← All posts

How a piece of paper in a box ended a century of open bribery

A piece of paper in a sealed box ended a century of open bribery — and now a phone camera is quietly undoing everything that paper was designed to prevent.

It is the summer of 1871 in an English market town, and a landlord is watching his tenants file past the poll. He knows how they voted. He has always known. The vote is called aloud, written in a book, and the book is published. If a tenant votes the wrong way, the landlord finds out by teatime. The lease renewal goes badly. The harvest contract disappears. There is no secret to protect — and so there is no protection at all.

Parliament had been watching this happen for decades. A series of reform bills had widened who could vote. None of them had addressed the bluntest problem: a vote you must declare in public is a vote you can be paid or threatened to cast.

One Act changed everything.


The mechanism of the Ballot Act 1872

On 18 July 1872, the Ballot Act 1872 (35 & 36 Vict. c. 33) received Royal Assent. Its long title is bureaucratic — An Act to amend the Law relating to Procedure at Parliamentary and Municipal Elections — but its machinery was revolutionary.

Voters now received an official, state-printed ballot paper. They entered a private compartment. They marked their choice with no one watching. The paper went into a sealed ballot box. The box was opened only by authorised officials at the count.

The poll book — that published ledger of who voted for whom — vanished.

What the Act understood, in mechanical terms that no amount of moral lecturing had ever achieved, is this: bribery and coercion are transactions, and every transaction requires a receipt. A landlord who pays a tenant sixpence for a vote needs to know the vote was delivered. An employer who threatens dismissal needs to be able to check the employee's compliance. Take away the proof of delivery and the market collapses. You can hand a voter sixpence, but you cannot verify what they did in that private compartment. The bet is unenforceable.

This was not a courtesy extended to voters. It was an architectural decision — a security feature built into the physical process to make a whole category of attack structurally impossible.

The model spread. What became known as the Australian ballot — a uniform, state-printed paper marked in private — had been pioneered in Victoria in 1856 for the same reason: public voting left people "vulnerable to intimidation and coercion." By the end of the nineteenth century, most democracies had adopted some version of it. They were not copying a courtesy. They were copying a weapon against coercion.

The ballot paper in its sealed box was that weapon. For about 150 years, it worked.


Why the box worked — and what the box could not do

Understand what the secret ballot actually guarantees, because this matters for everything that follows.

It guarantees unlinkability. Your identity goes on the register — you signed in, you received a ballot, your name was crossed off — but from the moment you stepped into that compartment, no one could link you to your vote. The marked paper and the person who marked it were formally separated. That separation was the whole point.

The sealed ballot box also provided something else: a durable, physical record. After the count, ballots were retained. If a result was challenged, the evidence existed. You could open the boxes and count again. The paper was the audit trail.

These are two different security properties — and they pull in different directions.

Secrecy means no one can prove how you voted.

Verifiability means someone can check that the count was correct.

The sealed paper ballot delivers both, but only under specific physical conditions: that the compartment was genuinely private, that the box was genuinely sealed, that the chain of custody was genuinely unbroken from the compartment to the count.

Break any of those conditions and one or both properties collapses. The Austrian Constitutional Court's 2016 annulment of a presidential run-off illustrates the verifiability side: around 77,000 postal ballot envelopes were opened prematurely and by unauthorised persons, a number exceeding the 30,000-vote winning margin. The court found no fraud. It annulled the election anyway — because a chain of custody broken in numbers that could have affected the result is a chain of custody that did destroy verifiability. The evidence of how those votes arrived could not be trusted.

The Austrian case was about the verifiability side of the box failing. The modern threat with mobile phones is about the secrecy side failing. And once secrecy fails, the market for votes reopens.


Albania, Georgia, and the live evidence that this is not history

If the landlord watching tenants at the poll feels like a Dickens novel, consider what international observers wrote down in 2021.

The OSCE's election-monitoring body — one of the world's most careful and least partisan — published its final report on Albania's 25 April 2021 parliamentary elections. It documented that "allegations of vote-buying by political parties were widespread during the campaign, leading to a number of investigations." It found "misuse of state resources and pressure on voters." Among its recommendations: guaranteeing the right to a free and secret vote and "preventing any form of pressure on voters to disclose whether and how they voted."

Preventing voters from disclosing how they voted. That is a nineteenth-century remedy being prescribed in a twenty-first-century democracy.

Three years later, the same body looked at Georgia's 26 October 2024 parliamentary elections and found something worse. Observers recorded "potential compromises" of ballot secrecy in 24 per cent of their observations due to how ballots were inserted into boxes, in 12 per cent due to how voters marked their ballots, and in 7 per cent due to inadequate polling-station layouts. The headline: issues with the secrecy of the vote were noted in over 30 per cent of observations. The mission concluded these issues "negatively impacted the integrity of the elections and eroded public trust."

Thirty percent. Not thirty percent fraud. Thirty percent of observed moments in which a voter's choice was, or plausibly could have been, observed by someone else. The architecture that was supposed to make coercion structurally impossible was structurally failing — not because the law was bad but because the physical process could not enforce what the law required.

This is not confined to countries outside Western Europe. The OSCE's 2023 report on Bulgaria — a full European Union member state — recorded "longstanding concerns over vote-buying and controlled voting," found secrecy compromised in 7 per cent of its election-day observations, and noted that law-enforcement agencies told the mission "obtaining evidence of vote-buying remains challenging and that most cases do not progress past the pre-trial stage."

The transaction still exists. The receipts are just harder to gather.


The phone camera is the new poll book

Now add a smartphone.

In 2016, a U.S. federal appeals court was asked to decide whether voters could photograph their own marked ballots. New Hampshire had banned ballot selfies. The state's defence, reviewed in Rideout v. Gardner, 838 F.3d 65 (1st Cir. 2016), was precise: secret-ballot reforms were adopted to "combat widespread vote buying and voter intimidation," practices that depend on a buyer or coercer being able to verify the vote. A photograph of a marked ballot lets a voter prove — to a third party, on demand, with precision — exactly how they voted.

The court struck the ban down on First Amendment grounds, finding no recent evidence that ballot photos had actually furthered vote-buying in that state.

But notice what the court did not dispute. It accepted the mechanism entirely. A photograph of your marked ballot is functionally a receipt for your vote. The court's disagreement with New Hampshire was about whether, on the current facts, that receipt was being redeemed — not about whether the receipt could be used that way if someone wanted to use it.

That is the theoretical door that a phone camera holds open. And it is a door that is already being pushed in practice.

The OSCE's 2017 report on Kyrgyzstan recommended that authorities "prevent any form of pressure on voters to disclose how they voted." The 2025 report on North Macedonia flagged "voter tracking on and around election day" — organisations recording who voted and following up to verify compliance. In an environment where a voter can be asked to send a photo of their marked ballot to confirm delivery, the phone camera is not a harmless novelty. It is the landlord's ledger, miniaturised.

Criminal penalties help at the margins. Courts can strike down selfie bans or uphold them. But prosecution requires evidence, evidence is hard to gather, and — as Bulgaria's law enforcement told OSCE — most cases never make it past the pre-trial stage. Criminal law is a slow and leaky bucket for a problem that is architectural in nature.

The Ballot Act 1872 did not solve vote-buying by making it more illegal. Open bribery was already illegal. It solved it by making verification impossible. Remove the verification mechanism and the illegality becomes unenforceable. Restore the verification mechanism — through a camera, through ballot design that lets a voter prove their choice, through inadequate booth screening — and the market reopens.


The harder problem: postal, remote, and phone-enabled voting

Every expansion of the ballot outside the private compartment reintroduces the verification risk. The compartment was not an inconvenience. It was the security perimeter.

The Tower Hamlets election court of 2015 found the London mayoral election void partly because of postal-vote fraud and bribery — practices that thrive precisely when the ballot leaves the controlled environment of the polling station. Postal voting moves the ballot to a kitchen table, a workplace, a landlord's anteroom, anywhere the voter can be watched, helped, or pressured. The sealed booth disappears. The secrecy guarantee is now procedural and legal rather than physical.

The North Carolina 9th District in 2018 produced the rare outcome of a U.S. House election set aside for fraud — built on a scheme involving absentee ballots collected and handled by a campaign operative. Chain of custody between voter and ballot box had been broken. The fix, after an investigation and indictments, was a new election.

New elections are expensive. They are disruptive. They are the last resort of a system whose preventive architecture failed.

Internet voting removes the booth entirely and leaves the voter at their phone or laptop, which can be monitored, screenshotted, and used to produce proof of a vote that a buyer or coercer can then verify. The Norwegian internet-voting trials — run in 2011 and 2013 — were discontinued in 2014. The ministry's conclusion: trust that votes would not be altered could not be secured, and the convenience did not deliver the promised turnout benefit. Norway quietly walked away from a system that could not guarantee what the 1872 ballot box guaranteed by physical design.

None of this is an argument against convenience in voting. It is an argument for being precise about what the compartment actually does and what must be preserved, in any system, to substitute for it.


What 'ballot not truly secret' really means — and who pays the price

When an international observer writes that ballot secrecy was compromised in 24 per cent of polling-station visits, they are not describing a legal technicality. They are describing a market in which a buyer or coercer can, with reasonable reliability, verify delivery of a purchased or coerced vote. They are describing an election whose margin might have been produced not by free choices but by verified transactions.

And here is the uncomfortable conclusion that no official statement reaches: you cannot verify the integrity of an election that cannot guarantee the secrecy of individual votes, because coercion and vote-buying operate precisely at the margin of close races.

The fix cannot be limited to training poll workers to position screens better, though that helps. It cannot be limited to prosecuting the ones who get caught, though that matters. The fix that is durable is the same fix that the Ballot Act 1872 reached: design the process so that verification is structurally impossible.

That means physical booths with genuine visual isolation. It means ballot handling that breaks the link between the person and the paper before anyone else sees the paper. It means postal and remote voting frameworks that are honest about their exposure and that build compensating technical controls — including, where the risk warrants it, rejecting convenience in favour of security.

And — the point that connects this to every other problem in election technology — it means precinct-level, machine-readable results published the moment they are final, so that anyone can check the aggregate count even when the individual ballot must remain secret. Secrecy and verifiability are not opposites. They are two separate guarantees that a well-designed system delivers simultaneously. Sacrifice either one and you are back in 1871, hoping the landlord isn't watching.

What is still not checkable, by you or anyone, in most jurisdictions:

  • Whether the booth you voted in was visually isolated from the angle of every other person in the room.
  • Whether the ballot paper you marked could have been seen as you folded it.
  • Whether the people running that polling station had a full and documented checklist for physical secrecy, checked and signed off by an independent observer.
  • Whether any voter in that precinct was photographed casting their ballot by someone positioned outside the screened area.

None of that is in the official results report. None of it can be reconstructed after the fact. The physical moment in the booth is, by design, unrecorded — which is exactly as it should be. But unrecorded also means uncheckable. And uncheckable means you are, once again, extending trust.

The landlord in 1871 knew how his tenants voted because the process let him find out. The ballot box took that away. The question worth asking about every voting arrangement today is simple: does this design make it possible for someone to find out how I voted? If the answer is yes — if a camera, a postal arrangement, an inadequately screened booth, or an online system hands that possibility to anyone — then we are not building on 1872. We are dismantling it.


Read the two-minute version of this argument at /simple. See where the 'ballot not truly secret' gap appears across different countries in our global mapping at /atlas. The full gap index is at /gaps.


Sources