires change comparisons and regression testing. [42]
On a possible departure because of restrictions: the consulted sources document participation, findings and criticism but do not establish that he left a particular project for that reason. We do not attribute that motive without an identifiable account. This section focuses on dated technical evidence and described restrictions.
According to the organizer's historical account, an attempt to capture keyboard emissions with a radio identified one key at approximately five centimeters; it did not demonstrate a complete breach of ballot secrecy. The team's full document was not obtained for this review. The description is therefore attributed to TSE and not generalized to a current remote attack. [22]
Aranha and colleagues showed a weakness in shuffling the Digital Vote Record: pseudorandom generation enabled vote order recovery in the tested setting. Correlating it with voter order threatens secrecy. This differs from demonstrating altered counts. The authors' slides also discuss access and time limits. [4]
The assessment acknowledged discoveries. The portal's technical history describes tampering with a BU used as input to the counting system, producing another valid BU with altered totals in that recovery/counting workflow; it did not demonstrate changed votes across all operational machines. It also reports an accessibility-audio risk and changes to BU authentication and audio activation. [23] [22]
The investigators' paper describes cryptographic keys embedded in code and shared across machines. Signature verification flaws and libraries lacking complementary signatures enabled code execution in the controlled setting. Secrecy and integrity properties were compromised. The authors note that test conditions restricted the investigation. [5]
In the 2018 confirmation, TSE reported changes and mitigation of the identified paths. Key protection received a solution different from the group's initial proposal. Assessing the fix requires linking each finding to the modified version, reproduction procedure and retest result. The organizer's statement does not replace these artifacts. [26]
Federal Police experts recovered material to access the encrypted SIS volume and interfered with GEDAI data generation. The technical account reports supplied passwords and relaxed barriers, representing an insider scenario. State and municipality data were changed, signed and accepted by the machine; changes to candidate and voter data were rejected by other signatures. Obtaining a key alone did not grant unrestricted signing: access to the signing tool was denied. [32]
The Evaluation Committee documented ten executed plans and their results, distinguishing unsuccessful tests from contributions. This case shows test limits and the importance of declaring removed barriers: laboratory conditions may also favor the attack. [33]
The Evaluation Committee's final report documents five plans and confirmation on 11 to 13 May 2022. In plan 6, a sensor overlay captured keystrokes. Changing booth height made placement harder but did not prevent it; mitigation also depends on procedures and poll workers' observation.
For plans 12 and 16, the report describes unauthorized access in JE-Connect components and verified controls. It notes the need for broader review and performance impacts. Plan 20 concerned audio output and poll-worker training.
Recommendations include documenting relaxed barriers and describing the environment delivered to investigators. This is evidence that execution conditions must accompany published results. [45]
The report lists seven alleged findings, five referred for confirmation. On UE2020, a laboratory device changed the bootloader between signature validation and execution, exposing a kernel decryption key: a concrete TOCTOU case. The reported fix unified media access and restricted module loading. There were also findings in BitLocker/SIS and JE-Connect. Modifying the bootloader does not amount to demonstrating election tampering. Adjustments and confirmation records were documented in the 15 to 17 May 2024 retest. [6]
The Regulatory Committee's interim report records 109 submitted plans, 38 approved, 29 executed, six alleged findings and three recommended plans at that stage. These figures describe different stages. [7]
The Evaluation Committee's final report addresses four plans in the May 2026 confirmation:
The committee recommends environments representing different election stages. It says a single environment imposes unnecessary restrictions and recommends expanding technical documentation. [44]
Analysis: accepting an explanation, reviewing documents and repeating experiments have different evidential reach. Reports must identify the evidence supporting each conclusion; listing four plans does not mean four attacks were reproduced after fixes.
Unicamp described three months of work and a favorable conclusion within the examined topics. USP described cooperation-based access and published a technical analysis of allegations with verification procedures. These studies show researchers are not necessarily limited to TPS week. [19] [27]
Defense recorded limitations in understanding code and libraries, citing over 17 million lines. Its statement also says it did not identify fraud. Failing to exclude every possibility does not demonstrate occurrence. [18]
TCU compared 4,161 first-round BUs with published results and reported agreement. This checks correspondence between sampled BUs and publication. It does not independently measure whether each choice was correctly recorded before BU issuance. [20]
Historical coverage: the eight TPS/TPU editions are identified, with deeper analysis where usable evidence was obtained. This is not an exhaustive inventory of all forensic examinations, academic reports, court requests or regional audits since 1996. Older editions do not automatically inherit 2026 rules.
TRE-AL Contract 48/2022 covers examining and validating the organization, conduct and conclusion of the Integrity Test. It provides for observation on the preceding day and election day, a conclusive report and a statement of hours worked. [46]
Technical interpretation: that contractual object differs from reviewing source code, extracting firmware or physically examining the entire fleet. Assessing execution requires comparing the contract, plan, hours, reports, exceptions and evidence. Hiring an external company does not alone establish unrestricted autonomy or coverage of every component.
The national 2022 collection contains reports from both rounds. It is a source for examining local execution, not a ready-made national conclusion. This study does not consolidate all state reports. [30]
| Stage | Time reference | Technical implication |
|---|---|---|
| 2026-cycle inspection | Advance access from 12 months before the election until compilation. [21] | Plan staffing, tools, critical modules, dependencies and version comparisons. |
| TPS 2025 | Registration: 30 June to 18 July. Inspection: 6 to 17 October. Testing: 1 to 5 December 2025. [3] | Publish actual hours, staff, targets, restrictions, executed tests and achieved coverage; the schedule does not measure these outcomes. |
| Confirmation | 13 to 15 May 2026. [3] [8] | Confirm the fixed test, recording conditions and the authors' presence. |
| Selection for election-day audits | The preceding day, 7 am to noon. First round: 3 October; second round: 24 October 2026. [1] [9] | Examine choices, random draws, eligibility and replacements. |
| Voting | 4 October 2026 and a possible second round on 25 October. [9] | Preserve collected BUs and record incidents with precinct, time and evidence. |
| Post-election request | Article 51: up to five days before the seal-retention deadline. [1] | Present facts, indications and a work plan; request preservation when necessary. Do not wait for reformatting. |
| Ordinary preservation | Voting machines and specified media: until 12 January 2027 under Article 272, with exceptions. [16] | A retention period is neither a promise of full forensic examination nor a single deadline for every legal action. |
Line counts do not measure security. A review must define the trusted computing base: application, kernel, libraries, compiler, firmware, cryptographic components and generation tools. Unexecuted code, duplication and generated code change the denominator. Estimating hours per line without a method and inventory would be speculative.
A useful approach is to publish an SBOM, pinned versions, provenance and transitive dependencies, and perform interface testing, static and dynamic analysis, fuzzing, cryptographic review and build reproduction. These are recommendations, not claims that none are practiced.
There is a gap between verification and use, the problem known as time-of-check to time-of-use (TOCTOU). The security argument must explain what prevents or reveals changes during that interval, including maintenance, transport, opening and equipment replacement.
Who produces the measurement also matters. A verifier running on a compromised platform may depend on the same root of trust it seeks to assess. This requires analysis of the actual architecture; it does not imply every hash check is ineffective.
Illustrative model: P = 1 − (1 − p)n, with independent selections (or a large-population approximation) and perfect detection when an affected unit is selected. It does not estimate Brazilian election security. Sampling without replacement requires a hypergeometric distribution; stratification, exclusions and test-aware attacks change the analysis. Including an affected unit does not always imply detecting the flaw.
| Threat class | Conditions to demonstrate | Desired control and evidence |
|---|---|---|
| Malicious source or dependency | Entry into the development chain, insufficient review or compromised provenance. | Third-party review, provenance, pinned versions, SBOM and reproducible builds. A signature alone also authenticates an authorized defect. |
| Replaced binary or media | Ability to produce accepted content or bypass verification. | Signatures, key protection, load-time validation, version records and negative tests. |
| Physical / firmware implant | Access to the device or manufacturing and ability to survive inspections. | Model/batch inspection, chain of custody, supervised opening and firmware assessment. Equipment age alone does not prove this threat. |
| Software recognizing a test environment | A distinguishable signal and control of the code that uses it. | Reduce observable differences; document randomization and limits. This is a threat hypothesis, not a malicious mechanism found in this study. |
| Electromagnetic / acoustic emissions | Physical coupling, signal, range and measurable relation to relevant data. In RAMBO, preexisting malware generates radio signals through the RAM bus. [12] | Side-channel tests on a specific model. The external receiver needs no internet connection to capture data; the experiment assumes prior compromise. |
| Attack on a switched-off device | A still-powered subsystem, implant or coupled energy, and a compatible vulnerability. | Measure actual power states and interfaces. Document network disconnection separately from absence of electrical power. |
| Incorrect aggregation/publication | Discrepancies in receipt, processing, inclusion or summation of results. | Reconstruct totals from independently collected BUs; verify signatures, pending items and coverage. |
These classes form a threat model. Concrete Brazilian-machine examples appear in historical research; untested hypotheses do not receive the same status. [5] [6] [28]
The illustrated flow, with verification through a window and automatic deposit in a sealed container, avoids giving the voter a readable receipt of their vote. This removes one way to present a receipt to others. It does not eliminate every risk of coercion, order linkage, printing errors or record substitution or loss.
Physical evidence actually verified by voters may enable outcome verification even if voting software is wrong. That is the goal of software independence. End-to-end cryptographic verification is another research direction; the property is not limited to paper. [13] [29]
An RLA limits the probability of ending an audit without correcting a wrong outcome, under its assumptions. The risk limit is not a probability of fraud. Sample size depends on the margin, method, observed errors and electoral rule; it may reach a full count. [14]
Accessible verification; rejection and correction of mismatched printouts; jam handling; readable text; no voter identification; protection against order reconstruction; reconciliation of issued, canceled and deposited records; seals and inventories; observed storage; public random draws; adjudication and recounts.
Appel and colleagues warn that voters do not always verify or notice changes in machine-produced records. Rates observed abroad should not be transferred to Brazil, but usability must be tested. [15]
Protected bags, banknotes and envelopes resist tampering or leave traces. Calling them tamper-proof requires an absolute guarantee they do not provide. Authentic paper may also contain an incorrectly printed vote.
The illustration proposes an architecture; it does not describe current Brazilian procedures or assess legal feasibility, budgets or implementation schedules. For the electronic machines discussed here, printing a BU is not printing each vote for individual verification.
The announced 2026 inventory lists UE2013, UE2015, UE2020 and UE2022. UE2020 and UE2022 total 439,468 units, or 77.9% of the announced 563,910. This is our calculation from source quantities, not a measurement of deployed equipment. [9]
The technical table distinguishes memory, processor and cryptographic boundaries. UE2013/UE2015 and UE2020/UE2022 should not be treated as identical hardware. Nor should a flaw in one generation be assumed to affect another without examining its implementation. [10] Documents plan replacement of UE2013 and UE2015 starting in 2028. [31]
Assessing the regional hypothesis would require data by election → round → state → electoral zone → precinct → machine number → model → version/hash → replacement. This study did not obtain a complete nationwide precinct-level inventory for 2026. It therefore does not provide a colored map suggesting an unmeasured distribution.
Comparing models with voting patterns would also require controlling for urbanization, income, location and electorate composition. Nonrandom equipment distribution can produce demographic correlations; correlation between model and political preference does not identify fraud.
Authorship and scope: ALAS TECHNOLOGY gathers and analyzes published sources, organizes the technical synthesis and creates the illustrations. Cited experiments were conducted by the authors identified in each reference. This material is neither a forensic expert report nor a security certification.
Nonpartisan position: The content neither supports nor challenges a government, party, candidate or winner. The same criteria apply to any result. Research independence is assessed through access, methodological autonomy, reproducibility, disclosure of conflicts of interest and freedom to report findings, not merely institutional identity.
Rules and test notices establish permissions and procedures, not proof of invulnerability. Researcher reports and papers characterize findings. Statements by TSE, Defense, TCU and universities are identified as institutional accounts with limited scope. Institutional authority, supportive or critical, does not replace reproducible evidence.
The consolidated text applicable to 2026 was used, considering the 2024 and 2026 amendments. No hardware tests, code inspection, exploit reproduction or election forensic examination were performed. We do not claim review of all state reports or historical audits. The analysis includes the 2025/2026 Evaluation Committee's final report. Review of the Regulatory Committee's final report and compendium, and consolidation of state reports, remain outside completed documentary coverage.
A team may find no flaw because a component is well protected, an attack is infeasible, conditions, time or access were insufficient, or the test did not exercise the relevant behavior. The cause must be established case by case. Not every negative result can be attributed to restrictions, nor can it prove the absence of vulnerabilities.
Editorial conclusion: criticizing auditability limits is technically legitimate. Alleging vote tampering, asserting invulnerability or promising zero risk requires evidence this review does not provide.
The 16 September 2026 review checked core statements against cited references, distinguished current from repealed provisions and recalculated fleet percentages. It is neither a guarantee of error-free content nor independent validation of the experiments.
| Topic | Checked basis | Limit of the conclusion |
|---|---|---|
| Permissions, random draws and deadlines | Consolidated Resolution 23.673, TPS notice and calendar. | A regulatory provision does not demonstrate execution at each location. |
| Announced fleet | 29,377 + 95,065 + 222,323 + 217,145 = 563,910. 2020 and 2022 models: 77.9%. | Announced inventory, without a nationwide precinct-level map. |
| Historical findings | Research papers and reports identified by edition. | ALAS TECHNOLOGY did not reproduce the attacks. |
| RAMBO and AI | Researchers' publications, Anthropic's report and Mozilla's confirmation. | They do not demonstrate automatic applicability to Brazilian machines. |
| 2025/2026 cycle | Calendar, Regulatory Committee interim report and Evaluation Committee final report. | Documentary acceptance and experimental retesting are distinct evidence; this analysis did not reproduce the tests. |
Documentary scope is identified in the references. Reports for one edition, location or sample do not certify the whole fleet. National assessment of execution requires a matrix by state, round, unit, procedure, result and exception; this version does not provide that consolidation.
Consult your state's regional electoral court (TRE) for ceremony and audit notices. Public observation and participation as an oversight entity carry different permissions. For technical assessment, record the election, round, precinct, model, version, target, team, method, result and limitations.
Article 60 permits regional grouping for representativeness and agreed logistical exclusions. Article 60-A requires publication of selected machines and identification data. Article 61 permits observing transport. These records help assess continuity and coverage; they are not an exhaustive review of every unit. [1]
After voting, comparing precinct-collected BUs with published results checks correspondence. It is not a recount of independent records of each vote. Formal post-election oversight requests follow the resolution's requirements and deadlines. [1] [20]
Slides identify sources by title. The numbers below organize the dossier references. Accessed: 16 September 2026. External links open the original document. Notes explain exactly how each source was used.
45 references available.
Oversight rules. Consult current wording, excluding struck-out or repealed provisions. Alone, it does not establish execution at every location.
Items 1.4 to 1.6, 7, 18.5 and 19.1: targets, exclusions, inspection and confirmation.
Registration, inspection and execution in the 2025/2026 cycle. Planned dates are not actual hours used.
Researchers' own source: vote-order recovery and limits of the 2012 test.
Paper on the 2017 test: keys in code and unauthenticated libraries. A historical finding, not a diagnosis of the 2026 version.
Pages 33 to 35: findings, conditions and fixes. A plan's name expresses its objective, not necessarily its result.
Interim report: 29 executed plans; 6 alleged findings; 3 plans recommended at that stage.
Reports four tests selected for confirmation and validated improvements. Institutional communication, not independent test reproduction.
563,910 machines announced; not a verified precinct-level deployment inventory. The text says 77%; the published quantities yield 77.9%.
Official specifications distinguishing hardware, memory, processors and cryptographic boundaries.
Research presented at NordSec 2023, with a preprint deposited in 2024. Demonstrates exfiltration through memory-bus emissions from an isolated, previously compromised computer, received remotely by radio.
2006 conceptual paper: undetected software changes must not cause undetectable changes to the outcome.
Statistical auditing method for physical records; not the design of Brazil's Integrity Test.
2020 paper: voter verification failures in ballot-marking devices. Evidence from other systems, not a measurement of a Brazilian design.
Article 272: preservation until 12 January 2027, with exceptions and specific procedures.
Numbered seals, security materials and production by Casa da Moeda. Tamper evidence, not invulnerability.
Oversight participant's account: over 17 million lines and access restrictions. The same statement says it did not identify fraud; it is not an independent count of 2026 code.
University statement on three months of analysis, with conclusions limited to examined topics. Institutional cooperation offers access different from TPS and ordinary oversight.
Audit of correspondence between result reports and publication. Not a recount of individual voter intent.
Changes preparation sampling to up to 6%, retains extraction restrictions and regulates subsequent checks.
Index of eight editions: 2009, 2012, 2016, 2017, 2019, 2021, 2023 and 2025. The page includes statistics and texts from different periods.
Preliminary institutional assessment acknowledging discoveries; it does not detail complete exploitation.
Announcement and access to the edition's report; absence of demonstrated compromise must not be confused with universal proof.
Reports 29 plans, five with relevant findings and retesting in May 2022.
Fixes and mitigation described by the organizer; includes Aranha's observations on changes to key protection.
Researchers' text with access to the report and tutorials. Describes access to code, binaries and equipment under a specific collaboration.
Research on media-based threats and deployed-system limits; it does not demonstrate exploitation of a current Brazilian machine.
Cryptographic alternative: verify inclusion and counting while preserving secrecy. Depends on protocol, implementation and usability, not just digital signatures.
Repository of reports from both rounds. Its existence does not mean every report was reviewed in this study.
Document plans UE2013 and UE2015 replacement starting in 2028; procurement planning is not completed deployment.
Describes SIS/GEDAI access, insider-attack conditions, modified data and remaining barriers.
Scope, group-specific results, barriers and recommendations.
US AccuVote-TS study: physical-access and media attacks, propagation and consistency of tampered records. Not a Brazilian-machine test; informs threat classes and methodology.
Research on verifiable correspondence between source and binary artifacts, including the environment and build chain.
Multidisciplinary scientific report. Recommendations 5.5 to 5.10 cover processes, registration, voting, results and post-election auditing. US context; it does not establish Brazilian conditions.
Project's technical reference: rebuilding identical artifacts from the specified source and environment.
Primary account of Claude-assisted discovery, human triage and a Linux use-after-free fix; introduction dated to July 2025.
The maintainer confirms verifiable bugs identified with AI assistance and reproducible tests.
Report of previously unidentified flaws in open-source projects, some long-standing. Age and scope depend on each finding.
Researcher's page: publications, project and presentations on Brazilian electronic voting security.
Participant's direct testimony, published on 17 October 2018. Restrictions described in that context, without automatic extrapolation to 2026.
Você Fiscal study: distributed comparison of result-report photographs with published 2014 results; coverage and method limits.
Sections 2 and 3: plans 09, 26, 31 and 33; confirmation methods and environment recommendations.
Sections 2 and 3: findings, retests, operational measures and documentation of barriers.
Clauses one, two and four: contracted scope, observation, reporting and hours recorded.
ALAS TECHNOLOGY · Voting in Brazil · Nonpartisan documentary study and explanatory illustrations.
Retain caveats and references when adapting the carousel. The dossier forms part of the evidence supporting the images.