More or less. You can fill a request to participate in the security checks open to the public. Then, you can read the code and try to discover insecurities. But there is not a repository over the internet where you can check the code anytime.
Pretty sure this is considered "source available", not open source. The difference being that I assume there's no license in the repo that grants the user who gets the code the right to modify and redistribute. Regardless source available is still substantially better than a lot of cases, and it's close enough for anyone who wants to just audit the code
If the code is actually licensed under an open-source license, then the lack of a public repository doesn't make it source available. Open source doesn't require the source to be publicly browsable at all times. The important question is whether people who obtain the source receive the license rights to use, modify, and redistribute it, rather than merely being allowed to inspect it for an audit.
They also host competitions and invite researchers to try to break it.
If I remember well, they were able to break stuff every once in a while, but always in a scenario that is not realistic (e.g., would take more than a day)
I remember that researchers once proved that the random generator and the votes scrambling system were not perfect, so you could theoretically know the order of votes cast.
It was such a specific scenario that it could not be exploited in practice.
Regardless, the electoral agency and court (TSE) have reworked the entire module to fix the problem.
One of the researchers that found some vulnerabilities have a website where he discloses them. His name is “Diego Aranha”. He’s a redditor as well and sometimes replies to messages mentioning his name. I don’t remember his username though!
It wasnt hard to exploit at all, given you have the scrambled record, the scrambling were based on a pseudo random number seeded from the machine boot time, which is easily available.
To be honest, this is a very naive implementation for such critical system, Diegos team found it in very restricting conditions, which make me think what else could be found if one had the oportunity to really dig deep into the code?
If youre talking about printed voting, it is a very different thing
But regardless, I dont expect engineer working on a critical system like this to take such mistakes, this is something a mid level engineer should know.
It's also part of the process that makes it secure. Countries that don't have those competitions have machines that can be hacked in to. Countries that do have those competitions get it proven to everyone just how hard it is to hack them, because any hacks that get discovered along the way get patched. Light is the best disinfectant.
I have responded to this question to someone on this post. But a summary:
Before the election starts, a representative amount of machines is selected at random to be collected from the voting areas.
A group of representatives performs a series of checks both on hardware and software to check whether it matches the approved digital signature of the official voting system.
This procedure is accompanied by representatives of diverse political parties, volunteers, judges, and many more people.
This is an official page from the Brazilian State, that describes one of the procedures. Besides this one, there are practical tests to cast varied votes on the machine and check if the amounts match. This is all done as a blind test.
The compilation is done publicly. There is a cerimony that builds the software where people have access to the binnary hashes and its digital signature. When the hardware goes to the public, it performs a series of checks that need to mach the compiled binnary.
The trust comes from this public verifiable compilation event, plus with the physical locks that hides the chips inside, which would be evidence of it being mechanically violated.
I don't think thats the only safety measure. It has been a while I read about this, but I'm pretty sure the machine prints a hash/digital signature of the code used on it and you can request to validate this if you suspect anything. Also the hash of all machines should match since its the same code.
So you would have to tamper a machine and make it print the valid hash, not impossible but there are people with eyes on the machines all the time, its very inconvenient.
The best way to fraud an election in Brasil is with fake news and manipulation, thats WAY more effective than compromising a few machines and risking being caught.
So besides needing to blindly trust the e-voting software, you also need to blindly trust the software doing the compilation, the crypto and the hashing of the aforementioned software?
Please read the comment just above you. Voting machines are selected at random during election day. These are then audited and they get tested live during the voting period. They have a livestream where these machines have test votes inputed on them, and then their result gets audited. If the result the machine gave is different from the votes inputed live, the whole thing gets canceled.
No, you don't blindly trust the software. You trust the experts that you hire to check the software and the process at these events.
I don't know the details of what happens, but people with access of these code will compile and check the hashes and signatures to guarantee that the software doing the compilation is producing the same binnary. It is not just a show and tell.
nobody has access to the code! What are you talking about! No even to the libraries, to the compiler or the basic software audit things, the audit is a scam, lol.
I was asking the same question over and over again. I got a lot of nice replies, a lot of links pointing only how flawed and unreliable all the audits are. I even go and read some papers about software audit and it become even worse than I first thought. But, it seems if you ask any technical question you get the same flawed answers and they get really creative with the name calling, but no technical answer whatsoever.
Why not fully open source it so everyone can check for vulnerabilities outside a controlled enviroment and without a government authority supervising the exercise?
I'm Brazilian and in favor of opening the source code as well.
But there are some big practical and ethical implications on it.
What if they open the source code today, and within a week a bug is found. Will the last election be discarded? Should we invalidate all presidential terms since ___? I'm sure the losing part would try to do so.
Also it would require a full team to be reviewing community requests, discussing issues and accepting/rejecting patches. Nowadays the system is relatively stable.
Lastly, the hardware is built specifically for it too. Even though they could also release an Open hardware spec, it's not like anyone would be able to have their own voting machine
What if they open the source code today, and within a week a bug is found. Will the last election be discarded? Should we invalidate all presidential terms since ___? I'm sure the losing part would try to do so.
If this "bug" is proven to introduce fraud to the election, then the entire system should be replaced. Simple as that.
There is something I worry about open sourcing it fully. One of my worries: If the US with its mythos/fables/astras, finds a bug, would it tell the people or would it use this knowledge to fraud the election?
Right now, if you are a researcher, the army or member of a political party you can already audit the source code. They never found a real issue. If you wanna be sure there's no vulnerability you can volunteer yourself to audit it.
Which kind of reward are they giving for being successful? Not saying that's what's happening here but if the reward of hacking a device and being able to rig an election is greater than the reward of winning that public session, then that session is just for show
They probably didnt understand. There isnt a reward, thats why these sessions never go anywhere, no one cares enough to try and break into a very locked system, even less without any rewards. Its just politicians dancing around pretending theyre doing something when in fact they are not doing anything
Every election, some sore losers, conspirationists and some others (notably the Bolsonaro clan) scream around that the system isn't safe and the elections were frauded (which is particularly funny in the Bolsonaro case, because he said that again and again while he was president, ie after this same system declared him the winner). These people have the opportunity to test and show the issues, but they were never able to do so. Imo, proving their theory is a reward on itself
And, incidentally, the only reason he alleged fraud even after winning in 2018 was the fact that he wasn't elected in the first round, in which he needed 50%+1 of the votes to do so.
Bolsonaro wasn't content with simply being president. He wanted to sell the idea that he should be more popular than the polls showed. In other words, he wanted to obscure any kind of opposition (especially from the Left). From that day on, Bolsonaro had been dropping hints that he didn't want to leave power and wanted to sabotage the democratic machine in favor of totalitarianism.
They didn't say someone needs to prove it has a failure to prove it is not safe.
They said that people need to spend time and resources to find failures (these "sessions only for hackers" that you said). If the reward of finding a failure is not high, or if the reward of actually hacking it is greater, then you don't have enough incentives for white hackers to find bugs in your system.
Imagine spending years of experience only and use your knowledge to help the security of something like this. You always need to give something in return. Otherwise more knowledgeble people will do it maliciously because rigging the ellection is far greater than trying to white hack it.
“The good guys” sometimes do things that benefit everyone , for moral reasons, national pride , just to help humanity in anyway they can . The other side pretty much only does things for money- that said, the recognition you’d get from hacking these machines would guarantee to line up high paying contracts in the future. Quite a thing to have on your resume
In theory. In real life things differ. That's not statistically possible.
Just imagine your population.
Now multiply by the fraction of who are the "good guys"
Now multiply by the fraction of those good guys who are experts in electronics
Of those, multiply by those experts who specialized in complex systems like these
Of those, multiply by those who are trained in digital security.
If you want this to happen "by chance", you'll soon run out people that would have these characteristics and also availiability to do it "for the greater good". Which is why these systems are usually audited by instituions: The parties involved, the judicial system, universitoes, some part of the press. It is really hard to find good people. Not because they don't exist, but because it is a very specific set of characteristics required.
Pretty sure any company would throw a shitfucking load of money at a guy that broke into a system that wasn't broken into in 30 years.
As for being able to use the vulnerabilities discovered, it's impossible because those sessions are open but anything that is remotely insecure gets patched right away.
So even if you discover something and decide to sell it to the highest bidder, your vulnerability would've already been patched.
"pretty sure" did not answer my question, no. To counter your argument, if you don't need the exposure, you're not doing this, which means the best are automatically filtered out already, since there is no reward, and thus no real reason at all for anyone who knows what they're doing, to attempt this.
Does that clear up your pretty basic logical fallacy?
You've clearly never met CyberSec/OpSec people and it shows.
The very best in this field do it for the love of the game and to show that they're the best, not for exposure or money.
I know literal dozens of people that are amongst the best for this field in the country, not based on my opinion but on their actual experience and roles they've exercised across their years, as well as actual places they hold onto these communities, and many of them have been part of this process, again, for the love of the game.
Your (also an obvious pretty basic logical fallacy) argument is also based on the fact that you're banking on not a single person of high ability setting out to show that the system is flawed. Not a single one.
You also obviously decided to ignore the other parts of the arguments such as any exploits found being patched right away and not being usable anymore.
You talk about my arguments being hypotheticals and then to counter it you show an obvious even more hypothetical one, did you notice that?
Does that clear up your pretty basic logical fallacy?
They kind make a open test, but it's not so open, you need to ask months earlier, but you can't ask as a single individual/citizen, need to be in a corporation or lab.
You have to stay inside the government room with their hardware and software, you can't use tools that you want, you can't use AI and in the end you can't check if it is the same you are seeing at the time is the same that is going to be compiled and used nationwide.
They have some cerimonial to say you are verifying, they talk about some "hash", but none of those prove anything and even the researchers that started the eletronical votes machine said we should go to vppat with verifiable printed paper, our politicians approved to apply this 3x times and the top judges just said: nah, you don't need that. And give some excuses to some scarecrow problems they created themselves about it.
All the cerimonials are just for politicians, you don't have anything that a software engineer would look and agree.
But you can't prove it can be used to fraud, mostly because you can't verify anything anyway
It's not open source. A few people can inspect in a very limited test.
Unfortunately brazillian voting process is a little sketchy to say the least (if you say you don't trust in it you might go to jail for "attacking democracy")
if you are a brazilian citizen you can request access to it, but you can never take it home in order to avoid leaks.
this code is property of the brazilian people, not the world.
why is absurd?
ive worked on sony project that we had to go to places similat to that and we were doing game updates... no voting systems...
and no, USA will never put their fucking hands on our voting machines and source codes, so im glad we dont release the code in the open and we take our time to prevent it from leaking.
security by obscurity, theres a lot of internal things, like custom compiler with builtin encryption and code signing that an attacker would need to umderstand its workings before they are able to compile code that could run on it. by obscuring this step alone, already makes an attack near to impossible.
ownership, the IP of this code is property of the brazilian people, one of the things the brazilian government do is sell this tech to foreign countries, which we do. and all the tech in that equipment is brazilian made, even the hardware is manufactured in brazil, with the exceptiin of the chips that are made in taiwan.
Security by obscurity is only security theater. In a properly-designed system, it should be secure even if the adversary knows everything about the system other than the actual keys. If any part of the design is kept under wraps, nobody knows what vulnerabilities could be there. Sure, it makes it harder to hack because less information is available, but also harder to secure.
Literally any citizen can request access if they want.
Lies. The TSE website only says it "opens the source code of electoral systems for wide auditing by various civil society actors".
If you had an ounce of critical thinking, you'd realize that, if 'literally any citizen' were automatically granted access to the code, there'd be no need to request access in the first place.
The code is audited from independent individuals, general public, anyone can subscribe to do it and there is representatives from all the political parties into the entire process.
35
u/ArtisticFox8 13h ago
Is the code for these open source?