Brazil dares the public to attack its voting machines — on purpose
Brazil's election court doesn't just certify its voting machines — it publishes the rules and dares the public to break them. Here's what that actually looks like, and why it still isn't enough.
It is a weekday morning in Brasília, and a group of people who are not election officials — researchers, computer scientists, an independent technologist or two — are sitting in front of Brazil's electronic voting machines with one explicit, court-sanctioned job: find a hole.
They are not hackers in the colloquial sense. Each submitted a test plan. Each was vetted. Each signed up through an official government portal. And the institution that invited them — Brazil's Superior Electoral Court, the Tribunal Superior Eleitoral — didn't just open the door once and call it transparency. It built a repeating, regulated process and named it the Teste Público de Segurança dos Sistemas Eleitorais: the Public Security Test.
This is what "come check for yourself" looks like when an election authority actually means it.
Most countries never get close.
The phrase every election authority loves — and what it costs them nothing to say
"The election was secure." "The systems were certified." "Audits confirmed the result."
Every election authority on earth says some version of this after every vote. Almost none of them give you a way to verify it yourself.
That asymmetry is the problem. An official statement about security carries exactly as much weight as the independent checks behind it — no more. When Germany's Constitutional Court struck down electronic voting machines in 2009, it didn't find evidence of fraud. It found something more fundamental: that citizens were being asked to trust a result they had no means to independently examine. The Court held that every essential step from ballot to result must be checkable by an ordinary citizen without specialist knowledge. Trust-me-it-was-fine failed the constitutional test.
Ireland bought 7,500 Nedap/Powervote machines and an independent commission couldn't recommend using them — not because the machines were proven wrong, but because accuracy and secrecy could not be independently verified to the commission's satisfaction. The machines spent years in a warehouse and were scrapped in 2009. The commission's language was precise and devastating: it was "not in a position to recommend with the requisite degree of confidence" their use.
The Netherlands reached the same conclusion. Its advisory commission on the election process, in a 2007 report called Stemmen met vertrouwen — "Voting with confidence" — set out what verifiability actually requires and found that paper ballots counted by hand met the standard while voting computers did not. The country went back to paper.
Three different democracies. Three different machines. One identical gap: nobody outside the vendor's circle could check the count.
Brazil is trying to close that gap a different way.
What the Public Security Test actually is
Regulated by TSE Resolution 23.444/2015, Brazil's Public Security Test runs in the year before a general election. The format is not a press event. It is an adversarial exercise.
Any eligible citizen can submit a test plan. Plans that pass review are approved. Approved investigators then get structured access to the urna eletrônica — the electronic voting machine — and to the systems surrounding it: ballot-media generation, voting, tabulation, file transmission and reception, and the audit systems used to cross-check the electronic vote. The testing spans the entire electoral lifecycle, not just the machine sitting in a polling booth.
What investigators find matters — and not just as a press release. Findings are used to improve the systems before the election, and fixes are subsequently re-checked in confirmation testing. This is a closed loop: find, fix, verify.
That is categorically different from a one-time certification. Certifications are a snapshot. They assess a system at a moment in time, under controlled conditions, by parties whose access is limited by the vendor's cooperation. They also carry institutional incentives to certify rather than to disqualify — because a failed certification means a delayed election and a political problem.
The Public Security Test is adversarial by design. The investigators are trying to break the system. The TSE publishes the rules, not the results it hopes for.
See how the verifiability gap plays out across dozens of elections worldwide
Why adversarial public testing beats private certification
Consider what happened in Washington, D.C. in September 2010. The city was about to run an internet ballot-return pilot for overseas and military voters. Before going live, the D.C. Board of Elections ran a public trial and invited the public to probe it.
A University of Michigan team led by J. Alex Halderman gained near-complete control of the pilot server within roughly 48 hours by exploiting a software vulnerability. They could change every ballot that had been cast. They could view secret ballots. As a demonstration, they programmed the system to play the University of Michigan fight song after each simulated vote. Officials didn't notice for days.
Here is what matters: the vulnerability was caught because the jurisdiction opened the system to public testing before real ballots were at stake. D.C. dropped the system. That is adversarial testing doing exactly what it is supposed to do.
Private certification did not catch this. An invited public test did.
The Princeton researchers who analyzed a real Diebold AccuVote-TS machine in 2006 found that an attacker with as little as a minute of physical access could install code that stole votes while keeping all internal records consistent — and that the code could spread machine-to-machine during normal election activity. The software was closed. No public testing had surfaced it. The researchers found it because they got their hands on the hardware and looked.
New South Wales ran an internet voting system in its 2015 state election that collected roughly 280,000 votes. A prior closed security review had cleared it. Independent researchers found serious flaws — including a verification mechanism that could itself be gamed — during the live election. The issues had not been detected before the researchers disclosed them.
The pattern is consistent. Closed systems, reviewed in private by parties working under certification pressures, miss things that open, adversarial public testing finds. This is not a surprise. It is the expected output of the two different processes.
Brazil's model runs the adversarial test in the open, on purpose, with a structured remediation loop. It is the closest thing to "institutional paranoia as a feature" that any election authority runs at national scale.
What a real transparency model fixes — and what it cannot
It is worth being precise about what the Public Security Test actually proves, because overstating it would be a different kind of dishonesty.
The test checks whether investigators, given structured time-limited access under defined conditions, can find exploitable weaknesses. Findings are fixed and re-checked. That is genuinely valuable. It surfaces real vulnerabilities. It creates accountability for fixes. It puts the burden on the authority to demonstrate security rather than assert it.
But it does not, by itself, prove that the machines counted correctly in a specific election. Testing a system before an election and auditing its output during one are separate problems requiring separate solutions. A machine can pass every pre-election test and still produce a wrong result on the day — because of a software bug that the test didn't trigger, a hardware failure at a specific polling station, or an attack vector the investigators didn't find.
This is why Brazil's approach is a model for transparency, not a complete solution for verifiability. The distinction matters.
A system that publishes its rules and invites outsiders to break it is more trustworthy than one that doesn't — but "more trustworthy" is not the same as "independently checkable by anyone."
The D.C. pilot caught its flaw because the public test happened before real votes were at stake. If the same vulnerability had been exploited on election day against real ballots, no amount of pre-election testing would have recovered the correct count. You also need a durable, independently checkable record of what voters actually chose — something the D.C. system didn't have.
The India Supreme Court grappled with exactly this tension in April 2024, in Association for Democratic Reforms v. Election Commission of India. Petitions asked the Court to either return to paper ballots entirely or require 100% cross-verification of electronic machine counts against Voter Verifiable Paper Audit Trail slips. The Court declined to order either, but it tightened the rules around chain-of-custody sealing and allowed candidates to request verification of the burnt memory in 5% of machines in disputed races. Even a court that upheld an electronic system recognized that confidence must flow from checkable evidence, not from the authority's assurances.
The two safeguards are not alternatives. They work together. Adversarial public testing finds weaknesses before the election. A verifiable paper record lets anyone check the count after it.
The harder lesson: what "Brazil does this" doesn't tell you about your country
Brazil is not a model of a perfect election. It is a model of a specific transparency mechanism that most countries don't bother to run. Those are different claims, and conflating them would be exactly the kind of authority-deferring we're trying to avoid.
The TSE's Public Security Test is real, structured, and documented. The fact that it exists does not settle whether the urna eletrônica's total architecture is verifiable in the full sense that Germany's Constitutional Court or the Dutch Korthals Altes commission would require. It does not tell you whether a sophisticated attacker could have found and exploited something the public test investigators missed. And it does not tell you what happens if an insider manipulates the system before the test-evaluated version reaches polling stations.
Venezuela in 2017 offers a useful negative benchmark. Smartmatic — the company that had provided Venezuela's automated voting systems since 2004 — issued a public statement saying it knew "without any doubt" that the turnout figure the National Electoral Council announced had been manipulated, and estimated the difference between actual and announced participation at "at least one million" votes. The vendor publicly disowned the official result produced on its own equipment. When even the system's builder cannot reconcile the numbers and independent audit is unavailable, there is no path to verification.
Brazil's model prevents that failure mode, at least in part, by making the authority's process contestable before the election happens. But a contestable process and a verifiable result are still not identical. The fix for the remaining gap is what Colorado has been building since 2017 — the first state to complete a statewide risk-limiting audit — and what Georgia demonstrated in 2020 when it hand-counted roughly 5 million presidential ballots across 159 counties in under six days. An audit that gives statistical confidence the reported outcome is correct, run against a durable paper record that voters produced, closes the circle that pre-election testing opens.
The full architecture looks like this: open, adversarial, public testing before the election + a voter-verified paper record during it + an independent, statistically rigorous audit after it. Brazil institutionalized the first element. Most countries have none of the three.
The question you should still be asking
After Brazil's Public Security Test runs, the TSE publishes what it found and what it fixed. That is better than a press release saying everything was fine.
But here is what you, as a citizen, still cannot independently verify: whether the software running in the polling booths on election day is the same software that investigators tested. The chain of custody between a tested system and a deployed system is a security control that receives far less public attention than the test itself. It is also one of the hardest to audit without independent access to the final deployment — which is not what the Public Security Test provides.
This is not a speculation about Brazil specifically. It is a structural observation about every electronic voting system on earth: the integrity of pre-election testing depends entirely on whether the tested version is what runs on the day.
Coffee County, Georgia in 2021 illustrated the inverse problem: an entire jurisdiction's proprietary voting system was copied and leaked by insiders, and the code spread in ways no certification authority had anticipated. The vulnerability wasn't the code being tested. It was the code being secret — a system whose security depended on nobody getting their hands on it, and then someone did.
Open-source code, independent compilation verification, public hash-checks of deployed software — these are not theoretical luxuries. They are the mechanisms that close the gap between "we tested this" and "you can verify what ran."
Brazil runs the best pre-election adversarial transparency program in the world. That is worth saying clearly. It is also worth saying clearly that "best pre-election adversarial transparency program in the world" is a threshold most countries haven't reached, not a finish line.
The finish line is a result any citizen can independently verify — not because an official said so, not because a test was run, but because the evidence is public, the chain of custody is sealed and traceable, and the audit math checks out.
That system doesn't fully exist anywhere yet.
See what verifiability gaps look like across the world's elections · Read the 2-minute version of why this matters · What TrustVoting is building to close these gaps
Sources
- Tribunal Superior Eleitoral (Brazil) — Teste Público de Segurança dos Sistemas Eleitorais
- Wolchok, Wustrow, Halderman, Prasad — Attacking the Washington, D.C. Internet Voting System, Financial Cryptography 2012
- Feldman, Halderman & Felten — Security Analysis of the Diebold AccuVote-TS Voting Machine (USENIX/EVT)
- Halderman, Teague — The New South Wales iVote System: Security Failures and Verification Flaws in a Live Online Election (arXiv:1504.05646)
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Commission on Electronic Voting — Interim Report on the Secrecy, Accuracy and Testing of the Chosen Electronic Voting System (Houses of the Oireachtas Library)
- Adviescommissie inrichting verkiezingsproces (Commissie Korthals Altes), 'Stemmen met vertrouwen', 27 September 2007
- Smartmatic, 'Statement on the recent Constituent Assembly Election in Venezuela' (2 August 2017)
- Lawfare — What the Heck Happened in Coffee County, Georgia?
- Colorado Secretary of State — A new kind of election audit: Colorado is first to complete it
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia
- Supreme Court of India — Association for Democratic Reforms v. Election Commission of India, 2024 INSC 341