> provide access to 3rd party libs referenced in the source code
Yes. I don't know what those libraries are, what they do or where they come from. I can't find any information on the matter.
> They didn't say the machines that compile the source code had internet access
> they explicitly stated those machines had network access (which is completely different)
You're right. I hadn't noticed that.
> they might have access to local network and it's expected so they can fetch the libraries needed for compilation
We still need access to those libraries.
> I can't deny that a supply chain attack might be possible by corrupting one of these 3rd party libs
Good, we at least agree on this possibility. I can't prove it was actually exploited but this shows it's not "unquestionable".
> but there wasn't anything on their report that is as bad as you make it out to be
A supply chain vulnerability seems pretty bad to me. Especially for an "unquestionable" system. Everything they did to defend it against criticism is cast into doubt given this possibility.
> how they would try to come up with a supply chain attack just to mess up the elections to favor their candidate?
If they can mess up the system, the elections are invalid anyway. All prior elections too. Including Bolsonaro's victory in 2018.
> there were several different auditors when they had the auditing session, including universities and the federal police, the source code was provided to these auditors in 2021 and none found the issues the army pointed out
Well they didn't publish detailed reports like the armed forces did. Or maybe they did and I didn't see the reports. Do you know?
They said nothing about the network access either. Why? Seems like a glaring omission to me. All these auditors and not a word about network access during compilation?
> It's even pointed out by TSE that the army had access to the source code at the same time the other auditors had.
Did they look at those libraries? I can't find any information on them.
> There's nothing to worry about.
I wouldn't go that far. I want them to publish the real executable that ran on the machines on election day. That way we can reverse engineer it and look for malicious code. That's the true test. If the binary is genuine and no one finds anything, I'll accept the results and never again speak of this matter. Otherwise the possibility is gonna remain at the back of my mind.