← All posts

Germany's top court: if only an expert can check the count, it isn't a real election

Germany's highest court ruled in 2009 that if understanding an election result requires a computer science degree, it isn't a democratic election at all — and the implications reach every voting system on earth.

It is the morning of March 3, 2009, and eight judges in Karlsruhe have just redrawn the line between a democratic election and a trusted performance of one.

The German Federal Constitutional Court — the Bundesverfassungsgericht, the closest thing Germany has to a supreme arbiter of what the Basic Law actually means — has just handed down its ruling on whether the Nedap voting computers used in the 2005 federal election were constitutional. The judges are not writing about a hack, a stolen election, or a broken machine. They are writing about something quieter and more fundamental.

They are writing about whether ordinary citizens could check what happened.

The answer the Court gave was no. And so the machines had to go.


"Without any specialist knowledge of the subject"

The Court's reasoning is compact enough to quote directly. It held that the use of electronic voting machines requires that "the essential steps of the voting and of the determination of the result can be examined by the citizen reliably and without any specialist knowledge of the subject."

Read that again slowly.

Not examined by auditors. Not examined by the vendor. Not examined by a government-certified lab. Examined by the citizen, reliably, without specialist knowledge.

This requirement, the Court explained, flows from the Öffentlichkeit der Wahl — the principle of the public nature of elections — embedded in Article 38 of the Grundgesetz in conjunction with Articles 20.1 and 20.2. The principle is not a technicality. It is a statement about who elections belong to.

The Nedap machines failed this test because they stored votes only in electronic memory. There was no independently verifiable record a voter could inspect. When the election was over, what you had was a number on a screen, produced by a process that lived entirely inside a black box. You could trust it. You could not check it.

In the German Constitutional Court's view, those two things are not the same.


Why this ruling cuts deeper than it looks

Official reactions to the judgment tended to focus on the outcome: Germany went back to paper ballots and hand counting, case closed, problem solved.

That is the least interesting part.

The deeper argument the Court was making is that verifiability is not an optional feature of a legitimate election — it is a definitional requirement. An election whose result only an expert can inspect is not an election in any meaningful democratic sense. It is a ritual performed with expensive equipment, and you are invited to applaud the result.

Notice what the Court did not say. It did not say the Nedap machines produced wrong results. It did not find evidence of tampering, fraud, or malfunction in the 2005 Bundestag election. In fact, precisely because no concrete harm could be demonstrated, the Court declined to invalidate the 2005 results themselves.

But absence of proof of wrongdoing was not the point. The point was that the structure of the system made independent verification impossible, and a system that makes verification impossible fails the constitutional standard regardless of whether anything actually went wrong.

That distinction matters enormously. It means the Court was not arbitrating between a claim of fraud and a denial of fraud. It was setting a floor. Below that floor, the question of whether fraud occurred is one you simply cannot answer — because you have built a system that cannot be checked.


The problem is the opacity, not just the machine

To understand why this matters beyond Germany, think about what "checking the count" actually requires with a paper ballot system. You watch the votes being cast. You watch the box being sealed. You watch it opened at the count. You watch a human being pick up a piece of paper, read it, and call out a name. If you disagree with what they call, you can look at the paper yourself.

None of this requires a university degree. None of it requires trusting a certification body or a vendor or a secretary of state. The full chain from voter to declared result is human-scale and observable.

Now think about what happens when a voting computer replaces that chain. The vote goes into software. The software runs on hardware. The hardware is certified — by a process you did not observe, carried out by experts you did not choose, against a standard you probably have not read. The "count" is the software's output. You are invited to trust it.

This is what the German court was pointing at. The opacity is not incidental to the technology; in most deployments, it is intrinsic to it.

The Netherlands arrived at the same conclusion through a different route. In 2007, the Dutch government's Election Process Advisory Commission published its report, Stemmen met vertrouwen — "Voting with confidence." Its core position: there are "no secrets in the election process" and questions must be answerable with checkable, verifiable answers. The Commission concluded that paper ballots counted by hand are preferable precisely because of their transparency and checkability, and that any electronic method is acceptable only if it produces a paper record the voter can physically inspect. The Netherlands withdrew approval for its voting machines and returned to paper.

Two neighboring European democracies. Two independent reviews. One conclusion.


What lives inside the black box

It is worth being precise about what makes an opaque voting system dangerous — not because the machines are necessarily compromised, but because there is no way to tell either way.

In 2006, Princeton researchers Ariel Feldman, J. Alex Halderman, and Edward Felten obtained a real Diebold AccuVote-TS voting machine — one of the most widely deployed in the United States at the time — and spent a few months with it. What they found was that an attacker with roughly sixty seconds of physical access could install code that would steal votes while keeping all internal logs, counters, and records internally consistent. The machines would show nothing wrong. A second finding was worse: the code could spread from machine to machine through memory cards during ordinary election-night activity.

The critical phrase is "internally consistent." A machine can lie without contradicting itself. Which means an audit that only checks the machine's own records can confirm the lie.

In Georgia in 2020, a federal court examining the state's Dominion ballot-marking system found something structurally similar. The system tabulates votes from a QR code printed on each ballot. The QR code cannot be read by the voter. A federal judge found the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter." A hand recount in Georgia audits the barcode's output. It does not audit the voter's intent.

The German court's principle, applied: if you cannot read what is being counted, you are not checking the count.


"Voting with confidence" is a slogan. Checkability is a mechanism.

Ireland's experience adds a third data point. The Irish government purchased 7,500 Nedap voting machines — the same family the German court would later rule unconstitutional — and asked an independent commission to assess them before their first national deployment. The Commission concluded it could not recommend the system with "the requisite degree of confidence." Not because it found the machines were broken. Because it could not satisfy itself that they would work correctly. The distinction matters: the absence of known problems is not the same as independently demonstrated reliability. The machines sat in a warehouse for five years and were scrapped in 2009.

Three countries — Germany, the Netherlands, Ireland — reached essentially the same conclusion through constitutional review, government commission, and independent assessment respectively. The common thread is not anti-technology sentiment. It is the demand that the public be able to verify, not merely trust.

Now consider what happens when that demand is not met.

Venezuela's 2017 National Constituent Assembly election was run on Smartmatic's automated voting system. On August 2, 2017, Smartmatic's chief executive issued a public statement announcing that the turnout figure declared by the government had been manipulated — by at least one million votes, in the company's estimate. Smartmatic said it "knew without any doubt" the numbers had been altered.

The vendor disowned the result run on its own equipment. And because independent audit was unavailable — because the system was a black box to everyone outside the ruling authority — citizens and international observers had no mechanism to confirm the true figure. They were left with one official claiming a number, one company disclaiming it, and no third path to the truth.

That is what opacity looks like at full scale.


"The audit confirmed it" — what that phrase actually means

There is a version of the official reassurance that sounds stronger than the Venezuela scenario: "we conducted an audit, and everything matched." It is worth asking what this guarantees.

In Georgia in 2020, after a presidential election decided by fewer than twelve thousand votes in a state of 10 million, election officials conducted a full manual hand tally of all roughly five million presidential ballots. The variation between the machine count and the hand count was about a tenth of one percent — a genuine achievement of scale and speed, carried out under enormous pressure.

But even here, the story is not quite "the gold standard confirmed the machine." The hand count confirmed the outcome. Whether it confirmed every individual vote is a harder question. In Antrim County, Michigan — a smaller test case that same year — a hand audit of roughly 15,700 presidential ballots still differed from the machine tabulation by about a dozen votes. Twelve votes sounds trivially small. In a race decided by twelve votes, it is the entire margin.

The Windham, New Hampshire forensic audit of 2021 documented how a machine miscount in the hundreds — not caused by fraud, not caused by malware, caused by a crease in folded absentee ballots that optical scanners read as marked ovals — was only discoverable because durable paper ballots existed and a physical hand count could recover voter intent.

The German court's standard is not that a manual recount is perfect. It is that the essential steps must be checkable by any citizen without specialist knowledge. A hand count meets that test imperfectly but genuinely — which is exactly why it caught Windham and confirmed Georgia. A paperless machine count, or a count audited only against a QR code no voter can read, does not meet the test at all.


The principle, taken seriously, points somewhere specific

The German court's ruling does not prohibit electronic voting technology. It prohibits unverifiable electronic voting technology. The distinction is important, because it points toward what a compliant system would look like.

Los Angeles County's VSAP system — the first publicly-owned, open-source election tally system certified in California, formally certified in August 2018 — represents one direction: public ownership of the code, open inspection by independent experts, rather than proprietary software shielded as a trade secret.

Brazil's electoral court runs an annual Public Security Test in which qualified outside investigators are invited to probe its electronic voting machines for weaknesses, with fixes implemented and re-tested before the election. The logic is the reverse of "trust our certification": it is "try to break it, publicly, and we will show you what we fixed."

Switzerland published its internet-voting source code in 2019 precisely to invite independent review — and within weeks, cryptographers Sarah Jamie Lewis, Olivier Pereira, and Vanessa Teague found a trapdoor in the shuffle proof that would have let an insider alter votes while producing a proof that appeared to pass verification. The system was suspended. The flaw was only findable because the code was public.

The pattern is consistent: verifiability is not a property that officials can assert — it is a property that must be demonstrable by outsiders. An official statement that a system is secure is a claim. Independent, adversarial testing that confirms or refutes it is evidence.


What is still not verifiable — and what would fix it

Here is what the German court's principle, applied rigorously, would require you to be able to do after any election: trace your vote — anonymously but verifiably — from the moment it was cast to the final count, using only the public record and your own eyes. No specialist degree. No trust in any official. No vendor assurances.

Most election systems in use today cannot pass that test. Many still count on software whose source code is a vendor trade secret. Many produce paper records, but paper records the counting software does not actually read. Many publish aggregate totals but not the precinct-level, ballot-by-ballot data that would let any citizen reconcile the numbers from the bottom up.

The U.S. Election Assistance Commission notes that election-night results are always unofficial and incomplete — which is fine, provided the final certified results are then published in machine-readable, precinct-level form that anyone can download and check. NCSL records that most states report at the precinct level. But "published somewhere" and "independently, cryptographically checkable" are not the same thing.

The German Constitutional Court gave the world a clean legal statement of what an election must be. If only an expert can check the count, it isn't a real election. Fifteen years later, that standard is still more aspiration than practice in most of the democracies that claim to share it.

The question is not whether your election authority is trustworthy. The question is whether their trustworthiness is something you have to take on faith — or something the system lets you verify yourself.

Those are different questions. And only one of them has a democratic answer.


See where your country stands on the verifiability gap — and what a checkable system would look like — at /atlas. For the two-minute version of why verifiability beats trust, start at /simple. And for a deeper map of specific gaps in election technology worldwide, see /gaps.


Sources