r/linux • u/ForsetiJusto • 12h ago
Popular Application Brazil election - 560K devices, the most fast e electronic election
812
u/Schudz 12h ago edited 12h ago
for those unsure about its security, take 5 min of your time and google how it works, thats way more secure than couting votes manually, and the system was NEVER hacked.
it doesnt have internet connection, doesnt have any chip for wireless\bluetooth, votes are stored on a removable drive that breaks a seal when removed and must match its id and encryption for vote processing. it emmits a sum of votes at the of the day that anyone can check.
its impossi le to hack without breaking into it, and if you do break into it it has redundant systems to invalidate the machine and make it useless.
it goes through public testing before and after the votes, theres a whole process to ensure its safety.
brazil is not a perfect place, and theres a ton of issues with our democracy, but the voting machines are not the problem.
125
u/mr_wetape 12h ago
There are people from all parties in the voting sites. In small cities they just wait for the closing of the voting machines and the printing of the votes of each session and sum the votes themselves. It takes 40 minutes for them to have an unofficial result, counting that it takes 30 minutes for closing the results, validating the encryption, sealing the disk and printing and putting the result in the entrance of the voting site.
→ More replies (28)45
u/ConceptualDrawing 10h ago
I will add this: This works so well that some candidates want to end electronic voting because they are unable to manipulate the results.
→ More replies (1)37
u/ArtisticFox8 12h ago
Is the code for these open source?
101
u/Calico_Shortcake 12h ago
More or less. You can fill a request to participate in the security checks open to the public. Then, you can read the code and try to discover insecurities. But there is not a repository over the internet where you can check the code anytime.
89
u/Darkblade_e 12h ago
Pretty sure this is considered "source available", not open source. The difference being that I assume there's no license in the repo that grants the user who gets the code the right to modify and redistribute. Regardless source available is still substantially better than a lot of cases, and it's close enough for anyone who wants to just audit the code
→ More replies (1)5
u/funforgiven 3h ago
If the code is actually licensed under an open-source license, then the lack of a public repository doesn't make it source available. Open source doesn't require the source to be publicly browsable at all times. The important question is whether people who obtain the source receive the license rights to use, modify, and redistribute it, rather than merely being allowed to inspect it for an audit.
32
u/zeppelin88 11h ago
They also host competitions and invite researchers to try to break it.Ā
If I remember well, they were able to break stuff every once in a while, but always in a scenario that is not realistic (e.g., would take more than a day)
31
u/Calico_Shortcake 11h ago
I remember that researchers once proved that the random generator and the votes scrambling system were not perfect, so you could theoretically know the order of votes cast.
It was such a specific scenario that it could not be exploited in practice.
Regardless, the electoral agency and court (TSE) have reworked the entire module to fix the problem.15
u/Jaded_Court_6755 10h ago
One of the researchers that found some vulnerabilities have a website where he discloses them. His name is āDiego Aranhaā. Heās a redditor as well and sometimes replies to messages mentioning his name. I donāt remember his username though!
2
u/Sad-Magazine4159 10h ago
It wasnt hard to exploit at all, given you have the scrambled record, the scrambling were based on a pseudo random number seeded from the machine boot time, which is easily available.
To be honest, this is a very naive implementation for such critical system, Diegos team found it in very restricting conditions, which make me think what else could be found if one had the oportunity to really dig deep into the code?
3
u/Logical-Volume9530 8h ago
Either way, the proposed alternative of paper ballots is way worse. So fucking worse with so many more problems it's ridiculous even as a proposition.
2
u/Sad-Magazine4159 8h ago
If youre talking about printed voting, it is a very different thing
But regardless, I dont expect engineer working on a critical system like this to take such mistakes, this is something a mid level engineer should know.Ā
2
u/GoatsFromUnderground 9h ago
It's also part of the process that makes it secure. Countries that don't have those competitions have machines that can be hacked in to. Countries that do have those competitions get it proven to everyone just how hard it is to hack them, because any hacks that get discovered along the way get patched. Light is the best disinfectant.
18
u/ArtisticFox8 11h ago
How would you check that code provided to you is the same as the code on the device?
33
u/Calico_Shortcake 11h ago
I have responded to this question to someone on this post. But a summary:
Before the election starts, a representative amount of machines is selected at random to be collected from the voting areas.
A group of representatives performs a series of checks both on hardware and software to check whether it matches the approved digital signature of the official voting system.
This procedure is accompanied by representatives of diverse political parties, volunteers, judges, and many more people.
This is an official page from the Brazilian State, that describes one of the procedures. Besides this one, there are practical tests to cast varied votes on the machine and check if the amounts match. This is all done as a blind test.
22
u/backwards_watch 11h ago
The compilation is done publicly. There is a cerimony that builds the software where people have access to the binnary hashes and its digital signature. When the hardware goes to the public, it performs a series of checks that need to mach the compiled binnary.
The trust comes from this public verifiable compilation event, plus with the physical locks that hides the chips inside, which would be evidence of it being mechanically violated.
→ More replies (5)5
u/theunsignedone 9h ago edited 8h ago
I don't think thats the only safety measure. It has been a while I read about this, but I'm pretty sure the machine prints a hash/digital signature of the code used on it and you can request to validate this if you suspect anything. Also the hash of all machines should match since its the same code.
So you would have to tamper a machine and make it print the valid hash, not impossible but there are people with eyes on the machines all the time, its very inconvenient.
The best way to fraud an election in Brasil is with fake news and manipulation, thats WAY more effective than compromising a few machines and risking being caught.
10
u/Miserable_Initial732 11h ago
That doesn't sound like open source at all
Why not fully open source it so everyone can check for vulnerabilities outside a controlled enviroment and without a government authority supervising the exercise?
9
u/Calico_Shortcake 11h ago
I also think it should be fully open source. Brazilian protocol of instant payment transfer (PIX) is fully open source.
https://github.com/bacen/pix-api
While the voting system is not totally open yet, independent and varied interested parties check it every election.
→ More replies (1)10
u/burgundus 10h ago
I'm Brazilian and in favor of opening the source code as well.
But there are some big practical and ethical implications on it.
What if they open the source code today, and within a week a bug is found. Will the last election be discarded? Should we invalidate all presidential terms since ___? I'm sure the losing part would try to do so.
Also it would require a full team to be reviewing community requests, discussing issues and accepting/rejecting patches. Nowadays the system is relatively stable.
Lastly, the hardware is built specifically for it too. Even though they could also release an Open hardware spec, it's not like anyone would be able to have their own voting machine
→ More replies (4)3
u/Wenir 10h ago
How bug found in open source code is different from the bug found by invited researchers or on competitions?
2
u/burgundus 10h ago
thats a good point.
Maybe because of the lack of propaganda (kind of security by obfuscation)
4
u/SimilarConfusion1836 10h ago
There is something I worry about open sourcing it fully. One of my worries: If the US with its mythos/fables/astras, finds a bug, would it tell the people or would it use this knowledge to fraud the election?
Right now, if you are a researcher, the army or member of a political party you can already audit the source code. They never found a real issue. If you wanna be sure there's no vulnerability you can volunteer yourself to audit it.
→ More replies (1)2
u/Little-Respond1765 9h ago
That's basically not open source though. Permissions based access underlies in obscurity as many mainstream software nowadays
2
u/CairesTieNdie 9h ago
Nah, and most of what people are saying its just BS.
The Army went to check on these and they complained that they didnt have enough time, because thats how that happens, 30million+ line codes....
→ More replies (14)7
u/ForsetiJusto 12h ago
once a year the vote department open a session only for hacker to try invade, none was success until today
9
u/foonek 11h ago
Which kind of reward are they giving for being successful? Not saying that's what's happening here but if the reward of hacking a device and being able to rig an election is greater than the reward of winning that public session, then that session is just for show
→ More replies (13)5
u/Jomgui 2h ago
A small correctionir got hacked quite a few times, but not DURING the election, the government basically opens a "contest" for certain universities and researches ro find problems with the system and then fix them.
It's in ironically one of the few things our government is serious about and acts really fast
55
u/VaporousMote 11h ago
"the system was never hacked" are the most famous last words in existence
25
u/HelpMyCatGotMyBalls 11h ago
Saying that the system was never hacked is incorrect. Several vulnerabilities were found and corrected over the years. Most of them were related to being able to figure out who voted for who, instad of changing voting numbers.
That said, the system has been broken into, the reason why the system is super safe is how these mavhines work. They have absolutily no external conecctions, so to hack one, you need to physicaly go to one machine, break into it, do yout thing and then somehow put it back in its place witout anyone noticing. And this is for one single machine. You cant atack many machines at once.
So to actualy compromise a significant amount of balots you would need an army of skilled hackers. Breaking into thousands of different sessions in complete secrecy.
Those that say that system is inpenetrable dont kmow what they are talking about. But it is simply impossible to do any real meddling without being discovered.
→ More replies (10)4
u/panda070818 9h ago
An important note about the "several vulnerabilities have been found and corrected over the years" They hire literal doctors, experts in subjects such as encryption, network and pentensting so they can try and hack this voting machines and fix vulnerabilities every 4 years period. To even attempt an attack you would need a lifetime of knowledge to even think of a vulnerability that they haven't found yet.
As of now, no incident report has been issued about any hacking or misuse of these voting machines.
2
u/VaporousMote 2h ago
An equally important note is that the US does this too (hire and consult an incredible variety of experts to secure elections), and that's why we have paper ballots.
7
u/Void_TK_57 11h ago
To be fair, he didn't say it "can't" or "never will" be hacked, just that was never hacked, and it was, indeed, never hacked
→ More replies (3)7
u/slinky3k 9h ago edited 9h ago
and it was, indeed, never hacked
As far as anyone knows. And not being detected would be the most important property of a successful hack in this realm.
There would have to be really strong guarantees that the system was specified properly and follows these specifications perfectly, aka being formally verified. With Linux on COTS hardware, that's impossible to do.
2
2
→ More replies (1)2
u/Poponildo 7h ago
Every year the losing parties try extensively to prove it was hacked, and noone has ever manage to prove anything, they always come to the same conclusion. We do not live in a dictatorship, every party is free to check and audit the whole election system (which is quite complex and full of redundancy, it goes way beyond the electric urn).
2
u/babyjesusisback2 8h ago edited 8h ago
Bro thinks everyone voting on paper (specially the ones living in the US) really connect A to B. Aren't these the same people who fail on most geography tests? Funny funny.
3
u/GL_S3_s3tc 3h ago edited 3h ago
I wish the source code was fully open, they say it's "open" but in reality it's only open to a specific set of people for a specific amount of time (IIRC, only educational institutions?) i don't understand why they don't just include their compiled binaries and source code and let anyone read and reproduce the software, in that case there would be no skeptics (unless of course they're just ignorant). It doesn't matter if there's WAN connectivity or whatever if there is something slipped in the OS itself...
Edit: Educational institutions, security researchers and officers are involved in the checking of the software. Would still much prefer it to be fully public but it's not trivial to bypass.
→ More replies (1)19
u/AtlanticPortal 11h ago
Unfortunately it lacks one single feature: the public understanding how it works. Itās a feature that with paper ballot is easy to provide.
4
u/backwards_watch 11h ago
This issue is solved by having both parties involved.
If you are running and you know that the other party will be able to check the code, you have enough incentive to send an expert yourself. You don't need to know how it works, you just need to trust that the person who will check it for you understands it.
4
u/LongestUsernameEverD 9h ago
This issue is solved by having both parties involved.
This is funny to me and probably not by the same reason as /u/PerfectEnthusiasm2
We've got dozens of parties, not just 2.
All parties have auditors across every single city.
→ More replies (6)6
u/PerfectEnthusiasm2 11h ago
This issue is solved by having both parties involved.
lmao, best joke I've seen all day.
→ More replies (6)10
u/ketoprom 11h ago
If the average person cannot understand why they should trust the system, it matters little how secure it actually is. If some elections were perfectly legit but half the country was convinced that there was fraud, then the elections were a failure. With electronic voting you're risking that scenario much more than if you used only paper ballots.
6
u/Schudz 11h ago
the average people dont understand how yo code in C. so open access would not do much for them, at the end of the day they would still relly on expert's opinions about it, which today is already possible, brazilian citizens experts can already access the source code.
→ More replies (7)5
u/Witty_Milk4671 10h ago
And if the elections were frauded but people believed it was legit, this creates a WAY bigger problem. A problem that your country doesn't have because it doesn't have insitutional fraud like brazil had.
→ More replies (15)16
u/sokratesz 9h ago
Still not as good as paper ballots.
→ More replies (4)5
u/rexyuan 9h ago edited 9h ago
Paper ballots also wonāt get bit flip by cosmic ray
→ More replies (5)6
u/sokratesz 9h ago
That, all all the touted redundancy and security is pointless when you can't go back and actually re count the ballots.
9
u/el_lley 9h ago
NEVER hacked⦠dude, they hacked it in like 5 minutes in 2014. Fortunately, it was during an open contest to everybody, so they have been improving it throughout the time.
8
u/sptzmancer 8h ago
Yeah, the machine was in front of the team and they had free access to the internals.
During electoral process each machine is escorted by armed forces and is never alone in a room for a minute without the police near it. They guard the machine during the whole night before and during the election.
And even if you manage to comprimise one of them, each machine has on average 300 votes. You would have to physically hack tens of thousands of machines in less than 24 hours to make a difference.
→ More replies (1)5
u/a3a4b5 9h ago
hacking contest to enhance security
it was hacked
surprised_pikachu.jpeg
→ More replies (1)→ More replies (10)4
u/hipster_dog 8h ago
I agree a single unit can absolutely be hacked, if you manage to get physical access to one, since they got no remote connection whatsoever.
But enough units to skew a presidential election? Very unlikely.
→ More replies (1)14
u/UnethicalApparatus 12h ago edited 12h ago
It probably also has security measures for that, but you missed everything that goes before running the machine. From the compiler to the flasher, you need to trust every piece of software and hardware involved. A malicious party (or the ruling party) could inject, and manipulate the elections using only the compiler.
And last I heard it also prints a paper with your vote, that you can confirm and cast. So in a last resource scenario those can be counted.No paper trail, but at least there is a mock election, done with random terminal.Edit: even the hardware selection is critical. Most readily available CPUs have a inner processor running code you dont control and can't audit.
9
u/the_bighi 12h ago
The voting machines arenāt directly set up by the ruling party. And some of them are randomly sampled for testing after loaded with the software.
→ More replies (10)9
u/holchansg 12h ago edited 11h ago
The code is audited from independent individuals, general public, anyone can subscribe to do it and there is representatives from all the political parties into the entire process.
https://international.tse.jus.br/en/electronic-ballot-box/auditability
There is even random blind picks on the machines and randomized blind trial.
Edit: No paper trail, but at least there is a mock election, done with random terminal.
There is paper trail. And they use it to manually cross check blind assigned.
→ More replies (23)→ More replies (4)4
u/Schudz 12h ago
yeah, theres that, but theres also so much more i left out, those machines are safer than airplanes, theres a bunch or redundant systems to make sure its unbreakable, and if it gets attacked its impossible not to know it were, so its pretty easy to investigate and replace the machine, although this was never recorded to happen
→ More replies (1)3
u/backwards_watch 11h ago
I believe there were some cases of violated machines. They are promptly replaced though.
Even today, there were a couple of cases at the south region of Brazil where some people put glue on the buttons and therefore it had to be replaced.
I don't know if the votes will be valid or not, it depends on the protocol. I hope they are, otherwise you could go around districts that you know will vote for your opponent and pay people to glue the machines.
→ More replies (1)5
u/Fidodo 10h ago
I'm fine with electronic voting machines with the requirement that they also produce a printed paper trail so they can be audited in case something seems off. Electronic voting machines in California print to paper and your can validate that your paper printout matches before you submit it.
6
u/Commercial-Taro-8187 10h ago
We have historical problems with the buying and persecution of voters because of their vote. An important part of the Brazilian system is the secret ballot.
2
u/Fidodo 10h ago
It's secret here too, the paper copy is sealed and doesn't have your name in it. Nobody sees it and even if they were to check it after you leave they would not know it belonged to you.
6
u/LongestUsernameEverD 9h ago
That we do have it here in Brazil.
Every machine prints the counts, has extensive information of how the voting went, and has several redundancies/checksums/etc in place to make it basically the kind of thing where, IF someone managed to break it in one place, everything else would become fucked up in one way or another, nothing would match, and everybody would know there is something off.
3
u/Fidodo 9h ago
That's good. I wasn't trying to claim Brazil didn't have it, just that a good electronic voting machine system should have it. That sounds legit! For some reason lots of other people here don't seem to understand that a paper trail does not have to be identifiable.
6
u/LongestUsernameEverD 9h ago
Oh no, I get it, you were clearly not speaking maliciously/being prejudiced, that's why you're the one non-confrontational reply I've got in this thread LOL
The vast of majority of the thread simply can't believe a supposedly third world country like Brazil has figured out something better than them and they're lashing out against us.
In the meantime, we literally meme about america and how long it takes, and the absolute vast majority of the people trust the system even if they don't understand it. Only folks that don't...are THOSE kind of people.
→ More replies (10)4
u/mulekitobrabod 10h ago
First, it already do that
Second, it don't give to you because we had something here called "coronelismo", we high power guys put people in front of voting stations for seeing if you vote for the right politician
So its REALLY important here the concept of secret voting and not having on you the vote
→ More replies (11)5
u/st945 9h ago
O que ele tÔ dizendo é que o comprovante do voto é impresso e a pessoa vê, mas ela não tem acesso à esse papel, não fica com ela. Portanto os votos individuais podem ser contados. No Brasil vc tem os totais por urna, é diferente.
→ More replies (1)3
u/a3a4b5 9h ago
No fim das contas, esse proposta de voto impresso que a pessoa vê dentro de uma capa de plÔstico transparente é a mesma coisa do boletim de urna que jÔ existe.
A validação do voto é digital, com biometria, e embaralhada pra ninguém saber quem votou em quem. A operação ainda é "usuÔrio u/st945 votou > candidato X recebeu +1 voto". Depois disso, embaralha pra não saber que foi você quem deu +1 no candidato X.
Adicionar um papel impresso no meio do caminho destrói a premissa secreta do voto. Uma coisa é você sair dizendo que votou em tal, outra é o sistema ter essa informação. Eu posso dizer pra todo mundo que votei 22, mas, na realidade, só eu e Deus sabemos que votei 13, por exemplo.
→ More replies (71)3
u/Jukibom 7h ago
even if this was somehow magically perfect:
- place a phone with scary looking terminal output next to it
- take a photo / video
- post online saying you wirelessly hacked it
congratulations, you just undermined the legitimacy of an election
3
u/Senedoris 5h ago
People who want to undermine legitimacy of elections will always find a way, electronic voting or not.
→ More replies (2)2
358
u/benjamarchi 12h ago
Hell yeah! I absolutely ADORE the sound this makes when you input your vote. This piece of tech makes me happy, it's extremely handy and useful!
80
u/Fun-Student197 12h ago
that little boot-up jingle is burned into my memory from family trips to the polling station. my parents would let me press the button to confirm their vote and i felt like i was launching a spaceship or something
always thought it was wild that they went with linux for these machines, but it makes perfect sense for something that needs to be locked down and auditable. the penguin on a voting terminal is such a flex honestly
brazil's been doing electronic voting longer than most countries and the whole system is weirdly satisfying to watch in action. the speed they count results after polls close still catches people off guard
→ More replies (3)22
u/tomei-ban-mas-voltei 10h ago edited 2h ago
Iām gonna register an official complaint with TSE: the sound of my voting machine was extremely low this election! I almost couldnāt hear the PI LI LI!
This a denial of my Brazilian constitutional rights! All we Brazilians wait the whole election to hear it and when the day comes itās like 10 decibels?!?!?
6
17
→ More replies (13)28
19
133
u/LucasZeppeliano 12h ago
For those who donāt know.
The Brazilian Vote Machine is completely offline. It stores data in diskette drives, and at the end of the day, authorized people take it to a place where all votes can be read and sent to the counting system.
→ More replies (18)97
u/PleaseDoNotMentionMe 12h ago
Just adding that diskette drives are no longer used for more than a decade, it has been long replaced with USB flashdrives.
Plus there are multiple layers of redundancy (there's also a printed report with signed checksums so data can be cross checked and more).
127
u/Head-Mud_683 12h ago
I see this as I wait my turn to vote. Proud of my country and proud of the electoral system we have.
"O Brasil não cabe no quintal de ninguém!"
→ More replies (32)
9
65
u/RoundManufacturer267 12h ago
BRASIL MENCIONADOš£š£š£š§š·š§š·š§š·š§š·š§š·šššššš
4
u/No-Fish-9989 9h ago
O mundo descobrindo que a tecnologia do Brasil Ć© evoluidissima.
Afinal aqui Ć© o paĆs que inventou o aviĆ£o, o rĆ”dio e o Pix.
→ More replies (5)
15
u/Agreeable_Back_6748 8h ago
People don't trust technology for voting, but trust for everything else. I don't get it.
8
u/Dry-Term7880 7h ago
Yeah me neither. People put all their money in digital banks but when it comes to a voting machine that looks like a typewriter they get all sci-fi about possible ways to tamper it
→ More replies (4)3
u/Sea-Presentation-173 5h ago
Because tech allows you to have very cheap traceability, but voting needs to be a protected secret.
This is one of those cases where speed is a very secondary objective. Transparency and effectiveness are the main goal.
4
u/JoJo_Embiid 5h ago
i think the main reason is you cannot verify. if your bank account has 100k less money you'll know.
if you vote for A but counted as B there is no way you will know
→ More replies (10)→ More replies (1)2
u/gravgun 4h ago edited 4h ago
Risk/benefit ratio. Things like banking and whatnot are still subject to regulation making so you don't completely get effed over most of the time.
Politics are the regulation, and can make your life meaningfully hell should the elected officials hate you enough. And those with enough hate are generally pretty motivated to not play by the rules and cheat the systems. Tech reduces the effort necessary to do so.
8
26
u/21p_ 12h ago edited 12h ago
In college i did a presentation about this specific matter (let me show off, i got a 9,5/10) and yes electronic voting can be secure and avoid fraud. I mentioned Brazil where it is like a digital ballot box so its not that different from normal voting, but you could vote 100% online through your smartphone like when you order uber eats and still be generally secure and consistent, they do that in Estonia
23
u/No-Dot4329 10h ago
Voting via smartphone in Brazil would not be safe at all. Given the Brazilian context, if a person voted from their home, someone could be next to them forcing them to vote for a particular candidate. As it stands, the candidate may even take the person to the polling place, but will never know who the person voted for. Source: I was a "mesƔrio" for over 10 years in Brazil.
→ More replies (3)10
u/astrovisionary 9h ago
yeah, voting on site secures the secrecy of your choice, online voting would probably result in people getting their parents phones and voting in the candidate of their choice
what I think is that the system itself could be changed so the parliament elections are on a different date
3
u/Sea-Presentation-173 5h ago
There are a lot of security talks on the Estonian voting system. E-voting is a dangerous idea.
→ More replies (10)14
u/Witty_Milk4671 10h ago
"but you could vote 100% online through your smartphone like when you order uber eats and still be generally secure and consistent, they do that in Estonia"
If you think this is secure and consistent, you deserved a Zero in that presentation.
People would buy the votes or coerce the others. Someone would say "you will only continue to be employed in my company if you vote for this candidate in front of me".
First world people are too naive LMAO.
→ More replies (6)
14
u/ExquisiteApathy 10h ago
foreigners don't get that before the current electronic system paper was full of fraud
12
u/jppoeck 9h ago
Just a copy from my other comment.
1- No network, of any type, so every device is Air-Gapped.
2- All hardware has a cryptographic check, if anything is connected or replaced. It won't work.
3- The software has a fail-safe, if anything tries to "inject" or change any parameter, it will fail.
4- Every storage device that "saves" the votes, also has a cryptographic key to the system.
5- a plus for you, 30+ years of service without any "tampering".
The problem with Brazil is simple: it's not the voting system, it's the people, do you really think the priest will think it's easier to hack a system or to make the people head to vote for one person? The criminals are forcing people to vote for one candidate, or thy will be executed.... It's way easier to change a vote outside the voting system than inside.
34
u/toxicity21 12h ago
→ More replies (3)14
u/StingMeleoron 11h ago
Read some of the comments here in this post.
That is precisely the joke xkcd is making. Would you trust printed money more than digital money? Then why would you trust printed ballots more than digital ballots?
Engineers are no different: they are just people too. Brazil shows this fear can be overcome with good engineering.
→ More replies (5)9
u/Jarcode 11h ago
I have worked in high-level administration and happen to have a deep academic familiarity with nascent proposals for E2E validated electronic voting systems, and older implementations like this.
There is a laundry list of problems that still exist, and some of them are fundamentally impossible to solve (registrar corruption in the case of online public ledger systems, chain of custody and ability to scrutinize the process in offline approaches like this).
Offline systems like this can be resistant to external tampering but have serious issues when it comes to their inability to distribute what would otherwise be single points of failure in election integrity. Generally, third party vendors that help design these systems (both software and hardware) effectively hold the keys to the election, whether they admit it or not. Truly auditing these systems is not possible (see "Reflections on Trusting Trust" by Ken Thompson).
This is actually why most modern proposals for electronic voting are now opting for E2E validation, which is still flawed.
→ More replies (8)
35
u/danilofenix 11h ago
Brazil has one of the best electoral systems in the world.
26
u/Failfoxnyckzex 11h ago
but one of the worst voters in the world
18
→ More replies (1)4
3
u/Mewtewpew 8h ago
Nah this is hard as fuck. Too bad we'll never see something like this in america. Actually I expect to see a trump social styled voting software next election cycle lmfao.
34
u/Ska82 12h ago
"Claude, hack the machine and make Trump win the Brazilian elections"
→ More replies (2)44
u/ohniz87 12h ago
Thank god they are not online
→ More replies (1)12
u/Aggravating_Oil8790 12h ago
The machine is completely sealed and even doesn't have any Ethernet component. It is practically impossible to hack one of these.
6
→ More replies (1)6
u/variaati0 11h ago
Not at all impossible to hack the machines, if one has access to the supply chain of the machines. So the hacker just has to be very well connected. Like say a state actor and foreign state actors ofcourse never would stoop so low as to try to influence Brazilian elections or any other nations elections for that matter.
→ More replies (5)5
u/Allian42 11h ago
A number of these machines are randomly selected and taken away on the voting day to be tested in front of an electoral judge to compare their code to the original and make sure no tamper occurred during assembly.
5
u/albrecbef 10h ago
Testing can be detected there was a whole scandal with VW about it.
→ More replies (13)
21
u/Golgi_Complex12 12h ago
it's air gapped. votes are printed before the start of the votes and after it closes. more reliable than a mailbox where you can put fire where you opposition has more votes
→ More replies (11)
5
u/EmperorN7 8h ago
Paper ballot people trying to argue that hacking possibly the most secure election device ever created in large scale is harder than some guy doing some sleight of hand to fill a ballot with papers is insane.
→ More replies (2)
4
u/UpbeatRegister 12h ago
Does anyone know what kind of keys they use on those machines? The travel distance for each one is so long, it's like going to Mars and back. You have to brutally finger each key to type a number.
12
u/yohanleafheart 12h ago
Iirc it is close to old IBM keyboards . The idea is that you will not be able to input the number by accident.
6
3
u/andreylh 5h ago
This thing has the best keyboard ever. Typing on it is so satisfying. I'd love a keyboard that feels just like the one on these voting machines
26
u/akioet 12h ago
"eletronic voting is a bad idea" - ok gringo, lets get you into bed
26
u/Ugly_Slut-Wannabe 12h ago
It's funny how so many people complain about voting machines and act like a bunch of paper in a box is a much safer and reliable approach to voting.
13
→ More replies (19)12
u/mrElffuhs 11h ago
You can't mass fraud it, in the way you can with eletronic vote.
8
u/Allian42 10h ago
Definitely. To mass fraud a paper system, you would need something ridiculous like a quarter or more of the population being so deeply fanatical to one of the candidates, to the point people in charge of small steps in the election like transporting, policing and management would, out of their own volition, do small bits of sabotage, enough that together these could change the result. But that's crazy.
→ More replies (2)→ More replies (2)2
u/Significant-Owl2580 5h ago
Brazilian electronic voting isn't 1 system where you hack and add +300K votes. Everysingle machine is sealed, and isn't connected to no network. Each voting station have around 20 to 30 of them, each receives something like ~200 votes, it's unfeasible for someone to silently tamper with thousands of them to change votes meaningfully.
7
u/SafeSpace-Fascism 11h ago
All these experts in here as top level upvoted comments, conveniently forgetting supply chain being the biggest non social engineered vector there fucking is.
Fucking amazing. Everyone clap.
→ More replies (3)
4
15
u/YourVentiMain 11h ago
omg all the gringos here talking shit about the best voting system in the world is crazy
yall act live you even have democracy LOL
→ More replies (49)7
u/Mindless_Cat_149 9h ago
They can't stand not being the best or the main protagonist. They take it personally every time a third-world country is better at something than them. Utterly pathetic.
5
u/Limp_Sky1141 7h ago
In Chile we do paper voting with a ton of oversight and transparency. The results are in the same day.
13
8
4
u/StiffAsToyTallAsMan 7h ago
back in the paper days, buying votes from the poor people was easy. now, you can "sell" your vote and then vote in someone you really want. it made a huge difference. it's not only bc it's fast
→ More replies (3)
10
u/GigaStressedSchwa 10h ago
Humor me on this, gringos: if paper ballots are so much better, how come every time you recount them, there is a different result??? How tf you can trust such a system? Something like the 2000 US election controversy or recently the Terrebonne election in Canada wouldāve never happened here. How come you just decide to re-run an election just because the difference is 1 vote and you canāt be sure if you REALLY got the right result? Lmao
5
u/clubley2 9h ago edited 9h ago
Paper ballot papers make election fraud extremely difficult at a scale that would influence an election.
In the UK we have local polling stations where you turn up, they check off your name and give you the paper ballot. You may be able to get away with going again, or somewhere else, and using a different name but after a few you'd be noticed. Then all the paper ballots get taken to counting centers and are counted. All of the people standing in the election will be present at the counting (usually). The total number of ballots should be correct to ensure it's fair.
Computers on the other hand can be tampered with and it could be impossible to know if that happened. Someone could sneak a device into a voting booth and fix it that way. Or it could be tampered with at the factory. Or there could even just be a bug in the system that isn't noticed and it just messes up the result.
Edit: This video from Tom Scott explains this way better than I can. https://youtu.be/LkH2r-sNjQs?is=cEcXkx68Na0tnRBC
6
u/Mindless_Cat_149 9h ago
None of those things happened even once in 30 years of use.
→ More replies (7)2
u/HardMarginSVM 9h ago edited 9h ago
Sorry, but in India booth hijacking has been a very common problem. Wherever ballot elections were held (especially in some of the most underdeveloped states), the goons would hijack the booth through forced entry and start depositing bogus slips. It was also a logistical nightmare to transfer ballots safely to counting centres.
I would assume something similar might be happening in other developing countries where the law and order is not exactly a state of art.
The current Indian EVM has rate limiting of 4 votes a minute and one cannot vote until the booth officer clears the machine for voting. It also has something called VVPAT which is kept along side the voting unit. When a voter presses the button of his favoured party, the VVPAT displays the physical slip to voter as a confirmation. So basically itās like voting on ballot but you have to press a button instead of stamp, minus the logistical and counting nightmare.
There was a research paper back in 2010 by engineers that exposed the gen 1 EVMs. The machine lacked vvpats which meant there was no way for voter to confirm what exactly did the machine register. The data was not encrypted. They also swapped the display of control unit with similar looking one that had Bluetooth and microprocessor inside. Even if the machine registered correct votes, the display could be controlled to show a different number to counting officials. All these issues were fixed in gen 3 EVMs that have been used in elections for past few years. The court can order recounting through VVPAT slips, just like ballot in case they suspect fraudulent activities.
Edit:
link for the video demonstration
link to the technical paper.→ More replies (7)2
u/Dry-Term7880 7h ago
Yeah but the way the system is set up and supervised by independently contracted technicians from all parties and involves sooo many redundancies make it highly unlikely that it gets tampered with. The reasons the system is like that is because Brazil is very different from the UK. Trust me you would get local armed gangsters fucking with the paper ballots.
2
u/slinky3k 9h ago
Humor me on this, gringos: if paper ballots are so much better, how come every time you recount them, there is a different result?
2000 US election controversy
Numerous problems with ballot design and they used mechanical punching machines followed by machine counting. That failed to count votes where the punch machines failed to make clean holes.
That is not how paper votes generally work.
Terrebonne election
Was an issue with voting by mail.
2
u/HotPrune722 9h ago
The supermarket of my little town keep having msdos as the main system for the cash machines, i feel a lot of pain when i see that old thing generate my food facture
2
2
2
u/big_chungus1117 4h ago
As far as I know it doesn't run on Linux, but I could be outdated on the OS they run.
3
u/l3ader021 4h ago
They're using Uenix on all machines since 2008 - 8 machines have been with it.
→ More replies (1)
4
3
u/boblancho 9h ago edited 9h ago
Now this is the type of nerdgasm I can goon to
Edit: my first distro was Conectiva Linux, eternal love to brazilian nerds
7
u/Euroblitz 12h ago
It takes about 13 steps and CPU instructions to validate an election, if you know what I mean
5
u/ScroogeMcQuacks 12h ago
I have mixed feelings about electronic voting.
40
u/GodderDam 12h ago
Search about Brazil's solution. These devices has no terminal, no internet, bluetooth, IO ports available, can't connect to anywhere, it's a custom kernel that'll only run signed binaries and libs, everything is encrypted. All open source and auditable by various parties...
25
u/MrScotchyScotch 12h ago
In other words, nothing the US would ever adopt because it's secure, modern, and auditable
2
u/w-g 12h ago
Not really "open source". The source is available to those who ask to participate in some kind of quality control process, but it's not allowed to pass it along. I wish it was truly free. But since it follows a strict crypto protocol and it's air gaped... It's safe (but not free, unfortunately)
→ More replies (5)12
u/GreenFox1505 12h ago
And how do you know the device in front of you is actually what its suppose to be? How would you go about teaching your grandmother how to verify the device?Ā
18
u/0Clown0 12h ago
The brazilian government runs national and sometimes international tests, allowing anyone to try to hack the machine and also gives them access to the source code. No one has done it yet.
9
u/Jean_Luc_Lesmouches 12h ago
How do you check that's the software that's actually in front of you when you vote�
→ More replies (9)5
u/Exotic-Half8307 11h ago
How do you know that the person counted your vote correctly? at the end of day you have to put trust something.
The same way its hard to fraud an paper election bcs too much people are involved you also have 500k+ machines with dozens of people for machine, at one point if widespread fraud is ocurring everybody will know abt it
3
u/variaati0 10h ago
How do you know that the person counted your vote correctly?
By there not being a single person I have to trust on that. Rather it is in first place usually two counters and by most places rules, they can't be from same political party. That is just for single pile. There is many such pairs. Pairs can then cross check by recounting other pairs work.
votes try to be removed? The number of votes cast to the boxes is known. Try to swap? It won't have the correct stamp on it. Since those stamps are under lock and key during counting. Plus anyway there is dozens of observers present.
How we trust the counting? By not trusting amount of people less than say ehhh 5 and those people have to represent and be appointed by multiple different parties. The more those parties hate each others guts, the better.
Non biased counters? Nah, you want as biased as possible counters. Biased very heavily of "our party must get as high vote total as possible. Not a single vote for our party must go uncounted (and if it over counts, we aren't against that either)". Which would lead to cheating, expect there is 3 other people from 3 other parties going "that party has to get as low result as possible. Watch like hawk for them trying to cheat and increase their vote. Make sure there is not a single extra vote registered for them... We would throw out their ballots, if we could. Sadly it is hard with them in the room".
7
u/Jean_Luc_Lesmouches 11h ago
How do you know that the person counted your vote correctly? at the end of day you have to put trust something.
In France they are counted in public on tables of 4 volunteers picked at random. 1 opens the ballot and looks at it silently, 1 reads it out loud, and 2 write it down independently. You don't have to trust any official or technical expert, a 5yo can see any irregularity as it happens.
you also have 500k+ machines with dozens of people for machine
Dozens of people for 500k+ machines? Do you have 5M+ cybersecurity experts?
14
u/GodderDam 12h ago
The same thing could be asked about paper voting with far less certainty about its legitimacy
18
u/hendrix-copperfield 12h ago
With paper voting in germany, anybody can go to your local voting area and watch hownthey xount the votes. With paper you have a paper trail of every single vote.
Unless those machines print also a paper vote receipt that is collected and can be counted afterwards to verify what the machine counted, you can't know if somebody manipulated the machine beforehand or if they are counting correctly.
To be fair, the Brazilian machines seem to be way safer than the US machines, but none are foolproof, especially if your government, who is providing and maintaining the voting machines is trying to establish an autocracy.
→ More replies (22)9
u/GreenFox1505 12h ago
Everyone puts their vote in a box, anyone with a stake in the election gets to watch the box, multiple parties with a stake watch the box get moved to the counting location, and counters are watched by multiple groups.
This is not so complex of a system that your grandma cannot understand. It is hard to attack. And attacks on it doesn't scale well.
5
u/Mechanical-Flatbed 11h ago edited 11h ago
No, it can't. Because with paper ballots anyone can physically audit the vote counting process. While you may not be able to trace your exact ballot in the paper pile, you can be sure it is being counted correctly and that prevents fraud. This catches spoiled votes, incorrect counting and the entire process is free and fair for all citizens to see.
With Brazil's e-voting machines you can't be sure if the machine is even running the software it says it is. And that opens the door for fraud. Since the process is not transparent and not auditable, you can't be sure your vote is being counted correctly.
Brazilians seem to miss the point completely when they point to their closed-off audits as proof of legitimacy, because that doesn't prove that the software that was tested by these party members is the same one that is being run during the actual election. And this is what everyone in the comments is correctly pointing to.
→ More replies (3)10
u/AssocialSocialist 12h ago edited 11h ago
In countries with paper-voting (with working systems...), citizens have the right to observe the entire process (except for the part where people fill in their votes). I can see the election workers prepare the urn, it being sealed, my vote being dropped into it, and then later I can see it unsealed and each and every vote counted. I never have to take my eyes off of it. It's a lot easier to understand and explain than digital trust, especially when the digital trust needs to be able to be verified from the "bottom up".
4
u/Aggravating_Oil8790 12h ago
I mean, if it isn't the device, the vote is not computed. There is a lot of cryptography and math to verifie if the device is trustful. But even if someone theoretically change the device, they would have to change 500000 voting machines.
5
u/julemand101 12h ago
I think it is more a question about how you, as a normal citizen, can be sure the government have not done something with the machines. With paper, it is many groups of normal citizens that does the counting and therefore a corrupt government does have a very hard time cheating without trying controlling lot of individual people there all must stay silent.
And if people call the counting invalid, the paper can be counted again by different group of people and the numbers should match if things are valid.
6
u/Aggravating_Oil8790 12h ago
The machine is checked by independent agents and opposed political parties, it's not that simple
5
u/julemand101 12h ago
So, at every voting place, they inspect the software from the machine? How can you prove the machine runs the exact software published?
→ More replies (9)3
u/reditanian 11h ago
How do you know the box you put your paper ballot in is actually a legitimate box? At some point thereās a degree of trust involved in elections
3
u/GreenFox1505 11h ago
Because every party with a stake in the election gets to watch the box. They can check that its empty before hand, they can watch it during the election, and they can watch it get transported to the final counting location where multiple groups can count the votes and count discrepancies would be obvious.
Physical voting is secure not because it is incorruptible. It's secure because attacks don't scale well. Sure, you could bribe a few people to lie about the contents of one box. But thats not enough to sway an election. You need to do this over and over again and the more people involved, the less likely your conspiracy will remain secret.
A digital device is made by a few suppliers and audited by even fewer.Ā
→ More replies (1)3
u/holchansg 12h ago
The code is audited from independent individuals, general public, anyone can subscribe to do it and there is representatives from all the political parties into the entire process.
https://international.tse.jus.br/en/electronic-ballot-box/auditability
There is even random blind picks on the machines and randomized blind trial.
→ More replies (8)6
u/GodderDam 12h ago edited 12h ago
Man, look it up. There are multiple people and parts involved in the process to guarantee its legitimacy. We've been doing this for 30y and it's no joke
5
u/OddDragonfly4485 12h ago
Wait. Do you north american folks vote with a piece of paper?!
3
u/zrad603 12h ago
In New Hampshire it's state law that it must be paper ballots, but in most towns they are counted by machine.
Which is important, because there have been recounts where the machines have fucked up.
But other parts of the country, they have touch screen voting, or mechanical levers, etc.
8
→ More replies (2)3
5
u/Blitzbahn 11h ago
Democracy is still an illusion. It doesn't matter who you elect if they are bribed or blackmailed into doing what someone else wants. Those with real integrity can't get past the propaganda machine.
→ More replies (3)
182
u/albrecbef 10h ago
Can it run doom?