ELINT · Electronic Intelligence

Ballot secrecy is certified as a data property. A September paper measures it as a radio one.

Researchers report recovering a candidate number from a Brazilian voting machine's display at about one metre, through a masonry wall, with a software-defined radio. The certification standard for voting systems does not test for that, because it defines secrecy in terms of records.

Emanation security has been a procurement question for four decades and an operational question for almost nobody. A preprint posted in September 2026 moves it. Researchers report that the candidate number displayed on a Brazilian electronic voting machine could be identified from an adjacent room, roughly one metre away, with a masonry wall in between, using a software-defined radio and a digital television antenna [1]. The equipment is a catalogue item. The distance is the length of a polling booth.

What the measurement says

The work is by Lucas Brito, Leonardo Teodoro, Pedro Tomaz, Alyson Isaluski, Leandro Hyeda and Saulo Queiroz, across the Federal University of Technology – Parana at Ponta Grossa, the Federal University of Goias, and Fraunhofer Portugal AICOS [1]. It is a preprint, not peer reviewed and not independently reproduced. Read the numbers as the authors’ own.

The target is the display, not the tabulation. The team used an Ettus USRP B200 with a digital television antenna against VGA monitors rendering the voting machine interface at 1280×768 and 1920×1080, both at 60 Hz [1]. At roughly one metre with a masonry wall between adversary and target, the candidate number could be identified. At under half a metre unobstructed, the image was reconstructed [1]. Greater distances with additional obstacles produced nothing intelligible.

That limit is the authors’ own. They state that the risk of violating ballot secrecy depends strongly on physical proximity between the adversary and the polling station, and their threat model reflects it: an adversary in an adjacent space, or a recruited insider carrying a portable radio [1]. This is not remote surveillance of an election. It is a room-scale problem with a room-scale answer.

The hardware is neither hobby money nor a national capability. The USRP B200 covers 70 MHz to 6 GHz continuously with up to 56 MHz of real-time bandwidth over USB 3.0, and lists at 1,462 US dollars [6]. It is the class of instrument that made passive emanation work reproducible outside signals intelligence agencies.

The gap is in the definition, not the equipment

What makes this operational is what the certification standards say. The US Election Assistance Commission’s Voluntary Voting System Guidelines 2.0 contain a dedicated principle on ballot secrecy. Requirement 10.2 states that the voting system does not contain nor produce records that can be used to associate the voter’s identity with the voter’s intent, choices, or selections [2]. A search of the document for emanation, emission or TEMPEST requirements returned nothing [2]. Ballot secrecy, as certified, is a property of records. The paper tests it as a property of radio frequency emissions. Only one of those measurements is in the test plan.

Civil electromagnetic compatibility rules do not fill the space. Section 15.109 of Title 47 caps radiated emissions from unintentional radiators: for a Class B digital device at three metres, 100 microvolts per metre from 30 to 88 MHz, rising in steps to 500 above 960 MHz [3]. Those limits exist so equipment does not interfere with other people’s receivers. A device can be fully compliant and still radiate a legible copy of its own screen, because compliance measures how much energy escapes, not what is encoded in it.

Defence acquisition treats the same physics as an information assurance requirement. DFARS clause 252.239-7000 obliges contractors to provide or use only information technology accredited to an established national TEMPEST standard, cites NSTISSAM TEMPEST 1-92, requires documentation on request, reserves the government’s right to test on site, and imposes a one-year correct-or-replace obligation [4]. The supporting policy at 239.7102-2 makes the requiring activity responsible for naming the standard, the markings, the inspection criteria, and a date through which accreditation is current [5]. Note the assumption: somebody upstream has already decided the threat applies, and the decision is documented and time-bounded. Civil election equipment has no equivalent chain.

The proximity bound is the next thing to fall

If the finding stopped at one metre it would be a facilities matter. A second September preprint attacks the bound itself. Haoran Yan, Ziyu Shao, Shuhao Zhang and Yan Long at the Hong Kong University of Science and Technology in Guangzhou, with Qinhong Jiang at Hong Kong Polytechnic University, describe injection-induced electromagnetic side channels, in which nonlinear components such as amplifiers, converters and transistors modulate secret electrical signals onto an injected carrier and upconvert low-frequency secrets into measurable emissions [7]. The paper is accepted to USENIX Security 2026.

The distinction is between listening and illuminating. Passive capture takes what a device happens to radiate, and attenuation sets the range. Active injection supplies the carrier, and the attacker chooses its frequency. The authors evaluate eleven commercial devices in five categories, reporting a maximum eavesdropping distance of 30 metres for headphone audio and six metres for wireless headphones and smart devices, at signal-to-noise ratios from about 6 dB to about 39 dB [7].

Those are not voting machines, and nothing here claims the technique has been demonstrated against one. The point is narrower: the assumption that emanation attacks are self-limiting because fields fall away with distance is an assumption about passive collection, and it is now being tested. The demanding end of this literature remains invasive by comparison. A Fraunhofer AISEC, German Federal Office for Information Security and Technical University of Munich team recovered ECDSA secrets from a Fairphone 4 only after removing the metal lid and plastic package over the system-on-chip [8]. Screens are far easier targets than keys.

What to do

The mitigations are physical and procedural, which makes them cheap and unglamorous. The authors recommend avoiding booth positions against walls with limited oversight, educating poll workers, voters and observers about software-defined radio hardware, and strengthening physical surveillance at polling locations [1]. Generalised for anyone running a facility rather than an election:

  • Treat the metre immediately outside a controlled space as part of it. Screen placement, booth orientation and what sits on the far side of a shared wall are emanation controls, and they cost nothing at the planning stage.
  • Ask whether your assurance requirement is written against records or against emissions. A framework that defines confidentiality only over stored and transmitted data puts emanations out of scope by construction, not by assessment [2].
  • Do not read electromagnetic compatibility certification as emanation security. Passing 47 CFR 15.109 or a regional equivalent says an appliance will not disturb other receivers, not that its display is illegible off-premises [3].

The timing is worth stating plainly. Brazil votes on 4 October 2026, with a second round on 25 October, and the electoral authority’s most recent public security test examined vote recording, transmission and source code, reporting no relevant inconsistencies [9]. The authority has separately restated a security model resting on regulated procedures open to political parties, the Public Ministry, the Federal Police and universities, on a Digital Vote Record storing each vote anonymously, and on seals produced by the national mint [10]. None of those controls is addressed by this paper, and it does not claim otherwise. Nothing here suggests a vote can be altered. What is in question is whether a vote can be observed.

The R3KONX view

Electronic intelligence is the discipline of reading equipment by what it radiates rather than by what it sends. It has spent thirty years as a state capability and a compliance annexe. Two September preprints put a 1,462-dollar radio against a monitor at one metre, and an injected carrier against consumer hardware at thirty [1][6][7]. For this region it matters less for elections – Malaysia votes on paper – than for the ordinary geometry of shared buildings: co-located tenants, serviced offices, operations centres with wall-mounted displays, diplomatic annexes with neighbours. The question is not whether a voting machine leaks. It is whether anyone has measured what your screens do, and against which definition of secrecy the answer was judged.

Sources

Every R3KONX article cites its primary material. 10 sources, in order of first citation. Links open the original publication.

  1. Do Electromagnetic Side-Channel Attacks Threaten Electronic Polling Stations? Scenarios and Recommendations Brito, Teodoro, Tomaz, Isaluski, Hyeda and Queiroz (UTFPR Ponta Grossa, UFG, Fraunhofer Portugal AICOS), arXiv preprint 2609.28209 · 2026-09
  2. Voluntary Voting System Guidelines 2.0 US Election Assistance Commission · 2021-02-10
  3. 47 CFR 15.109 - Radiated emission limits, general requirements Electronic Code of Federal Regulations, US Government Publishing Office · 2026-09-30
  4. DFARS 252.239-7000 Protection Against Compromising Emanations US Department of Defense, Defense Federal Acquisition Regulation Supplement · 2026-09-30
  5. DFARS 239.7102-2 Compromising emanations - TEMPEST or other standard US Department of Defense, Defense Federal Acquisition Regulation Supplement · 2026-09-30
  6. USRP B200 product specifications Ettus Research, an NI brand · 2026-09-30
  7. Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity Yan, Shao, Zhang, Jiang and Long (HKUST Guangzhou, Hong Kong Polytechnic University), arXiv preprint 2609.04785, accepted to USENIX Security 2026 · 2026-09-04
  8. Breaking ECDSA with Electromagnetic Side-Channel Attacks: Challenges and Practicality on Modern Smartphones Fraunhofer AISEC, German Federal Office for Information Security (BSI) and Technical University of Munich, arXiv preprint 2512.07292 · 2025-12
  9. TSE conclui teste publico de seguranca das urnas para as eleicoes de 2026 SBT News · 2025-12
  10. TSE reafirma mecanismos de seguranca das urnas eletronicas apos criticas ao sistema eleitoral O Povo · 2026-07-29

This article was researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveat: the central result is a preprint that has not completed peer review, the reported recovery distances are the authors' own and have not been independently reproduced, and the absence of an emanation requirement in the US Voluntary Voting System Guidelines 2.0 is a negative finding from a search of that document rather than a statement by its publisher. Corrections: event@r3konx.asia

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.