Table of Contents
Quick Summary
- Brazil's electronic voting machines do run a customized Linux distribution called "Uenux".
- Uenux was introduced by Brazil’s electoral authority (TSE) in 2008, after it decided to unify the operating systems used by its voting machines. It is developed specifically for the voting hardware, rather than a standard desktop Linux distribution adapted for the job.
- Brazil's voting machines are not connected to the Internet while voters are using them. They don't use Wi-Fi, Bluetooth, cellular connectivity, or a normal network interface for voting.
- For the 2026 presidential election (held On October 4, 2026), TSE used 563,910 voting machines for more than 158 million registered voters.
Brazil Runs Its Elections on Linux
Brazil has been using electronic voting machines for decades. All these machines run a Linux-based operating system called Uenux, developed by Brazil’s electoral authority, the Superior Electoral Court (TSE).
Image credit: https://x.com/brunoborges
Uenux is not a normal desktop Linux distribution. It includes the kernel, bootloader, drivers, libraries and applications needed for the voting machine. It boots, checks its own digital signatures, accepts input from a numeric keypad, stores votes, and prints a paper report at close.
There is no desktop environment, no package manager, no network stack in use.
How the Voting Machine Ended Up on Linux
It wasn't always Linux. The first machine in 1996 was a modified IBM PC 386 clone running VirtuOS, a DOS-like system from one of the vendors. From 2002, it ran Windows CE under licenses reportedly provided by Microsoft free of charge.
In 2008 the TSE migrated to a Linux system known as UEnux, with the stated aim of cutting costs and taking full control of the development cycle.
The Voting Machine is Fully Isolated
The voting machine is not an Internet-connected PC waiting for someone to find an open service. During voting, the machine does not use the Internet, Wi-Fi or cellular networks to communicate with the outside world. The voter terminal and the poll worker's terminal communicate locally.
The machine has two parts: a poll worker's terminal, where your voter registration is entered, and the voter's terminal inside the booth. A cable connects them.
It has no internet, Wi-Fi, or Bluetooth connection, and no hardware for them. In August 2026 the TSE disassembled a machine live on television to demonstrate this. The physical ports are also sealed with security seals made by the Brazilian Mint, which help show whether someone tried to open the machine.
That removes the biggest risk in most systems: a remote attacker. You can't SSH into a machine with no network interface.
Election Day: Layers of Checks
Before voting, the TSE signs and seals the software in a public ceremony. Each build gets a hash, a fingerprint that changes if any part of the program changes.
On Election Day, the machine verifies its own signatures at startup and is meant to refuse to run if something has been altered. It then prints a Zerésima, a paper showing every candidate at zero.
During voting, each choice is stored in the Digital Vote Record (RDV). It does not link a vote to a voter's identity, and the order of votes is deliberately scrambled so the sequence can't be reconstructed. The RDV also supports recounts and audits.
The machine stays offline all day. When polls close, it:
- Prints the Boletim de Urna (BU), a paper tally for that station, in five copies. One is posted at the polling place.
- Writes the results to a signed, encrypted memory card, which people carry to the electoral office, where it enters the TSE's private network.
The posted paper is the key checkpoint. If the TSE's published total for a station doesn't match the BU on the school door, anyone with a phone can spot the discrepancy, and parties can independently add up the BUs and check the national total. That protects against tampering after the BU is printed, such as during transmission or tallying. As we'll see below, it doesn't by itself prove the machine counted correctly.
There are two other checks worth distinguishing:
- Authenticity test: verifies that the software on the machines matches what was signed and sealed, by checking media, signatures, and cryptographic hashes.
- Integrity test: machines are drawn by lot, paper ballots filled out in advance are typed into them under camera and with an external auditor, and the machine's count is compared with the paper. A biometric version, with volunteer voters unlocking the test machine, was added in 2024.
The two are complementary. The first asks "is this the right software?" The second asks "does that software count correctly under test?"
What Security Researchers Have Found
The TSE holds Public Security Tests, where outside experts are invited to attack the system. The findings are worth reading, because they show what's really been broken:
- 2009: A researcher used a battery-powered radio to pick up electromagnetic emissions from the keyboard from over 20 meters away, revealing whom someone voted for. A privacy break.
- 2012: A team led by Diego Aranha at the University of Brasília found a single cryptographic key protecting every machine, stored unprotected. They also found the vote-shuffling used a predictable seed tied to the machine's clock, which let them reconstruct the order of votes at a station. Another privacy break.
- 2017: Researchers ran their own code inside the machine and altered votes. But this required access to the software load medium before the machine was sealed, plus reverse engineering and re-signing. That makes it an insider or supply-chain path, not something an outsider could do from home or on Election Day.
- 2018: Someone entered the TSE's own network through a former employee's account that had never been revoked, with a weak password and no two-factor authentication. They stayed for months and copied source code for JEDI, the system that installs software on the machines. Specialists reported the access was read-only, with no votes altered.
- 2021: Findings included a 3D-printed fake panel and a Bluetooth device used to eavesdrop on audio for visually impaired voters. Federal Police experts also got through barriers on the transmission network, though without being able to alter votes or configuration.
Please note that all these failures are mostly human and procedural (a reused key, an unrevoked account), not breaks in the cryptography itself. And no outsider has changed a vote on a sealed machine in a real election.
The TSE says it has fixed what these tests found, and reports no fraud case has been uncovered.
The Strongest Criticism
The biggest criticism is not about remote hacking or conspiracy theories. It is about who can independently verify the vote.
Researchers such as Diego Aranha argue that Brazil's system does not produce a record of the vote that exists independently of the voting software.
Consider a simple example. You vote for Alice, but the software secretly records your vote for Bob. The machine could then print a Boletim de Urna (BU) showing Bob. The paper would match the software's result, but that does not prove that the machine recorded your choice correctly. In other words, the machine would be checking itself.
This is what security researchers mean by software independence: you should have some evidence of the vote that does not depend entirely on the software being honest.
This is a criticism of the system's design, not an accusation that Brazil's elections have been rigged. Aranha himself has said there is no evidence of election fraud. The argument is simply that, if someone with enough access managed to compromise the software, the system has limited ways to prove that the software did not alter votes.
The TSE's answer is that the system has several layers of testing. One of the most important is the Integrity Test, where selected voting machines are given known votes and their results are compared with the paper records. The machines used for the test are selected by lot, and the test takes place on Election Day.
That is useful evidence, but it is still a test. A test can show that the machines behaved correctly under those conditions; it cannot prove that no piece of software could behave differently outside the test.
So the disagreement is not really about whether the voting machines have security controls. They clearly do. The harder question is whether those controls provide enough independent evidence that the software counted what voters actually chose.
So How Hard is It to Change an Election?
Be careful with the usual reassurance that an attacker would have to compromise tens of thousands of machines one at a time. That's true for physical tampering, but it isn't how the only successful attack path works.
A compromise in the software build or loading process, the one route that worked in a test, is upstream of all the machines, so a single point of failure could reach many of them.
What actually makes a large-scale attack hard is the combination of everything around it:
- Insider access to the build or loading process is subject to inspection by parties, prosecutors, the Federal Police, and universities.
- Avoiding detection by the authenticity test, the integrity test, and the signature checks.
- Surviving the paper trail: thousands of posted BUs that any party or citizen can photograph and compare with the published totals.
- Silence from developers, auditors, rival parties that inspect the code, and the people who collect the BUs.
That doesn't make it impossible. No system is 100% secure. But it makes it extremely costly, and it makes the attack look less like hacking and more like a conspiracy among rivals. The BU check is the part ordinary people can do themselves, and it only works if people actually collect and compare the BUs.
Conclusion
Linux gives the machine a solid, minimal foundation. But the weak points lie in how the system is configured, sealed, audited, and administered.
The operating system won't stop an organization from reusing one key across hundreds of thousands of machines or forgetting to disable an old account. Those are human problems, and they're harder to patch.
Resources:
- Copas YouTube Channel
- Electronic ballot box: see how it works and how the vote is protected
- Inside the electronic voting machine - CodeBit
- Electronic voting in Brazil - Wikipedia
- TSE Disassembles Electronic Voting Machine - TV Senado
- Software Vulnerabilities in the Brazilian Voting Machine - USENIX
- Hackers break into Electoral Justice system and take confidential data - Estadão
- 'There's no evidence of fraud,' says Diego Aranha, a champion of print voting that inspires Bolsonarist speech - Correio Braziliense

