← All posts

Federal auditors warned the voting-security safeguards weren't finished. In 2005.

In 2005, federal auditors told Congress the safeguards meant to secure your electronic vote still didn't fully exist — and "we use certified systems" was a promise without a working check behind it.

It is September 21, 2005, and somewhere in Washington a 107-page report has just been transmitted to congressional committees. It carries no partisan signature. It was written by career auditors at the U.S. Government Accountability Office — the same agency Congress sends in when it wants to know if the government is actually doing what it said it would do.

The report is titled Elections: Federal Efforts to Improve Security and Reliability of Electronic Voting Systems Are Under Way, but Key Activities Need to Be Completed.

Read that title again. Not "efforts have succeeded." Not "key activities have been done." Need to be completed.

The year is 2005. Five years after a hanging chad nearly brought American democracy to a halt in a Florida recount. Three years after Congress passed the Help America Vote Act and created the Election Assistance Commission specifically to fix this. And the federal auditors are telling Congress: the machinery for assuring that electronic voting systems are secure and reliable is still, right now, being built.

That word — incomplete — is the subject of this post.


The check that was supposed to exist

Here is what "we use certified systems" is meant to reassure you of.

It is meant to mean: before your jurisdiction deployed that touchscreen or optical scanner, an independent body examined it against published technical standards, verified that the software and hardware met those standards, and issued a certification. When the machine counts your vote, it is not just a vendor's promise you are trusting — it is a documented, audited finding.

That is the theory.

In 2005, the GAO examined the reality. It found that key activities remained incomplete. Specifically, it recommended that the Election Assistance Commission act to:

  • Improve voting-system standards — because the ones in place were not fully adequate to the security challenges posed by electronic systems.
  • Establish certification procedures — because those procedures were not yet finished.
  • Create repositories for certified software — so that jurisdictions, auditors, and researchers could independently verify that what was running on a machine was actually what had been certified.
  • Share information about system vulnerabilities — because when problems were found, there was no reliable channel to get that information to the people running the machines.
  • Disseminate recommended security practices — because best practices existed, but getting them to local election officials was not yet a functioning system.

Read the full GAO report here.

Every item on that list is a building block of the claim "our systems are certified." Every incomplete item is a hole in that claim. Not a partisan claim. Not a conspiracy. A finding by the federal government's own independent auditors, addressed to Congress, in plain language.


Why the check mattered — and what happened without it

To understand why the GAO's findings bit so hard, you need to understand what was being deployed in American polling places at the time.

In 2006 — one year after the GAO report — researchers at Princeton University acquired a real Diebold AccuVote-TS touchscreen voting machine. Ariel Feldman, J. Alex Halderman, and Edward Felten demonstrated that an attacker with about a minute of physical access could install malicious code that would steal votes while altering all internal records, logs, and counters to stay consistent. They built a working voting-machine virus that could spread from machine to machine during normal election activity. AccuVote-TS-family machines were, at the time, among the most widely used in the United States.

These machines had been certified.

The certification existed. The standards it was measured against — those were the ones the GAO found still needed improvement. The software repositories that would let anyone verify the certified code matched the running code — those were the ones the GAO found still needed to be built. The vulnerability-sharing channels that would push a discovery like Princeton's out to every jurisdiction using those machines — those were the ones the GAO found still needed to be created.

Certification without a complete, enforced, publicly verifiable framework is not a guarantee. It is a label.


The disappeared votes — and nothing to check them against

The same year Princeton's researchers were running their tests, something went wrong in Sarasota County, Florida.

In November 2006, voters cast ballots in one of the closest congressional races in the country — Florida's 13th District, ultimately decided by 369 votes. In Sarasota County, roughly 18,000 ballots showed no recorded choice in that race. Thirteen percent of all ballots cast in the county. The machines were ES&S iVotronic touchscreen DREs — paperless, leaving no independent voter-verified record.

The GAO was called in. Its tests did not find a machine malfunction that caused the undervote. But — and this matters — the GAO's own report on the investigation noted that a voter-verified paper trail could have provided independent confirmation that the touchscreens recorded votes correctly.

In other words: the only way to know whether 18,000 votes vanished into a machine error, a software flaw, or a design quirk was to check the machines against an independent record. There was no independent record. The certification process that was supposed to catch problems like this was the one the GAO had just told Congress was incomplete.

The race was certified. The 18,000 undervotes were never explained.

GAO testing report on the Sarasota undervotes.


What "certified" was actually built on

The Help America Vote Act of 2002 — passed in the urgent aftermath of Bush v. Gore — created the Election Assistance Commission and mandated minimum standards for voting systems. The statute is real. The money was appropriated. The intent was genuine.

But HAVA created the architecture for a certification regime. It did not, by itself, build one. The EAC had to write the standards. Hire the testing labs. Establish the procedures. Build the software repositories. Create the vulnerability-sharing channels. Design the security-practice dissemination.

By September 2005 — three years after HAVA — the GAO found those tasks still unfinished. And in the meantime, states were purchasing and deploying systems under a certification framework whose foundations were still being poured.

This is not a scandal in the dramatic sense. Bureaucracies move slowly. Standards bodies argue over technical details. Laboratories take time to accredit. None of that is evidence of bad faith.

But it is devastating to the specific reassurance that officials were giving the public: our systems are certified. A certification process that is itself incomplete cannot fully certify anything.


The deeper problem the GAO was diagnosing

Here is the sentence worth screenshotting: "We use certified systems" is a claim. Whether it means anything depends entirely on whether the check behind it actually exists.

The GAO's role is institutional verification — a body that does not trust official statements but goes and looks. When it goes and looks at election-system security and comes back saying the key activities needed to support those systems' trustworthiness are still incomplete, that is not an anomaly in the system. It is the system working as intended, surfacing a gap that would otherwise stay invisible.

What the GAO found in 2005 is structurally the same problem that courts and independent researchers have found everywhere electronic voting has been examined without deference to official assurances.

In Germany in 2009, the Federal Constitutional Court ruled that the use of electronic voting machines requires that the essential steps of voting and counting can be examined by ordinary citizens without specialist knowledge — a standard that the machines in use failed. The court did not say fraud had happened. It said that the system's design made verification impossible, and that a democracy cannot run elections whose correctness can only be taken on faith. (Bundesverfassungsgericht, 3 March 2009.)

In Ireland, an independent commission examined the Nedap/Powervote system the government had purchased, found it could not satisfy itself as to the system's accuracy and secrecy, and declined to recommend its use. The machines were never deployed and were eventually scrapped. (Commission on Electronic Voting interim report.) The commission's conclusion was not "the system will fail." It was: the system has not been proved to work to our satisfaction. That is the correct epistemic standard — and the standard the GAO was also applying.

In the Netherlands, a government commission concluded in 2007 that transparency and checkability were non-negotiable foundations of a trustworthy count, and that electronic voting was acceptable only if it produced a paper record the voter could verify. The country dropped voting computers. (Adviescommissie inrichting verkiezingsproces, 'Stemmen met vertrouwen.')

Each of those judgments was saying, in a different legal and cultural language, exactly what the GAO said in plain American English in 2005: the framework for independently verifying these systems is not complete, and until it is, official assurances are claims without a functioning check behind them.


What completion actually looks like

It is possible to build a certification and verification regime that means something. The GAO's own recommendations are a blueprint: finish the standards, establish the procedures, build the repositories, share the vulnerabilities, disseminate the practices. Each step is achievable.

Beyond that, a handful of jurisdictions have shown what genuine verifiability looks like in practice.

Colorado in 2017 became the first state to complete a statewide risk-limiting audit — a statistical method that sizes the hand-verification sample to the closeness of the race, delivering a defined level of confidence rather than the false comfort of a fixed percentage spot-check. Colorado Secretary of State, November 2017. Georgia in 2020 hand-counted roughly 5 million ballots as part of a statewide audit and found the machine totals matched to within a tenth of a percent — not because officials said so, but because any observer could watch the counting. Georgia Public Broadcasting, November 2020. Los Angeles County built a publicly-owned, open-source vote-tally system — the first certified in California — so the code counting votes can be read and inspected by anyone, not just the vendor. California Secretary of State, August 2018.

These are not theoretical solutions. They exist. They have been run. They produce results that anyone can independently verify, rather than outcomes whose correctness depends on trusting that a certification process — somewhere, at some point — was complete.

That is the difference between a reassurance and a proof.


What is still not verifiable

The GAO report is now nearly two decades old. The EAC has continued its work. Standards have been developed and updated. Some states run rigorous post-election audits. Some do not.

But the GAO's core challenge has never been fully resolved at a national level, and the structural problem it identified — that the machinery for verification is what matters, not the presence of a certification label — remains live.

Here is what is still not independently checkable in most American jurisdictions:

Whether the software running on a certified machine is the same software that was certified. Without a functioning, public software repository linked to each certified version, a jurisdiction and its voters cannot independently verify this. Certification of version X is meaningless if version X+1 is what ran on Election Day.

Whether a machine that passed pre-election testing behaved identically on Election Day. Certification tests a machine at one point in time. Without continuous, independently verifiable audit trails tied to physical ballots, election-day behavior is attested by the machine itself.

Whether an undervote like Sarasota 2006's was a voter preference or a machine failure. Only a voter-verified paper trail, audited against the electronic totals by someone independent of the vendor and the jurisdiction, can answer that question. In a close race, the answer is the race.

The fix is not a better press release from an election authority. It is not a statement that the election was the most secure in history. The fix is a system whose outputs — precinct-level, machine-readable, tied to voter-verified paper — can be downloaded, checked, and reconciled by any member of the public, at any time, without asking anyone's permission.

That is what the GAO was asking for in 2005. It is still the right question.

See how this gap appears across different countries and systems →

Read the two-minute summary of what verifiable elections actually require →


Sources