# Brazilian Voting Machines | Independent Technical Study | ALAS TECHNOLOGY

> An illustrated nonpartisan study of controls, limitations and evidence in Brazilian electronic voting audits.

## 1. What does an audit actually prove?

Hardware, software, people and processes: what evidence supports evaluating election security from beginning to end?

YOUR VOTE; 1; 2; 3; 4; 5; 6; 7; 8; 9; 0; BLANK; CORRECT; CONFIRM; DESIGN; Code + hardware; INSTALLATION; Signatures + custody; OUTCOME; Records + recount



PURPOSEAn ALAS TECHNOLOGY study: the same technical standards, regardless of the government, candidate or outcome.

TECHNICAL ANALYSISTechnical criteria, without political preference

This analysis is nonpartisan and unaffiliated with any government, party or candidate. Its criteria are independent of the election outcome.

The subject is the complete chain of trust. Independent research informs architectural assessment; rules help compare the available oversight powers with the tests needed.

## 2. An election is bigger than the machine.

A complete assessment follows equipment, code, data, people and evidence through every transition.

01  Design; Factory + components; 02  Software; Source + build + keys; 03  Data; Voters + candidates; 04  Preparation; Loading + seals; 05  Custody; Transport + storage; 06  Voting; Secrecy + recording; 07  Results; BU + transmission; 08  Aggregation; Reception + publication; 09  Post-election; Audit + preservation

AUDIT THE PROCESSWho had access, what changed and how it was authorized.

AUDIT THE OUTCOMEWhether the evidence supports the reported result.

DISTINCTIONAt each stage: a defined threat, a test method, preserved evidence and identifiable responsibility.

TECHNICAL ANALYSISFull scope and demonstrable coverage

The diagram is a proposed assessment map. It includes registration, suppliers, builds, media, logistics, precincts, servers and retention.

Covering every stage does not mean testing every possible state of every component. Auditing must justify depth, sampling and residual risk, including transitions between teams and systems.

## 3. Limited time. Coverage to establish.

TPS 2025 testing lasted five days. Preparatory inspection and institutional oversight have separate access windows.

30 JUN → 18 JUL / 2025; TPS registration; 06 → 17 OCT / 2025; Preparatory code inspection; 01 → 05 DEC / 2025; Execution of test plans; 13 → 15 MAY / 2026; Confirmation of fixes; ANOTHER ROUTE; Inspection by; oversight; entities; Advance access:; from 12 months; before the election.*

THE FULL STACKApplications, libraries, kernel, firmware and hardware.

ACTUAL EFFORTTeam, hours, access and tests determine depth.

COVERAGEThese windows do not establish exhaustive review of the machine and its dependencies.

SCOPE LIMITATIONAn available schedule is not demonstrated coverage

Five days of TPS test-plan execution form a bounded testing window, not a complete machine review. The schedule also provides preparatory inspection, and an institutional channel offers advance access.

Time sufficiency must be assessed against objectives, staff, actual hours, access, tools and complexity. There is no basis here for a universal minimum duration or a claim that every team had only five days.

Coverage of transitive libraries, compilers, kernel, drivers, firmware, physical components and their interactions must be documented. Formal inclusion in scope does not reveal how much was actually examined.

In a 2018 interview, Diego Aranha described time and environment restrictions in editions he attended. His testimony helps assess effective team capability; it does not establish that all historical rules persist in 2026.

## 4. Tests have boundaries. So do conclusions.

TPS equipment is supplied by the organizer. Teams cannot freely select any unit from the deployed fleet for examination.

INCLUDED; OUTSIDE TPS 2025; UE2022 machine and firmware; Voting and local counting; Media generation; Transmission and reception; Verifiers and JE-Connect; SISTOT and databases; Production servers; Build environment; Key generation; Destructive attacks and seals; Outside TPS ≠ outside all oversight.



LIMITATIONA laboratory scope does not establish coverage of the deployed fleet or its chain of custody.

LIMITATIONPartial coverage is a real restriction

The rules also exclude biometric identification, JE-Connect infrastructure, processing after reception and denial of service. Success in a limited test must not become universal certification.

Article 41 provides for integrity and authenticity checks at TSE. Alone, that provision does not establish review of aggregation logic, administrative permissions or production environments: documented plans, access and results are needed.

Freely selecting an operational unit and preserving its state differs from testing event-supplied objects. Comparing the scenarios requires documenting equipment origin, preparation, interventions and equivalence with deployed versions. The 2017 authors describe methodological restrictions as well as demonstrated attacks.

## 5. Samples check parts. What about the whole?

Oversight entities participate in selection, but tests do not follow every unit from preparation through the post-election period.

PREPARATION; Up to 6% per electoral zone: authenticity and integrity checks.; ELECTION DAY • SAMPLES PER STATE; Precincts in the state; Integrity; Authenticity; Up to 15,000; 20; 3; 15,001 to 30,000; 27; 8; Above 30,000; 33; 10; Selection the day before, 7 am to noon; testing on election day.

SELECTIONExclusions and predictable tests require risk analysis.

CONTINUITYRequire unit-level traceability at every transition.

COVERAGE GAPFormal responsibility does not establish independent auditing of the entire fleet from beginning to end.

COVERAGE LIMITATIONFormal responsibility and effective coverage differ

Rules assign responsibilities to TRE audit committees. Assessing execution requires identifying who examined each stage, with what autonomy, which artifacts were preserved and how they link the same unit across the cycle.

The described sample tests are not continuous individual monitoring of every machine. This limits generalization without making sampling automatically useless. Conclusions depend on design and statistical assumptions.

Logistical exclusions, model and regional representativeness, predictability and differences between test and real-use environments belong in the threat model. Environment-conditioned behavior is a risk to investigate, not an attack established by this study.

Assessing the full chain requires unit inventories, versions and hashes, loading, custody, transport, replacement, voting and subsequent preservation records, with identified accountable personnel and independent checks.

## 6. Vulnerabilities have been found.

Teams produced technical findings. Their meaning depends on the target, conditions and version tested.

2012; Ballot secrecy; Recovery of vote order in the RDV.; 2017; Software integrity; Code execution through library vulnerabilities.; 2023; Boot and support systems; Findings in boot, SIS and JE-Connect; retested in 2024.; 2025; Support systems; ZipSlip, privileges and validation: findings with caveats.



EVIDENCEDocumented findings reinforce the need for continuous testing, broad scope and independent verification of fixes.

DOCUMENTED FINDINGSIt is incorrect to say nothing was ever found

The 2012 and 2017 publications document security-property violations in controlled tests. The 2023 report distinguishes findings and fixes.

Documents distinguish adjustments, retests and acceptance of technical explanations. The dossier details this for the 2025/2026 cycle. Defects, barrier exploitation, complete attacks and proven election alteration must be distinguished.

eVotingBR gathers work by Aranha and colleagues. Contributions cover ballot secrecy, software integrity and distributed verification of result reports. The dossier has a dedicated section on findings and researchers' reported restrictions.

## 7. One fleet. Four generations.

Models announced for 2026. Hardware, firmware and dependencies require explicit coverage by version.

UE2013; 29,377; 5.2%; UE2015; 95,065; 16.9%; UE2020; 222,323; 39.4%; UE2022; 217,145; 38.5%; 563,910 machines announced; Model inventory ≠ software version installed at each precinct.

MODEL × REGIONPublish distribution and test coverage.

STRATIFIED SAMPLEInclude generations, versions, batches and operating conditions.

REPRESENTATIVENESSRegional concentration requires explicit coverage. Average vote totals do not validate counting integrity.

SCOPED DATAFleet distribution and audit design

The model year identifies an equipment generation; alone it does not reveal manufacturing year, loaded binary or security state.

Defense reported over 17 million lines in 2022. This study did not measure that figure or verify it for 2026. Without dependency inventories, scope and coverage metrics, the reviewed proportion cannot be quantified.

Investigating regional model concentration is relevant: hardware differences may be confounded with geographic and operational differences. The proposal is to publish the model × version × location matrix and justify coverage of each stratum.

Distributing every model in equal proportions nationwide is not a universal technical security requirement. Failure or availability comparisons need controls for usage, maintenance and environment; average votes across models or regions do not verify election correctness.

Stratified sampling can address heterogeneity without redistributing equipment. Allocation depends on objectives and risk: simple proportionality is not always sufficient for small or higher-risk groups. The national inventory shown does not measure regional distribution.

## 8. Offline does not mean risk-free.

Physical access, removable media, firmware and supply chains are attack surfaces. Feasibility depends on concrete conditions.

RAMBO EXPERIMENT • DATA EXFILTRATION CHANNEL; RAM; Previously infected computer; Software induces emissions; RADIO SIGNAL; No internet connection; SDR / RF; External receiver; Captures and decodes data; OTHER SURFACES TO EXAMINE; Media and ports; Firmware and manufacturing; Physical access and custody

CONTROLSVerified boot, signatures and custody.

STUDY PRECONDITIONRunning malware and an external radio receiver.

EVIDENCERAMBO demonstrated remote data extraction through RAM emissions, without internet, from a previously infected computer.

TECHNICAL ANALYSISRAM as a radio channel

In RAMBO, preinstalled malicious software induces electromagnetic emissions on the memory bus. An external radio receiver captures and decodes data remotely without internet connectivity on the computer.

The experiment demonstrates exfiltration from a previously compromised machine. Electoral-system assessment must include physical channels, initial access and hardware-specific conditions.

## 9. The voter checks. The paper stays.

In the illustrated proposal, voters inspect the record through a window without handling it. It drops into a sealed compartment.

CHECK THROUGH THE WINDOW; YOUR VOTE; ✓  CHECK; SEALED; BALLOT BOX; NOT TAKEN HOME; The record remains under custody; for later verification and auditing.; 01; SEALS AND IDENTIFICATION; Evidence of opening and traceability.; 02; CONTROLLED ACCESS; Accountable personnel and logged movements.; 03; PRESERVATION AND AUDIT; Secrecy, inventory and ballot comparison.

CUSTODY ANALOGYCash-in-transit bags and sealed exam envelopes.

CUSTODY ANALOGYPolice evidence: seals and transfer records.

RETAINED ON SITESecurity paper, seals and controlled custody: voters verify the record but do not receive a receipt to take away.

TECHNICAL PROPOSALVVPAT and risk-limiting audits

The illustrated design is a voter-verifiable paper audit trail (VVPAT). Its security requires discrepancy handling, accessibility, secrecy, retention and inventory controls.

A risk-limiting audit (RLA) can expand the sample to a full count. It depends on trustworthy records and a rule compatible with the electoral system. Paper without auditing does not automatically provide this guarantee.

Cash bags, exam envelopes and police evidence illustrate custody controls. They do not imply identical protocols or security levels. An electoral proposal must still specify paper, seals, access, inventory reconciliation, secrecy and discrepancy responses.

## 10. Open source. Continuous auditing.

Broader access allows independent public and private teams to investigate beyond event-specific windows.

01; OPEN AND REPRODUCE; Code, dependencies and history;; verifiable builds and public versions.; 02; AUDIT CONTINUOUSLY; Independent research, accessible; hardware and coordinated disclosure.; 03; ADOPT NEW METHODS; AI, fuzzing and code analysis;; human validation of findings.; 04; FIX AND RETEST; Version-controlled updates,; regression tests and a new audit.



IMPROVEMENTAI has supported findings in Linux and Firefox. New methods justify reexamining even mature systems.

RECOMMENDATIONSTransparency and research beyond the electoral calendar

The proposal is to release openly licensed code, history, dependencies and build instructions, alongside representative equipment for independent public and private teams. Supervised code access is not equivalent to an open project with continuous review.

Funding, documentation and effective access are needed to turn availability into coverage. Findings must be reproduced, fixed and retested; changes to electoral systems require versioning and change management.

Report ANT-2026-CM0TCREP attributes a Linux discovery to Claude, with human triage and a fix: CVE-2026-43074. The report dates its introduction to July 2025, so this example is not a decades-old flaw. Mozilla also confirms AI-assisted findings in Firefox. Separate reports concern older flaws in other projects; their age should not be attributed to the Linux case.

Evolving tools support periodic reassessment. They do not demonstrate a vulnerability in a particular voting machine without checking its version, configuration, access and exploitation conditions.

ALAS TECHNOLOGY STUDY / VERSION 1.2

What each audit can demonstrate.

Documentary research and analysis by ALAS TECHNOLOGY, nonpartisan and unaffiliated with any government, party, candidate or electoral outcome. The focus is the entire ecosystem: hardware, software, people, operations and evidence. Independent research informs the security criteria; rules describe formal access. This is a documentary study, without direct inspection of machines or code.

How to assess evidence
Technical criteria
The full ecosystem
Premises
Audit opportunities
Aranha and colleagues
Historical findings
Time frames
Threats
Paper records
How to follow the process
Glossary
Verification
Sources
10 PNGs ↓
Open source, continuous auditing and AI

The proposal is to release openly licensed code, history, dependencies and build instructions, alongside representative equipment for independent public and private teams. Supervised code access is not equivalent to an open project with continuous review.

Funding, documentation and effective access are needed to turn availability into coverage. Findings must be reproduced, fixed and retested; changes to electoral systems require versioning and change management.

Report ANT-2026-CM0TCREP attributes a Linux discovery to Claude, with human triage and a fix: CVE-2026-43074. The report dates its introduction to July 2025, so this example is not a decades-old flaw. Mozilla also confirms AI-assisted findings in Firefox. Separate reports concern older flaws in other projects; their age should not be attributed to the Linux case.

Evolving tools support periodic reassessment. They do not demonstrate a vulnerability in a particular voting machine without checking its version, configuration, access and exploitation conditions.

[35] [38] [39] [40]
From announced procedures to technical evidence

Permission does not prove effective access. Executing a test does not prove total coverage. Announcing a fix does not prove independent retesting. These are the criteria used in this dossier, applied to organizers, oversight bodies, suppliers and researchers. Political views or a source's prestige do not determine the validity of a finding.

INFORMATION TYPE	USE IN THIS ANALYSIS	VERIFICATION NEEDED
Rule or test notice	Identify formal permissions, restrictions and deadlines.	Minutes, approved and denied requests, access granted and execution reports.
Institutional statement	Record what the institution claims to have done.	Data, methods, versions, findings and technical documentation supporting the statement.
Research demonstrating an attack	Assess the property compromised under the published conditions.	Preconditions, target, version, materials, reproduction and comparison with the operational configuration.
Retest	Assess whether the known attack still works on the modified version.	Investigators' presence, test procedure, evidence, regression tests and variants.
Hypothesis or recommendation	Guide research and improvements.	Do not present it as a discovered flaw or an already implemented security measure.
Selection, preparation and custody: the specific criticism of TPS

Access to equipment supplied by the organizer does not, by itself, establish independent selection from the operational fleet. Aranha and colleagues describe methodological restrictions and attacks that compromised security properties in the examined setting. Criticism of laboratory scope has a technical basis; its representativeness must be demonstrated. [2] [5]

Proposed independent assessment: define the eligible population, record exclusions, enable independent participation in selection, identify each unit and preserve its state before any test preparation. Document interventions, images and versions, personnel, transfers and access conditions. These are recommendations of this analysis, not procedures already verified as implemented.

When examining operational state, preparation that replaces software or deletes records may remove the very evidence sought. Reproducing an attack may require preparing a controlled environment. The report should state which objective was met and what was changed. A verifiable technical requirement is to track and limit interventions, rather than assume nobody previously touched the equipment.

Agreement between records is not sufficient for every conclusion

Records generated by the same component may share the same fault. On a US AccuVote-TS, Feldman and colleagues demonstrated modifications with internally consistent records. This supports that threat class; it is not a finding in a Brazilian voting machine. [34] Software independence concerns the ability to detect changes to the outcome even when software fails. [13]

Limits of this review: the ten topics and the dossier were reviewed, with foundations rechecked against primary sources. ALAS TECHNOLOGY did not inspect equipment, reproduce attacks or verify execution at all precincts. Limits to documentary coverage remain identified. Publications alone cannot establish the complete operational reality.

Technical foundations / assessing security

The central criterion is the evidence produced, not an authority's declaration. Test rules state what may be tested. An engineering assessment asks which threats were examined, what conditions were reproduced and what conclusions the results support. Missing data in this dossier are marked as unverified, not as automatic evidence that a control is absent.

Independent research on real systems

Feldman, Halderman and Felten analyzed the hardware, software and operation of a US AccuVote-TS. In the laboratory, they demonstrated attacks through physical access and media, with tampered records that remained mutually consistent. The study informs analysis of custody, propagation and record dependence; it did not examine Brazilian equipment. [34]

In Brazil, work by Aranha and colleagues provides evidence directly tied to the versions they tested. The 2017 account shows why keys, libraries and code loading must be assessed together. [5]

Source, binary and execution

Research on reproducible builds examines reconstructing the same artifact from identified sources, instructions and environments. This makes part of the source-to-binary link verifiable. [35] [37]

The complete argument must also cover compilers, firmware, keys, installation and execution. Two identical builds do not prove program correctness; a signed image does not prove that its logic was sufficiently reviewed.

The scientific report Securing the Vote recommends assessing processes and outcomes, including registration, preparation, voting and publication, with audit data that enable reproduction and protect voters. It is a foreign methodological reference, not a measurement of Brazil. [36]

How to record each conclusion: target and version → threat → access obtained → method → reproduced result → fix → retest → limits to generalization. Useful categories: demonstrated, mitigated under test, threat hypothesis, not examined and insufficient data.

The full ecosystem / proposed audit plan

The matrix below is a proposed technical scope. It does not claim these procedures were performed in Brazil or that they are absent. Assessing implementation would require artifacts from every stage. There is no universal time frame derivable from line counts: effort depends on access, team, versions, tools and depth.

STAGE / ASSET	WHAT TO INVESTIGATE	EVIDENCE TO REQUIRE
Architecture and governance	Integrity, secrecy, availability, accessibility; external and internal attackers and suppliers; separation of duties.	Threat model, flows, responsibilities, acceptance criteria and assessors' conflicts of interest.
Manufacturing and components	Board revisions, microcontrollers, memory, debugging interfaces, peripherals and component substitutions.	Hardware bill of materials, batch traceability, independent model-specific inspection and test reports. Destructive testing may require dedicated units.
Firmware and boot	Root of trust, validation before execution, updates, rollback, maintenance interfaces and induced faults.	Versions, extracted images where authorized, negative tests, model coverage and update records. The root of trust also needs assessment.
Source and dependencies	Voting logic, parsers, transitive libraries, cryptography, memory and privileged modules.	SBOM, versions and provenance; reviews, static analysis, fuzzing and integration tests with documented coverage and failures.
Build, distribution and keys	Source-to-binary correspondence, compiler, build environment, key access, signatures and revocation.	Build recipe, artifacts and independent references, signing records, control by multiple responsible parties and third-party reproduction.
Voter registration and election configuration	Eligible voters, precincts, candidates, numbers and election rules; authorized changes and inconsistent data.	Change traceability, reconciliation against authorized sources, boundary tests and personal data protection.
Media generation and loading	Preparation workstations, media contents, accepted/rejected files and correct machine-to-precinct assignment.	Workstation and machine versions, verification results, minutes, exceptions and tests that reject invalid content.
Transport, storage and contingencies	Physical access, seals, storage, maintenance and equipment replacement; the interval between verification and use.	Identifiers, responsible personnel, timestamps, opening and replacement records; deviation handling and preservation procedures.
Precinct operation	Voter authorization, interface, secrecy, confirmation, accessibility, power, failures, recovery and operator behavior.	Operational tests, independent observation, turnout reconciliation, logs and incident handling without linking voters to their votes.
Counting and precinct output	Consistency of BU, RDV and logs; closing, reprinting, replacements and preservation of originals.	Locally collected result reports, signed files, incident history and origin identification. Internal consistency must be distinguished from independent evidence.
Transmission, servers and aggregation	Authentication, duplication, omission, rejection, processing, administrative permissions, databases and availability.	System inventory, reception and exception records, administrative audit trail and independent reconstruction of totals from authenticated inputs.
Publication, audit and challenges	Agreement between computed and published results; sampling criteria, discrepancies, escalation and correction.	Verifiable data, published methods, reproducible reports and, in architectures that provide them, independent voting records for outcome auditing.
Archiving, maintenance and disposal	Retention, forensic preservation, pending requests, subsequent access and data deletion.	Evidence inventory, hashes and custody, preserved copies, deadlines and proof of authorized disposal.

End-to-end auditability: every transition needs an accountable party, reference and evidence. Logical inspection of every file, physical sample testing and statistical outcome auditing have different costs and scopes. The design must justify those choices and the residual trust in each component.

01 / Technical questions and available evidence
TECHNICAL QUESTION	WHAT THE DOCUMENTATION SUPPORTS	EVIDENCE STILL NEEDED
Frequency, access and duration of assessments.	TPS had eight editions between 2009 and 2025; institutional inspection is a separate channel. [22] [21]	Nominal access time does not describe effort, staffing or coverage.
Who defines the objects and selects the units?	TPS rules define the objects. During preparation and operational audits, entities participate in selection and random draws. [2] [1]	Choosing from a supplied set is not equivalent to independently selecting any fleet unit. Laboratory scope must be distinguished from operational representativeness.
Autonomy to select units and verify their preparation in TPS.	TPS uses TSE-supplied equipment within a defined scope. It does not give teams unrestricted removal of any operational machine for independent testing. Selections and draws in other audits are separate procedures. [2] [21] [1]	Testing equipment supplied for an event is not equivalent to selecting production units under independent custody. Provenance, preparation and fleet equivalence need verifiable evidence. This limits generalization; it does not prove prior equipment manipulation.
What do aggregation checks and post-election oversight cover?	Rules provide for checks at TSE and afterward. Comparing BUs examines correspondence between records and published results. [1] [20]	Demonstrate effective access, systems and versions examined, processing and permission tests, exceptions and independent reproduction of results.
Which flaws were demonstrated and how were they retested?	Investigators documented technical findings, including the 2012 and 2017 work. [4] [5] [6]	Publish versions, preconditions, fixes, independent reproduction and regression tests to assess how each flaw was addressed.
Which threats remain without internet connectivity?	Attacks through media, physical access and the supply chain do not require internet on the machine. [5] [28]	The feasibility of an attack class does not prove exploitation of a current model.
How can a physical record provide independent evidence?	A voter-verified, preserved record can support an audit independent of voting software. [13] [14] [15]	Verification, custody, secrecy, reconciliation, accessibility and auditing remain essential.
02 / Map of audit opportunities

Auditing encompasses distinct activities. The matrix separates vulnerability discovery, file verification, procedural observation and outcome validation. Actual powers depend on accreditation, the applicable instrument and the edition. [1] [2] [19] [21]

Who qualifies as an oversight entity in 2026?
CHANNEL / PARTICIPANTS	CAPABILITY OR EVIDENCE	WHAT IT DOES NOT DEMONSTRATE
TPS/TPU · selected applicants	Controlled attacks on defined targets, under approved plans. [2]	Universal security, production coverage or coverage of excluded components.
Confirmation · finding authors	Repeating tests on modified versions. [2]	Absence of other flaws or regressions outside the test. Item 18.5 allows a TSE adjustment to be considered if the investigator is absent; that is not independent reproduction.
Code inspection · eligible entities	Reading and static analysis in a supervised environment; tools subject to usage rules. [1] [21]	It is not unrestricted public repository access. Extraction restrictions reduce external collaboration and reproduction.
Academic cooperation · partner institutions	Access and tests under the agreement. USP described access to equipment, code and binaries. [19] [27]	One team's access does not prove equivalent access for all.
Hardware and supply · target-specific assessments	Examine specifications, firmware, cryptographic boundaries and model tests. [2] [10]	Certifying a component does not certify the whole system, every unit or the manufacturing chain.
Build and signing · accredited oversight	Observe generation and record reference values for programs. [1]	Signing a program does not eliminate errors. Without independent reproduction, the compiler and environment remain in the trusted computing base.
Media generation and preparation	Check programs, correspondence and seals; sample-based verification. [1] [21]	It does not automatically cover every later custody transition.
Transport and storage	Track responsible personnel, seal numbers, opening events and replacements. [16] [17]	A seal with no observed discrepancy is not firmware analysis or physical proof that access is impossible.
Authenticity test	Compare programs against references at the selected precinct before voting. [1]	It does not exercise every logical path, all hardware or behavior during the rest of the day.
Integrity test	Compare known inputs from a test election with the output; a biometric variant exists. [1] [30]	It does not recount the real election. It depends on representative conditions and the selection method.
BUs and published data · citizen participation	Compare locally collected result reports against published results and reconstruct totals. [20]	It does not recover individual votes from a source independent of the machine.
Post-election · requests and forensic examinations	Data, logs, checks and preservation subject to justification and deadlines. [1] [16] [21]	It is not general permission for anyone to dismantle, possess or alter any machine.

Independent review of execution would require minutes, requests, decisions, access logs, version inventories, chain of custody and location-specific reports. This dossier maps the mechanisms and their limitations; it does not certify execution at every precinct.

Diego Aranha and colleagues: findings, restrictions and proposals

The researcher collects his work in the project Electronic Voting in Brazil (eVotingBR), including papers and presentations. This documentation enables assessment of technical findings and methodological criticism by participants in the investigations. [41]

CONTRIBUTION	FINDING OR ACCOUNT	IMPLICATION FOR AUDITING
2012: secrecy	Recovery of vote order in the simulated election by exploiting pseudorandom generation used in the RDV. [4]	Verify secrecy protection, randomness sources and correlation opportunities.
2017: software integrity	Keys embedded in code and unauthenticated libraries enabled injected code execution in the studied setting. [5]	Assess keys, media, loading and installation together; verify versions and fixes.
2018: investigation conditions	In the interview, Aranha describes few days for a large codebase, supervision, restrictions on notes and personal equipment, and time spent preparing the environment and completing forms. [42]	Formal event duration overstates usable time when administration and setup consume part of the window. Effective effort must be recorded.
Você Fiscal: study published in 2016	Photographs of result reports were compared with published results. For the 2014 experience, the authors report coverage of 1.6% of reports and 4.1% of votes. [43]	A citizen check of transmission and publication with measured coverage. It does not reconstruct every choice from a record independent of machine software.

In the same 2018 interview, Aranha noted that development continued between testing and the following election. Engineering inference: confidence in a version must be reassessed when code, dependencies or configuration change; this requires change comparisons and regression testing. [42]

On a possible departure because of restrictions: the consulted sources document participation, findings and criticism but do not establish that he left a particular project for that reason. We do not attribute that motive without an identifiable account. This section focuses on dated technical evidence and described restrictions.

03 / What the tests found
2009 · first edition: historical reference
2012 · vote order and secrecy

Aranha and colleagues showed a weakness in shuffling the Digital Vote Record: pseudorandom generation enabled vote order recovery in the tested setting. Correlating it with voter order threatens secrecy. This differs from demonstrating altered counts. The authors' slides also discuss access and time limits. [4]

2016 · discoveries reported in the edition's assessment
2017 → 2018 · code execution and retest

The investigators' paper describes cryptographic keys embedded in code and shared across machines. Signature verification flaws and libraries lacking complementary signatures enabled code execution in the controlled setting. Secrecy and integrity properties were compromised. The authors note that test conditions restricted the investigation. [5]

In the 2018 confirmation, TSE reported changes and mitigation of the identified paths. Key protection received a solution different from the group's initial proposal. Assessing the fix requires linking each finding to the modified version, reproduction procedure and retest result. The organizer's statement does not replace these artifacts. [26]

2019 · report and improvement opportunity
2021 → 2022 · retests and operational limitations
2023 → 2024 · boot, keys and support systems

The report lists seven alleged findings, five referred for confirmation. On UE2020, a laboratory device changed the bootloader between signature validation and execution, exposing a kernel decryption key: a concrete TOCTOU case. The reported fix unified media access and restricted module loading. There were also findings in BitLocker/SIS and JE-Connect. Modifying the bootloader does not amount to demonstrating election tampering. Adjustments and confirmation records were documented in the 15 to 17 May 2024 retest. [6]

2025 → 2026 · from interim report to final assessment

The Regulatory Committee's interim report records 109 submitted plans, 38 approved, 29 executed, six alleged findings and three recommended plans at that stage. These figures describe different stages. [7]

The Evaluation Committee's final report addresses four plans in the May 2026 confirmation:

09, JE-Connect dependencies: documentary analysis of vulnerable libraries; reference updates and removal of two libraries, verified during confirmation.
26, ZipSlip: insufficient path validation identified in code, without successful exploitation according to the committee; protection redesigned and assessed.
31, JE-Connect: unexpected interface closure after pressing ESC; stability fix confirmed.
33, SIS/GEDAI-UE: access to protected folders through the interface; considered resolved based on technical-team information, without a confirmation test.

The committee recommends environments representing different election stages. It says a single environment imposes unnecessary restrictions and recommends expanding technical documentation. [44]

Analysis: accepting an explanation, reviewing documents and repeating experiments have different evidential reach. Reports must identify the evidence supporting each conclusion; listing four plans does not mean four attacks were reproduced after fixes.

Other assessments · universities, Defense and result reports in 2022

Historical coverage: the eight TPS/TPU editions are identified, with deeper analysis where usable evidence was obtained. This is not an exhaustive inventory of all forensic examinations, academic reports, court requests or regional audits since 1996. Older editions do not automatically inherit 2026 rules.

External audit: contract, execution and scope

TRE-AL Contract 48/2022 covers examining and validating the organization, conduct and conclusion of the Integrity Test. It provides for observation on the preceding day and election day, a conclusive report and a statement of hours worked. [46]

Technical interpretation: that contractual object differs from reviewing source code, extracting firmware or physically examining the entire fleet. Assessing execution requires comparing the contract, plan, hours, reports, exceptions and evidence. Hiring an external company does not alone establish unrestricted autonomy or coverage of every component.

The national 2022 collection contains reports from both rounds. It is a source for examining local execution, not a ready-made national conclusion. This study does not consolidate all state reports. [30]

04 / Access windows, capacity and preservation
STAGE	TIME REFERENCE	TECHNICAL IMPLICATION
2026-cycle inspection	Advance access from 12 months before the election until compilation. [21]	Plan staffing, tools, critical modules, dependencies and version comparisons.
TPS 2025	Registration: 30 June to 18 July. Inspection: 6 to 17 October. Testing: 1 to 5 December 2025. [3]	Publish actual hours, staff, targets, restrictions, executed tests and achieved coverage; the schedule does not measure these outcomes.
Confirmation	13 to 15 May 2026. [3] [8]	Confirm the fixed test, recording conditions and the authors' presence.
Selection for election-day audits	The preceding day, 7 am to noon. First round: 3 October; second round: 24 October 2026. [1] [9]	Examine choices, random draws, eligibility and replacements.
Voting	4 October 2026 and a possible second round on 25 October. [9]	Preserve collected BUs and record incidents with precinct, time and evidence.
Post-election request	Article 51: up to five days before the seal-retention deadline. [1]	Present facts, indications and a work plan; request preservation when necessary. Do not wait for reformatting.
Ordinary preservation	Voting machines and specified media: until 12 January 2027 under Article 272, with exceptions. [16]	A retention period is neither a promise of full forensic examination nor a single deadline for every legal action.
The cost of reviewing every line

Line counts do not measure security. A review must define the trusted computing base: application, kernel, libraries, compiler, firmware, cryptographic components and generation tools. Unexecuted code, duplication and generated code change the denominator. Estimating hours per line without a method and inventory would be speculative.

A useful approach is to publish an SBOM, pinned versions, provenance and transitive dependencies, and perform interface testing, static and dynamic analysis, fuzzing, cryptographic review and build reproduction. These are recommendations, not claims that none are practiced.

After installation

There is a gap between verification and use, the problem known as time-of-check to time-of-use (TOCTOU). The security argument must explain what prevents or reveals changes during that interval, including maintenance, transport, opening and equipment replacement.

Who produces the measurement also matters. A verifier running on a compromised platform may depend on the same root of trust it seeks to assess. This requires analysis of the actual architecture; it does not imply every hash check is ineffective.

Educational sampling simulator
Sample n
Hypothetical affected rate (%)
CHANCE OF INCLUDING AT LEAST ONE AFFECTED UNIT
28,23%

Illustrative model: P = 1 − (1 − p)n, with independent selections (or a large-population approximation) and perfect detection when an affected unit is selected. It does not estimate Brazilian election security. Sampling without replacement requires a hypergeometric distribution; stratification, exclusions and test-aware attacks change the analysis. Including an affected unit does not always imply detecting the flaw.

05 / Possible attacks, conditions and evidence gaps
THREAT CLASS	CONDITIONS TO DEMONSTRATE	DESIRED CONTROL AND EVIDENCE
Malicious source or dependency	Entry into the development chain, insufficient review or compromised provenance.	Third-party review, provenance, pinned versions, SBOM and reproducible builds. A signature alone also authenticates an authorized defect.
Replaced binary or media	Ability to produce accepted content or bypass verification.	Signatures, key protection, load-time validation, version records and negative tests.
Physical / firmware implant	Access to the device or manufacturing and ability to survive inspections.	Model/batch inspection, chain of custody, supervised opening and firmware assessment. Equipment age alone does not prove this threat.
Software recognizing a test environment	A distinguishable signal and control of the code that uses it.	Reduce observable differences; document randomization and limits. This is a threat hypothesis, not a malicious mechanism found in this study.
Electromagnetic / acoustic emissions	Physical coupling, signal, range and measurable relation to relevant data. In RAMBO, preexisting malware generates radio signals through the RAM bus. [12]	Side-channel tests on a specific model. The external receiver needs no internet connection to capture data; the experiment assumes prior compromise.
Attack on a switched-off device	A still-powered subsystem, implant or coupled energy, and a compatible vulnerability.	Measure actual power states and interfaces. Document network disconnection separately from absence of electrical power.
Incorrect aggregation/publication	Discrepancies in receipt, processing, inclusion or summation of results.	Reconstruct totals from independently collected BUs; verify signatures, pending items and coverage.

These classes form a threat model. Concrete Brazilian-machine examples appear in historical research; untested hypotheses do not receive the same status. [5] [6] [28]

06 / Paper records: requirements beyond the printer

The illustrated flow, with verification through a window and automatic deposit in a sealed container, avoids giving the voter a readable receipt of their vote. This removes one way to present a receipt to others. It does not eliminate every risk of coercion, order linkage, printing errors or record substitution or loss.

The technical benefit

Physical evidence actually verified by voters may enable outcome verification even if voting software is wrong. That is the goal of software independence. End-to-end cryptographic verification is another research direction; the property is not limited to paper. [13] [29]

An RLA limits the probability of ending an audit without correcting a wrong outcome, under its assumptions. The risk limit is not a probability of fraud. Sample size depends on the margin, method, observed errors and electoral rule; it may reach a full count. [14]

What needs to be designed

Accessible verification; rejection and correction of mismatched printouts; jam handling; readable text; no voter identification; protection against order reconstruction; reconciliation of issued, canceled and deposited records; seals and inventories; observed storage; public random draws; adjudication and recounts.

Appel and colleagues warn that voters do not always verify or notice changes in machine-produced records. Rates observed abroad should not be transferred to Brazil, but usability must be tested. [15]

Protected bags, banknotes and envelopes resist tampering or leave traces. Calling them tamper-proof requires an absolute guarantee they do not provide. Authentic paper may also contain an incorrectly printed vote.

The illustration proposes an architecture; it does not describe current Brazilian procedures or assess legal feasibility, budgets or implementation schedules. For the electronic machines discussed here, printing a BU is not printing each vote for individual verification.

07 / Models and distribution: missing evidence

The announced 2026 inventory lists UE2013, UE2015, UE2020 and UE2022. UE2020 and UE2022 total 439,468 units, or 77.9% of the announced 563,910. This is our calculation from source quantities, not a measurement of deployed equipment. [9]

The technical table distinguishes memory, processor and cryptographic boundaries. UE2013/UE2015 and UE2020/UE2022 should not be treated as identical hardware. Nor should a flaw in one generation be assumed to affect another without examining its implementation. [10] Documents plan replacement of UE2013 and UE2015 starting in 2028. [31]

Assessing the regional hypothesis would require data by election → round → state → electoral zone → precinct → machine number → model → version/hash → replacement. This study did not obtain a complete nationwide precinct-level inventory for 2026. It therefore does not provide a colored map suggesting an unmeasured distribution.

Comparing models with voting patterns would also require controlling for urbanization, income, location and electorate composition. Nonrandom equipment distribution can produce demographic correlations; correlation between model and political preference does not identify fraud.

08 / Method, independence and limitations

Authorship and scope: ALAS TECHNOLOGY gathers and analyzes published sources, organizes the technical synthesis and creates the illustrations. Cited experiments were conducted by the authors identified in each reference. This material is neither a forensic expert report nor a security certification.
Nonpartisan position: The content neither supports nor challenges a government, party, candidate or winner. The same criteria apply to any result. Research independence is assessed through access, methodological autonomy, reproducibility, disclosure of conflicts of interest and freedom to report findings, not merely institutional identity.

Rules and test notices establish permissions and procedures, not proof of invulnerability. Researcher reports and papers characterize findings. Statements by TSE, Defense, TCU and universities are identified as institutional accounts with limited scope. Institutional authority, supportive or critical, does not replace reproducible evidence.

The consolidated text applicable to 2026 was used, considering the 2024 and 2026 amendments. No hardware tests, code inspection, exploit reproduction or election forensic examination were performed. We do not claim review of all state reports or historical audits. The analysis includes the 2025/2026 Evaluation Committee's final report. Review of the Regulatory Committee's final report and compendium, and consolidation of state reports, remain outside completed documentary coverage.

A team may find no flaw because a component is well protected, an attack is infeasible, conditions, time or access were insufficient, or the test did not exercise the relevant behavior. The cause must be established case by case. Not every negative result can be attributed to restrictions, nor can it prove the absence of vulnerabilities.

Editorial conclusion: criticizing auditability limits is technically legitimate. Alleging vote tampering, asserting invulnerability or promising zero risk requires evidence this review does not provide.

What was checked and what remains open

The 16 September 2026 review checked core statements against cited references, distinguished current from repealed provisions and recalculated fleet percentages. It is neither a guarantee of error-free content nor independent validation of the experiments.

TOPIC	CHECKED BASIS	LIMIT OF THE CONCLUSION
Permissions, random draws and deadlines	Consolidated Resolution 23.673, TPS notice and calendar.	A regulatory provision does not demonstrate execution at each location.
Announced fleet	29,377 + 95,065 + 222,323 + 217,145 = 563,910. 2020 and 2022 models: 77.9%.	Announced inventory, without a nationwide precinct-level map.
Historical findings	Research papers and reports identified by edition.	ALAS TECHNOLOGY did not reproduce the attacks.
RAMBO and AI	Researchers' publications, Anthropic's report and Mozilla's confirmation.	They do not demonstrate automatic applicability to Brazilian machines.
2025/2026 cycle	Calendar, Regulatory Committee interim report and Evaluation Committee final report.	Documentary acceptance and experimental retesting are distinct evidence; this analysis did not reproduce the tests.

Documentary scope is identified in the references. Reports for one edition, location or sample do not certify the whole fleet. National assessment of execution requires a matrix by state, round, unit, procedure, result and exception; this version does not provide that consolidation.

How to follow the process and request evidence

Consult your state's regional electoral court (TRE) for ceremony and audit notices. Public observation and participation as an oversight entity carry different permissions. For technical assessment, record the election, round, precinct, model, version, target, team, method, result and limitations.

Article 60 permits regional grouping for representativeness and agreed logistical exclusions. Article 60-A requires publication of selected machines and identification data. Article 61 permits observing transport. These records help assess continuity and coverage; they are not an exhaustive review of every unit. [1]

After voting, comparing precinct-collected BUs with published results checks correspondence. It is not a recount of independent records of each vote. Formal post-election oversight requests follow the resolution's requirements and deadlines. [1] [20]

Essential terms
BU: Boletim de Urna (machine result report)
Precinct totals, printed at the end of voting and also recorded digitally.
RDV: Registro Digital do Voto (Digital Vote Record)
Digital record of votes by office, without identifying voters by name.
Hash and digital signature
Enable file comparison and verification of authorized origin. Alone, they do not demonstrate correct logic.
Firmware and dependencies
Code close to hardware and system components such as libraries, drivers and build tools.
Chain of custody
Records of storage, access, transport and transfers of equipment or evidence.
Residual risk
Risk remaining after controls and tests, under the assessment's assumptions.
09 / Sources and verification trail

Slides identify sources by title. The numbers below organize the dossier references. Accessed: 16 September 2026. External links open the original document. Notes explain exactly how each source was used.

Search references by title, author or topic

45 references available.

[1]Resolução 23.673/2021, texto compilado ↗

Oversight rules. Consult current wording, excluding struck-out or repealed provisions. Alone, it does not establish execution at every location.

[2]Edital 10/2025: escopo do TPS/TPU ↗

Items 1.4 to 1.6, 7, 18.5 and 19.1: targets, exclusions, inspection and confirmation.

[3]Calendário do TPU 2025 ↗

Registration, inspection and execution in the 2025/2026 cycle. Planned dates are not actual hours used.

[4]Aranha et al.: Software Vulnerabilities in the Brazilian Voting Machine (2012) ↗

Researchers' own source: vote-order recovery and limits of the 2012 test.

[5]Aranha et al.: The Return of Software Vulnerabilities in the Brazilian Voting Machine (2019) ↗

Paper on the 2017 test: keys in code and unauthenticated libraries. A historical finding, not a diagnosis of the 2026 version.

[6]TPS 2023 / confirmação 2024: relatório técnico ↗

Pages 33 to 35: findings, conditions and fixes. A plan's name expresses its objective, not necessarily its result.

[7]TPU 2025: relatório parcial da Comissão Reguladora ↗

Interim report: 29 executed plans; 6 alleged findings; 3 plans recommended at that stage.

[8]Confirmação de maio de 2026: relato institucional ↗

Reports four tests selected for confirmation and validated improvements. Institutional communication, not independent test reproduction.

[9]Inventário anunciado para 2026: TSE ↗

563,910 machines announced; not a verified precinct-level deployment inventory. The text says 77%; the published quantities yield 77.9%.

[10]Configurações técnicas dos modelos ↗

Official specifications distinguishing hardware, memory, processors and cryptographic boundaries.

[12]Guri: RAMBO: Leaking Secrets from Air-Gap Computers (2023/2024) ↗

Research presented at NordSec 2023, with a preprint deposited in 2024. Demonstrates exfiltration through memory-bus emissions from an isolated, previously compromised computer, received remotely by radio.

[13]Rivest e Wack: On the Notion of Software Independence in Voting Systems (2006) ↗

2006 conceptual paper: undetected software changes must not cause undetectable changes to the outcome.

[14]Ottoboni et al.: Bernoulli Ballot Polling (2018) ↗

Statistical auditing method for physical records; not the design of Brazil's Integrity Test.

[15]Appel, DeMillo e Stark: Ballot-Marking Devices Cannot Ensure the Will of the Voters (2020) ↗

2020 paper: voter verification failures in ballot-marking devices. Evidence from other systems, not a measurement of a Brazilian design.

[16]Resolução 23.751/2026: atos gerais ↗

Article 272: preservation until 12 January 2027, with exceptions and specific procedures.

[17]Portaria 273/2026: lacres e envelopes ↗

Numbered seals, security materials and production by Casa da Moeda. Tamper evidence, not invulnerability.

[18]Ministério da Defesa: limitações relatadas em 2022 ↗

Oversight participant's account: over 17 million lines and access restrictions. The same statement says it did not identify fraud; it is not an independent count of 2026 code.

[19]Unicamp: escopo e conclusões de 2022 ↗

University statement on three months of analysis, with conclusions limited to examined topics. Institutional cooperation offers access different from TPS and ordinary oversight.

[20]TCU: comparação de 4.161 BUs em 2022 ↗

Audit of correspondence between result reports and publication. Not a recount of individual voter intent.

[21]Resolução 23.728/2024: alterações da fiscalização ↗

Changes preparation sampling to up to 6%, retains extraction restrictions and regulates subsequent checks.

[22]Portal de documentos e edições do TPS/TPU ↗

Index of eight editions: 2009, 2012, 2016, 2017, 2019, 2021, 2023 and 2025. The page includes statistics and texts from different periods.

[23]TPS 2016: reconhecimento de vulnerabilidades ↗

Preliminary institutional assessment acknowledging discoveries; it does not detail complete exploitation.

[24]TPS 2019: divulgação do relatório ↗

Announcement and access to the edition's report; absence of demonstrated compromise must not be confused with universal proof.

[25]TPS 2021 / confirmação 2022: resultados ↗

Reports 29 plans, five with relevant findings and retesting in May 2022.

[26]Confirmação de 2018: resposta aos achados de 2017 ↗

Fixes and mitigation described by the organizer; includes Aranha's observations on changes to key protection.

[27]USP e colaboradores: análise técnica de alegações em 2022 ↗

Researchers' text with access to the report and tutorials. Describes access to code, binaries and equipment under a specific collaboration.

[28]Halderman et al.: You Go to Elections with the Voting System You Have (2008) ↗

Research on media-based threats and deployed-system limits; it does not demonstrate exploitation of a current Brazilian machine.

[29]Benaloh et al.: End-to-End Verifiability (2015) ↗

Cryptographic alternative: verify inclusion and counting while preserving secrecy. Depends on protocol, implementation and usability, not just digital signatures.

[30]Relatórios de integridade de 2022 ↗

Repository of reports from both rounds. Its existence does not mean every report was reviewed in this study.

[31]Consulta de aquisição para 2028 ↗

Document plans UE2013 and UE2015 replacement starting in 2028; procurement planning is not completed deployment.

[32]TPS 2019: relatório técnico detalhado ↗

Describes SIS/GEDAI access, insider-attack conditions, modified data and remaining barriers.

[33]TPS 2019: relatório da Comissão Avaliadora ↗

Scope, group-specific results, barriers and recommendations.

[34]Feldman et al.: Security Analysis of the Diebold AccuVote-TS Voting Machine (2007) ↗

US AccuVote-TS study: physical-access and media attacks, propagation and consistency of tampered records. Not a Brazilian-machine test; informs threat classes and methodology.

[35]Reproducible Builds: Increasing the Integrity of Software Supply Chains (2021) ↗

Research on verifiable correspondence between source and binary artifacts, including the environment and build chain.

[36]National Academies: Securing the Vote, 2018 ↗

Multidisciplinary scientific report. Recommendations 5.5 to 5.10 cover processes, registration, voting, results and post-election auditing. US context; it does not establish Brazilian conditions.

[37]Reproducible Builds: critérios de reprodução ↗

Project's technical reference: rebuilding identical artifacts from the specified source and environment.

[38]Anthropic: ANT-2026-CM0TCREP: Linux / CVE-2026-43074 (2026) ↗

Primary account of Claude-assisted discovery, human triage and a Linux use-after-free fix; introduction dated to July 2025.

[39]Mozilla: Hardening Firefox with Anthropic’s Red Team (2026) ↗

The maintainer confirms verifiable bugs identified with AI assistance and reproducible tests.

[40]Anthropic: LLM-discovered 0 days (2026) ↗

Report of previously unidentified flaws in open-source projects, some long-standing. Age and scope depend on each finding.

[41]Diego F. Aranha: Electronic Voting in Brazil (eVotingBR) ↗

Researcher's page: publications, project and presentations on Brazilian electronic voting security.

[42]Diego Aranha: entrevista ao WeLiveSecurity sobre limites dos testes (2018) ↗

Participant's direct testimony, published on 17 October 2018. Restrictions described in that context, without automatic extrapolation to 2026.

[43]Aranha, Ribeiro e Paraense: Crowdsourced integrity verification of election results (2016) ↗

Você Fiscal study: distributed comparison of result-report photographs with published 2014 results; coverage and method limits.

[44]TPS 2025/2026: Relatório Final da Comissão Avaliadora ↗

Sections 2 and 3: plans 09, 26, 31 and 33; confirmation methods and environment recommendations.

[45]TPS 2021/2022: Relatório Final da Comissão Avaliadora ↗

Sections 2 and 3: findings, retests, operational measures and documentation of barriers.

[46]TRE-AL: Contrato 48/2022 de auditoria externa ↗

Clauses one, two and four: contracted scope, observation, reporting and hours recorded.

ALAS TECHNOLOGY · Voting in Brazil · Nonpartisan documentary study and explanatory illustrations.
Retain caveats and references when adapting the carousel. The dossier forms part of the evidence supporting the images.

- [Resolução 23.673/2021, texto compilado](https://www.tse.jus.br/legislacao/compilada/res/2021/resolucao-no-23-673-14-de-dezembro-de-2021): Oversight rules. Consult current wording, excluding struck-out or repealed provisions. Alone, it does not establish execution at every location.
- [Edital 10/2025: escopo do TPS/TPU](https://www.tse.jus.br/eleicoes/arquivos/edital-2025): Items 1.4 to 1.6, 7, 18.5 and 19.1: targets, exclusions, inspection and confirmation.
- [Calendário do TPU 2025](https://www.tse.jus.br/eleicoes/arquivos/anexo-edital-tpu): Registration, inspection and execution in the 2025/2026 cycle. Planned dates are not actual hours used.
- [Aranha et al.: Software Vulnerabilities in the Brazilian Voting Machine (2012)](https://www.usenix.org/sites/default/files/conference/protected-files/aranha_evt12_slides.pdf): Researchers' own source: vote-order recovery and limits of the 2012 test.
- [Aranha et al.: The Return of Software Vulnerabilities in the Brazilian Voting Machine (2019)](https://dfaranha.github.io/publication/aranhabcam19/): Paper on the 2017 test: keys in code and unauthenticated libraries. A historical finding, not a diagnosis of the 2026 version.
- [TPS 2023 / confirmação 2024: relatório técnico](https://www.justicaeleitoral.jus.br/tps/arquivos/2023/documentos/relatorio-avaliacao-geral-TPS-Teste-de-confirmacao.pdf): Pages 33 to 35: findings, conditions and fixes. A plan's name expresses its objective, not necessarily its result.
- [TPU 2025: relatório parcial da Comissão Reguladora](https://www.tse.jus.br/eleicoes/arquivos/relatorio-parcial-da-comissao-reguladora/@@display-file/file/relatorio-parcial-da-comissao-reguladora.pdf): Interim report: 29 executed plans; 6 alleged findings; 3 plans recommended at that stage.
- [Confirmação de maio de 2026: relato institucional](https://www.tse.jus.br/comunicacao/noticias/2026/Maio/eleicoes-2026-testes-confirmam-mais-uma-vez-a-seguranca-do-sistema-eleitoral-brasileiro): Reports four tests selected for confirmation and validated improvements. Institutional communication, not independent test reproduction.
- [Inventário anunciado para 2026: TSE](https://www.tse.jus.br/comunicacao/noticias/2026/Agosto/veja-os-modelos-de-urna-que-serao-utilizados-nas-eleicoes-gerais-2026): 563,910 machines announced; not a verified precinct-level deployment inventory. The text says 77%; the published quantities yield 77.9%.
- [Configurações técnicas dos modelos](https://www.justicaeleitoral.jus.br/urna-eletronica/informacoes-tecnicas.html): Official specifications distinguishing hardware, memory, processors and cryptographic boundaries.
- [Guri: RAMBO: Leaking Secrets from Air-Gap Computers (2023/2024)](https://arxiv.org/abs/2409.02292): Research presented at NordSec 2023, with a preprint deposited in 2024. Demonstrates exfiltration through memory-bus emissions from an isolated, previously compromised computer, received remotely by radio.
- [Rivest e Wack: On the Notion of Software Independence in Voting Systems (2006)](https://www.nist.gov/system/files/si-in-voting.pdf): 2006 conceptual paper: undetected software changes must not cause undetectable changes to the outcome.
- [Ottoboni et al.: Bernoulli Ballot Polling (2018)](https://arxiv.org/abs/1812.06361): Statistical auditing method for physical records; not the design of Brazil's Integrity Test.
- [Appel, DeMillo e Stark: Ballot-Marking Devices Cannot Ensure the Will of the Voters (2020)](https://collaborate.princeton.edu/en/publications/ballot-marking-devices-cannot-ensure-the-will-of-the-voters/): 2020 paper: voter verification failures in ballot-marking devices. Evidence from other systems, not a measurement of a Brazilian design.
- [Resolução 23.751/2026: atos gerais](https://www.tse.jus.br/legislacao/compilada/res/2026/resolucao-no-23-751-de-26-de-fevereiro-de-2026): Article 272: preservation until 12 January 2027, with exceptions and specific procedures.
- [Portaria 273/2026: lacres e envelopes](https://www.tse.jus.br/legislacao/compilada/prt/2026/portaria-no-273-de-1o-de-junho-de-2026): Numbered seals, security materials and production by Casa da Moeda. Tamper evidence, not invulnerability.
- [Ministério da Defesa: limitações relatadas em 2022](https://www.gov.br/defesa/pt-br/centrais-de-conteudo/relatorio-das-forcas-armadas-nao-excluiu-a-possibilidade-de-fraude-ou-inconsistencia-nas-urnas-eletronicas): Oversight participant's account: over 17 million lines and access restrictions. The same statement says it did not identify fraud; it is not an independent count of 2026 code.
- [Unicamp: escopo e conclusões de 2022](https://www2.unicamp.br/unicamp/noticias/2022/08/25/unicamp-usp-e-ufpe-chancelam-seguranca-das-urnas-eletronicas/): University statement on three months of analysis, with conclusions limited to examined topics. Institutional cooperation offers access different from TPS and ordinary oversight.
- [TCU: comparação de 4.161 BUs em 2022](https://portal.tcu.gov.br/imprensa/noticias/tcu-finaliza-analise-de-boletins-de-urna-do-1%C2%BA-turno-das-eleicoes): Audit of correspondence between result reports and publication. Not a recount of individual voter intent.
- [Resolução 23.728/2024: alterações da fiscalização](https://www.tse.jus.br/legislacao/compilada/res/2024/resolucao-no-23-728-de-27-de-fevereiro-de-2024): Changes preparation sampling to up to 6%, retains extraction restrictions and regulates subsequent checks.
- [Portal de documentos e edições do TPS/TPU](https://www.tse.jus.br/eleicoes/tpu): Index of eight editions: 2009, 2012, 2016, 2017, 2019, 2021, 2023 and 2025. The page includes statistics and texts from different periods.
- [TPS 2016: reconhecimento de vulnerabilidades](https://www.tse.jus.br/imprensa/noticias-tse/2016/Marco/ministro-dias-toffoli-faz-balanco-sobre-o-teste-publico-de-seguranca-2016): Preliminary institutional assessment acknowledging discoveries; it does not detail complete exploitation.
- [TPS 2019: divulgação do relatório](https://www.tse.jus.br/comunicacao/noticias/2019/Dezembro/relatorio-final-do-tps-2019-ja-esta-disponivel-para-consulta): Announcement and access to the edition's report; absence of demonstrated compromise must not be confused with universal proof.
- [TPS 2021 / confirmação 2022: resultados](https://www.tse.jus.br/comunicacao/noticias/2022/Maio/tps-2021-comissao-avaliadora-divulga-relatorio-final): Reports 29 plans, five with relevant findings and retesting in May 2022.
- [Confirmação de 2018: resposta aos achados de 2017](https://www.tse.jus.br/comunicacao/noticias/2018/Maio/tse-conclui-teste-publico-de-seguranca-do-sistema-eletronico-de-votacao): Fixes and mitigation described by the organizer; includes Aranha's observations on changes to key protection.
- [USP e colaboradores: análise técnica de alegações em 2022](https://jornal.usp.br/artigos/alegacoes-sobre-falhas-nas-urnas-eletronicas-nao-tem-fundamentacao-e-rigor-tecnico/): Researchers' text with access to the report and tutorials. Describes access to code, binaries and equipment under a specific collaboration.
- [Halderman et al.: You Go to Elections with the Voting System You Have (2008)](https://www.usenix.org/legacy/events/evt08/tech/full_papers/halderman/halderman_html/): Research on media-based threats and deployed-system limits; it does not demonstrate exploitation of a current Brazilian machine.
- [Benaloh et al.: End-to-End Verifiability (2015)](https://arxiv.org/abs/1504.03778): Cryptographic alternative: verify inclusion and counting while preserving secrecy. Depends on protocol, implementation and usability, not just digital signatures.
- [Relatórios de integridade de 2022](https://www.tse.jus.br/eleicoes/eleicoes-2022/testes-de-integridade-relatorios-referentes-ao-1o-e-2o-turnos): Repository of reports from both rounds. Its existence does not mean every report was reviewed in this study.
- [Consulta de aquisição para 2028](https://sintse.tse.jus.br/documentos/2025/Nov/27/diario-oficial-da-uniao-secao-3-tse/edital-de-consulta-publica-no-7-2025-comunica-que-sera-realizada-consulta-publica-com-o-objetivo): Document plans UE2013 and UE2015 replacement starting in 2028; procurement planning is not completed deployment.
- [TPS 2019: relatório técnico detalhado](https://www.justicaeleitoral.jus.br/tps/arquivos/tps_2019_relatorio_tecnico_atualizado_17_12_2019.pdf): Describes SIS/GEDAI access, insider-attack conditions, modified data and remaining barriers.
- [TPS 2019: relatório da Comissão Avaliadora](https://www.justicaeleitoral.jus.br/tps/arquivos/tps_2019_relatorio_final-atualizado_17_12_2019.pdf): Scope, group-specific results, barriers and recommendations.
- [Feldman et al.: Security Analysis of the Diebold AccuVote-TS Voting Machine (2007)](https://www.usenix.org/legacy/events/evt07/tech/full_papers/feldman/feldman.pdf): US AccuVote-TS study: physical-access and media attacks, propagation and consistency of tampered records. Not a Brazilian-machine test; informs threat classes and methodology.
- [Reproducible Builds: Increasing the Integrity of Software Supply Chains (2021)](https://arxiv.org/abs/2104.06020): Research on verifiable correspondence between source and binary artifacts, including the environment and build chain.
- [National Academies: Securing the Vote, 2018](https://people.csail.mit.edu/rivest/pubs/NASEM18.pdf): Multidisciplinary scientific report. Recommendations 5.5 to 5.10 cover processes, registration, voting, results and post-election auditing. US context; it does not establish Brazilian conditions.
- [Reproducible Builds: critérios de reprodução](https://reproducible-builds.org/docs/plans/): Project's technical reference: rebuilding identical artifacts from the specified source and environment.
- [Anthropic: ANT-2026-CM0TCREP: Linux / CVE-2026-43074 (2026)](https://red.anthropic.com/2026/cvd/findings/ANT-2026-CM0TCREP): Primary account of Claude-assisted discovery, human triage and a Linux use-after-free fix; introduction dated to July 2025.
- [Mozilla: Hardening Firefox with Anthropic’s Red Team (2026)](https://blog.mozilla.org/en/firefox/hardening-firefox-anthropic-red-team/): The maintainer confirms verifiable bugs identified with AI assistance and reproducible tests.
- [Anthropic: LLM-discovered 0 days (2026)](https://www.anthropic.com/research/zero-days): Report of previously unidentified flaws in open-source projects, some long-standing. Age and scope depend on each finding.
- [Diego F. Aranha: Electronic Voting in Brazil (eVotingBR)](https://dfaranha.github.io/project/evotingbr/): Researcher's page: publications, project and presentations on Brazilian electronic voting security.
- [Diego Aranha: entrevista ao WeLiveSecurity sobre limites dos testes (2018)](https://www.welivesecurity.com/br/2018/10/17/diego-aranha-os-testes-de-seguranca-nas-urnas-eletronicas/): Participant's direct testimony, published on 17 October 2018. Restrictions described in that context, without automatic extrapolation to 2026.
- [Aranha, Ribeiro e Paraense: Crowdsourced integrity verification of election results (2016)](https://dfaranha.github.io/publication/aranharp16/): Você Fiscal study: distributed comparison of result-report photographs with published 2014 results; coverage and method limits.
- [TPS 2025/2026: Relatório Final da Comissão Avaliadora](https://www.tse.jus.br/eleicoes/arquivos/tpu-relatorio-final-da-comissao-avaliadora/@@display-file/file/Final-Relatorio-Comissao-Avaliadora.pdf): Sections 2 and 3: plans 09, 26, 31 and 33; confirmation methods and environment recommendations.
- [TPS 2021/2022: Relatório Final da Comissão Avaliadora](https://www.justicaeleitoral.jus.br/tps/arquivos/2021/relatorio-da-comissao-avaliadora-2021.pdf): Sections 2 and 3: findings, retests, operational measures and documentation of barriers.
- [TRE-AL: Contrato 48/2022 de auditoria externa](https://static.tre-al.jus.br/portal/transparencia/contratacoes/contratos/2022/contrato_482022.pdf): Clauses one, two and four: contracted scope, observation, reporting and hours recorded.