America spent billions to fix voting after 2000. Did it buy verifiability?
America spent $3 billion replacing punch-cards after the 2000 election chaos — but buying new hardware isn't the same as buying a count anyone can independently verify.
It is October 29, 2002, and a bill has just become law. In the eighteen months since a handful of hanging chads nearly brought American democracy to its knees, Congress has done something it rarely does at speed: agreed on a problem, written a check, and signed it. The Help America Vote Act — HAVA — authorizes roughly $3.9 billion in federal funds to modernize elections. It creates a new federal agency, the U.S. Election Assistance Commission. It promises minimum standards. It tells states to replace their punch-card and lever machines.
The question nobody pauses long enough to ask: replaced with what, exactly — and can the public check whether the replacement actually works?
That question is still open today.
The statute and its promise
HAVA was, in the language of its sponsors, a response to the chaos of Florida 2000. The law itself is explicit: federal money flows to replace punch-card and lever voting systems. Minimum administration standards will be established. The new Election Assistance Commission will test and certify voting equipment.
Read that list again. Every item is about process — funding, administration, standards, certification. None of it, in the text, guarantees that the machines replacing the punch cards will produce a record an ordinary voter can independently check.
That is not a cynical reading. That is the statute's actual architecture.
And it matters enormously, because the hanging-chad crisis of 2000 was never really about punch cards. It was about what Bush v. Gore actually exposed: a system with no uniform, publicly known standard for reading what a voter marked. Different counties applied different rules. Different canvassing boards held the same chad to different light. The Supreme Court found that identical ballots were being evaluated differently across the state — a violation of equal protection because it valued one person's vote over another's.
The problem wasn't the technology. It was the absence of a verifiable, uniform standard for what a marked ballot means.
HAVA addressed the technology. The deeper problem it carried, unresolved, into the digital age.
The GAO looked, three years later, and found the work unfinished
By 2005, the replacement machines were arriving in county courthouses and school gyms across the country. Electronic touchscreen voting was spreading. The federal apparatus HAVA had promised — testing laboratories, certification procedures, software repositories, security guidelines — was supposed to be in place.
It wasn't.
In a report issued September 21, 2005 — GAO-05-956 — federal auditors examined the security and reliability of electronic voting systems in the post-HAVA landscape. Their findings: documented problems with electronic voting systems had raised questions about their security and reliability. Federal efforts were under way, but key activities remained incomplete. The GAO recommended the EAC act to improve voting-system standards, establish certification procedures, create repositories for certified software, share information about system vulnerabilities, and disseminate recommended security practices.
Think about what that list means. Three years after HAVA, the agency created to certify that voting systems are secure had not yet fully built the apparatus for certifying that voting systems are secure.
The money had moved. The machines had shipped. The standards were still being written.
This is not a partisan finding. The GAO is the independent auditing arm of Congress; its job is to report what it finds, and what it found was a gap between legislative promise and operational reality. Replacing hardware did not automatically create verifiability. It created a new class of hardware whose verifiability was still being figured out.
What the new machines actually produced
Here is what mattered about the machines HAVA funded replacing punch cards with: many of them were paperless.
Sarasota County, Florida, 2006. A congressional race ends with a margin of 369 votes. Roughly 18,000 ballots cast in that county — about 13 percent — show no recorded choice in the race at all. The county used ES&S iVotronic touchscreen machines that produced no independent voter-verified paper record.
Nobody could check what happened. There was nothing independent to count. The GAO examined the systems and could not identify a machine malfunction — while noting that a voter-verified paper trail would have provided independent confirmation that the touchscreens recorded votes correctly.
HAVA had funded the replacement of an ambiguous, analog record (a chad) with no record at all.
That same year, Princeton researchers Ariel Feldman, J. Alex Halderman, and Edward Felten obtained a Diebold AccuVote-TS — one of the most widely deployed touchscreen machines in post-HAVA America — and demonstrated that an attacker with about a minute of physical access could install malicious code that would steal votes while altering all records, logs, and counters to stay internally consistent. They built a working voting-machine virus that could spread machine to machine during normal election activity.
The machine was HAVA-funded. It had passed the certification process that existed at the time.
Certified is not the same as verifiable. These are different words that do the opposite of the same job.
What "certified" actually certifies
The federal voting-system certification process that HAVA created — eventually administered through the EAC in partnership with accredited testing laboratories — tests whether machines meet a set of technical standards. Those standards have evolved over time and grown more demanding. That is real progress.
But certification tests a machine against a standard. It does not make the machine's internal workings visible to the public. It does not mean any voter or independent researcher can inspect the software counting the ballots. It does not mean a third party outside the certification process can check whether the tested machine is the same as the deployed machine.
Germany's Federal Constitutional Court understood this distinction precisely. In its 2009 ruling, it held that electronic voting is only constitutional if the essential steps of the voting and the determination of the result can be examined by the citizen reliably and without any specialist knowledge. The German machines had passed their own certification processes. The court ruled they still violated the public nature of elections because a citizen could not independently verify what had happened without trusting expert intermediaries.
The court's logic cuts directly at the HAVA framework: certification by experts, for experts, reviewed by experts, is not the same as verifiability by the public. A democratic election must be checkable by the people it is supposed to serve.
India's Supreme Court reached a similar fork in the road in 2024, when it tightened the rules around paper audit trails and chain-of-custody sealing for electronic voting machines — even while declining to abolish them. The court's direction of travel was clear: confidence flows from independently checkable evidence, not from official assurance.
The EAC's own guidance — the joint CISA statement issued after the 2020 election declaring it "the most secure in American history" — actually proves the point by accident. The statement's own reasoning rests on the existence of paper records that allow independent recounts and audits. It argues for security by citing verifiability. Which means the claim is only as strong as the paper trail behind it, and in jurisdictions where that trail is thin, the assurance floats free of its anchor.
The paper trail: necessary but not sufficient on its own
Congress noticed the paperless-machine problem. The Voter Confidence and Increased Accessibility Act, VVPAT legislation, and eventually evolving EAC standards pushed most jurisdictions toward voter-verified paper records — either optical scan ballots voters mark by hand or ballot-marking devices that produce a printed record.
This is progress. Paper is auditable. Georgia's 2020 hand count of roughly five million ballots — the largest manual audit in American history — confirmed the machine tally to within about a tenth of a percent. Colorado's statewide risk-limiting audit in 2017, the first of its kind, showed that statistical confidence in a correct outcome is achievable when you have durable paper to audit against.
But a paper printout is not automatically a voter-verifiable record. The U.S. District Court in Curling v. Raffensperger found that Georgia's ballot-marking devices produce a QR code that the tabulator reads — but that the voter cannot read. A hand recount audits the QR code's output. It does not audit what the voter intended to mark. If the machine silently encodes a different choice than the one displayed on screen, no amount of paper recounting catches it.
And even a clean optical scan with hand-marked paper carries irreducible human error. Windham, New Hampshire, 2021: a forensic audit ordered by the state legislature traced a miscount to folds through vote targets on absentee ballots — a folding machine had creased ballots in the wrong place, and the scanner read fold lines as filled ovals. No malware. No tampering. Just dust on a lens and a crease in the wrong spot, silently miscounting hundreds of validly marked ballots. The hand count recovered voter intent. But the hand count in Antrim County, Michigan's full presidential recount in 2020 still differed from the machine total by roughly a dozen votes out of fifteen thousand cast.
A method that is itself off by a handful of votes cannot definitively settle a race decided by a handful of votes. "The hand count confirmed it" is a reassurance. It is not proof in the mathematical sense.
The auditing gap HAVA didn't close
HAVA created a framework. The EAC built standards. Testing laboratories certify equipment. States must meet minimums for provisional ballots, identification, and registration databases.
What HAVA did not create — and what the certification apparatus still does not guarantee — is a system where an ordinary member of the public can independently verify, without trusting any single official or vendor, that the count is correct.
That gap shows up in concrete ways:
Voting-system software remains proprietary in most jurisdictions. You cannot read the code that counts your vote. Neither can your neighbor, your local journalist, or an independent security researcher who hasn't signed a nondisclosure agreement.
Certification tests machines before deployment, not after. It cannot confirm that the machine in the polling place on election day is running the same software the laboratory tested. Coffee County, Georgia, showed how easily a jurisdiction's entire voting system can be copied and removed by people who are let in the door.
Post-election audits — risk-limiting audits, hand counts, forensic examinations — are conducted by election officials and then reported. Their results are authoritative only if you trust the officials conducting them. For most jurisdictions, a member of the public cannot independently download precinct-level machine-readable results and reconcile them against a public, cryptographically signed record the moment results are final.
The EAC's own guidance urges officials to publish results in downloadable formats like .csv and .xml with clear labeling of ballot types. That is sound practice. Some states do it. Most do not do it in real time, with machine-readable data, signed in a form anyone can audit independently.
Los Angeles County's VSAP system, certified in 2018 as California's first open-source, publicly-owned election tally system, is a meaningful step: public ownership means the code counting the votes can be inspected by independent experts rather than shielded as trade secrets. Open code is not a complete guarantee — implementation and chain of custody still matter — but it removes one layer of enforced opacity. That is the direction of travel HAVA's original architects could have insisted on and didn't.
The real lesson of $3.9 billion
HAVA's money did real things. Punch cards are gone. Lever machines are gone. Provisional ballot rights exist. A federal agency sets baseline standards. Certification procedures, incomplete as they were in 2005, are more developed today.
But the statute's fundamental bet was that replacing hardware would solve a verifiability problem. It didn't — because verifiability isn't a property of any particular machine. It is a property of a system: the chain from ballot marking to result publication, with every link independently checkable by anyone who wants to check it.
You cannot buy verifiability. You have to build it into the architecture.
The Netherlands concluded that in 2007 — that transparency and a human-checkable record were non-negotiable foundations, not optional upgrades — and went back to paper and manual counting until something better could be proven. The German Constitutional Court drew the line at public intelligibility: if only an expert can verify the count, it is not a democratic election. Brazil institutionalizes public adversarial testing of its machines; outsiders are invited to break them before each election cycle, and fixes are made and re-checked.
America spent billions buying new machines and building a certification bureaucracy. The certification bureaucracy tests machines in a laboratory. It does not give you — the voter, the journalist, the independent researcher — a way to confirm the count yourself.
That is the question HAVA answered with money but not with architecture. And it remains, two decades later, the open question.
What would actually close it
The fix is not another hardware replacement cycle. It is not a more expensive certification laboratory. It is not a bigger federal agency with more staff.
It is a voting system designed so that its correctness is checkable by the public, not asserted by officials.
That means: voter-marked paper ballots whose marks are unambiguous and human-readable — not a QR code only a scanner can decode. It means routine, mandatory risk-limiting audits in every jurisdiction, not optional pilots in progressive states. It means precinct-level, machine-readable results published the moment each precinct's count is complete, in formats any spreadsheet can open — so the public can reconcile results as they are reported, not after officials have explained them. It means open-source vote-counting software that any security researcher can inspect without signing an NDA.
And it means treating "the Secretary of State certified the result" and "the audit confirmed it" as claims to scrutinize, not as conclusions. Because in a race decided by a handful of votes, a method that is itself off by a handful of votes cannot settle the question. Only a system the public can check independently can do that.
HAVA was a bill. Verifiability is an engineering requirement. They are not the same document.
Explore how this verifiability gap looks across different countries and systems: browse the global atlas, or read the 2-minute summary of what's missing and why it matters.
Sources
- Help America Vote Act of 2002, Pub. L. 107-252 (GovInfo)
- GAO-05-956, 'Elections: Federal Efforts to Improve Security and Reliability of Electronic Voting Systems Are Under Way, but Key Activities Need to Be Completed' (Sept. 21, 2005)
- Bush v. Gore, 531 U.S. 98 (2000), per curiam opinion (Cornell LII)
- U.S. GAO (GAO-08-97T) — Testing of Voting Systems in Florida's 13th Congressional District
- Feldman, Halderman & Felten — Security Analysis of the Diebold AccuVote-TS Voting Machine (USENIX/EVT)
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Joint Statement, Election Infrastructure Government Coordinating Council & Sector Coordinating Council (Nov. 12, 2020) (CISA)
- Curling v. Raffensperger, No. 1:17-cv-2989-AT, Opinion and Order (N.D. Ga. Oct. 11, 2020) (Justia)
- New Hampshire SB 43 Forensic Audit Report (July 2021), Hursti, Lindeman & Stark (via Internet Archive)
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia
- Colorado Secretary of State — A new kind of election audit: Colorado is first to complete it
- California Secretary of State — Certifying LA County VSAP Tally as California's first certified open-source election technology (Aug. 21, 2018)
- U.S. Election Assistance Commission — Election Results Reporting Quick Start Guide (PDF)
- Lawfare — What the Heck Happened in Coffee County, Georgia?
- Supreme Court of India — Association for Democratic Reforms v. Election Commission of India, 2024 INSC 341 (26 Apr 2024)
- Michigan Department of State — Final numbers from Antrim County audit affirm accuracy of election results