Earlier quoted context omitted.
Well, are they wrong? When we filter out all the noise, that's what it comes down to. Are they wrong? > They found a couple of issues in the last year which had no impact on the election and wouldn't have. "A couple of issues" ? Does the voting machine software's build system NOT download unaudited proprietary manufacturer shared objects from the internet? Because that's the conclusion I came to after I read that doc…
https://www.gov.br/defesa/pt-br/centrais-de-conteudo/relator... they said they couldn't point to any security risks that would invalidate the whole process. I would like to read more about these findings, I can't find them anywhere and feel like I can only find them in alternative media sites.
Page 4, they recommend that access be given to the libraries referenced by the code. In other words, those libaries weren't audited.
Page 5, they say they noticed that the internet was accessed during the software compilation process for the purpose of downloading third party libraries. They outright say that this is an attack vector.
The rest of the document more or less verifies that everything is as expected after the final binary has been cryptographically signed. This is expected, any tampering necessarily occurred before the binary was signed.
Auditing source code doesn't matter given the nature of the attack vector. Protesters asking for source code will be embarrassed when they publish it and nothing is found. I'll only be satisfied if they publish the actual signed binary which ran on every machine on election day, the whole world looks at it with reverse engineering tools and finds nothing. Then I'll accept brazilian elections as legitimate.