Ireland bought a national e-voting system, then couldn't prove it worked
Ireland spent millions on voting machines that sat in a warehouse for five years, then got scrapped — because an independent commission couldn't prove they worked.
It is the spring of 2004, and a warehouse somewhere in Ireland holds the future of Irish democracy — still in its original packaging.
The Irish government had procured roughly 7,500 Nedap/Powervote electronic voting and counting machines. The deal cost tens of millions of euros. The machines had passed the vendor's own tests. Elections were scheduled. Polling-station staff had been trained. The government was ready to go.
There was one problem. An independent Commission on Electronic Voting had been asked to review the system. And when it looked closely, it could not say the machines worked.
Not "the machines are broken." Not "we found fraud." Something more unsettling than either: we cannot satisfy ourselves, to the requisite degree of confidence, that they work.
That sentence — measured, technical, devastating — is the one that stopped an entire national e-voting program. The machines were mothballed. In 2009 they were formally scrapped. And the question the Commission raised has never gone away.
"Not proven" is not the same as "fine"
The Commission on Electronic Voting's 2004 Interim Report was not a conspiracy theory. It was not a political hit job. It was a group of independent experts tasked with a specific question: can we verify, to our satisfaction, that this system is accurate and secret?
Their answer: no.
The Commission was explicit that its conclusion was not a finding that the system would not work. It was a finding that the system had not been proven to the Commission's satisfaction that it would work. That is a different and harder standard — and it is the right one.
Accuracy means: does every vote cast become the vote counted? Secrecy means: can no one link a ballot to the voter who cast it? These are not exotic technical demands. They are the two non-negotiable properties of a legitimate election. And the Commission, after examining the Nedap/Powervote system as presented, could not confirm either one to its own satisfaction.
The Commission's Interim Report is a short document, and worth reading in full. What it does not say is as important as what it does. It does not say the vendor lied. It does not say the government acted in bad faith. It says: the evidence presented was not sufficient to allow independent verification. And for a device whose entire job is to produce a trustworthy count, "not independently verifiable" is a fatal defect — not a minor gap to be papered over with promises.
The machines went into storage.
The default should always have been: don't deploy unproven systems
Here is what the Ireland story makes concrete. The vendor said the machines worked. The government believed the vendor. A purchase was made, money was spent, training was conducted. The system was on the verge of being used to determine actual election outcomes for millions of Irish voters.
And then an independent body asked a simple question — can you prove it? — and the answer was no.
That sequence is backwards. Proof should precede deployment, not chase it. The Irish Commission, to its credit, treated "not yet proven" as sufficient grounds for "do not use." That is the correct default. The burden of proof sits with the system. An election authority that cannot demonstrate, to independent reviewers, that its technology is accurate and secret has not cleared the bar. It has simply chosen not to clear it before going live.
The Nedap/Powervote machines used in Ireland were the same manufacturer whose machines Germany used in its 2005 federal election — the Bundestag vote later challenged before the Federal Constitutional Court. In March 2009, the German court ruled that electronic voting machines whose operation cannot be independently checked by ordinary citizens, without specialist knowledge, violate the constitutional principle of public elections. The Bundesverfassungsgericht's judgment is careful and worth reading: it is not a ban on computers in elections. It is a requirement that whatever technology is used, citizens must be able to verify the essential steps from ballot to result for themselves. The Nedap machines failed that test in Germany's constitutional court five years after Ireland's independent commission had already reached the same conclusion by different means.
Two countries. Same machines. Same verdict. Neither required evidence of a specific fraud. Both reached the same result: unverifiable is unacceptable.
"Certified" is a claim, not a proof
The machines had been through vendor testing. Some version of a certification process had been run. The Irish government had signed off on a procurement. None of that was enough for the Commission.
This is not a quirk of the Irish case. It is the persistent gap at the heart of election-technology oversight.
In the United States, the GAO reported in 2005 — in the aftermath of HAVA, the law Congress passed to modernize elections after the 2000 mess — that federal efforts to improve electronic voting security and reliability were "under way but that key activities remained incomplete." The GAO report found that standards needed strengthening, certification procedures needed establishing, software repositories needed creating. Years after the crisis that prompted the reform, the machinery of assurance was still being built. "We use certified systems" was, at that moment, a claim about a process that was not yet fully operational.
Certification, done properly, is a meaningful check. Done as a formality — a box-ticking exercise by a body that lacks the access, time, or independence to genuinely probe the system — it becomes a liability. It creates the appearance of assurance without the substance. And appearances of assurance, in elections, are worse than admitted uncertainty: they stop people from asking harder questions.
The Irish Commission did not have the access it needed. What it was shown was not sufficient to verify the system's accuracy or secrecy. That gap — between what a vendor presents and what an independent reviewer can actually check — is what makes certification claims worth scrutinizing rather than accepting.
What "can't verify secrecy" actually means
Let's make this physical for a moment, because "secrecy" can sound abstract.
A voting machine that cannot be independently audited for secrecy is one where you have to take the vendor's word that your vote is not linkable to you. In practice, that means: if the software records not just which candidate received a vote but also an identifier connecting that vote to the specific terminal, smart card, or timestamp that produced it, that information exists inside the machine. If you cannot inspect the code — and on a proprietary system, you cannot — you cannot confirm it does not.
This is not a hypothetical vulnerability. In 2006, Princeton researchers examined a real Diebold AccuVote-TS machine and found that malicious code could be installed in under a minute of physical access, and that the code could alter vote tallies while keeping all internal logs consistent. Their paper showed a working vote-stealing virus that could spread automatically between machines during normal election activity. The audit logs would look clean. The totals would look plausible. Nothing from the outside would catch it.
The Irish Commission did not have to find a specific vulnerability to reach its conclusion. It only had to fail to rule one out. That is how independent technical review is supposed to work: the system must demonstrate its trustworthiness, not merely assert it. Absence of a confirmed attack is not the same as confirmed absence of the possibility of attack.
The Netherlands learned the same lesson, with better follow-through
Ireland was not alone in this reckoning. The Dutch government commissioned its own independent review — the Korthals Altes Commission — which reported in September 2007 under the title Stemmen met vertrouwen: "Voting with confidence." Its conclusions were unambiguous.
The Commission set out that there are no secrets in the election process — meaning that the mechanics of how votes are cast and counted must be observable and checkable, not hidden in firmware. It concluded that paper ballots in a polling station are preferable from the standpoint of transparency and checkability, and that any electronic method is acceptable only if it produces a paper record the voter can inspect.
The Dutch commission's report reached its conclusion after public controversy, after activists called "We do not trust voting computers" demonstrated live how easily the machines leaked radio signals that could reveal how someone had voted. The 1997 regulation approving voting machines was withdrawn. The Netherlands returned to paper and manual counting.
What the Netherlands did that Ireland, arguably, did not get the chance to do — because the machines were stopped before deployment — was make the political commitment explicit and durable. The default shifted. The burden of proof switched from "prove the machine is broken" to "prove the machine can be independently verified." When that proof could not be furnished, the answer was paper.
The deeper problem: who gets to decide what "proven" means?
Here is the question the Ireland case leaves open, and it is not a comfortable one.
The Commission on Electronic Voting existed because someone decided to create it. An independent body was empowered to say "not yet." In Ireland in 2004, that mechanism existed and was used. The machines were stopped.
But that outcome was not structurally guaranteed. It depended on a government willing to commission a genuine independent review, an independent commission willing to reach an inconvenient conclusion, and a political environment that accepted that conclusion rather than overriding it. Remove any of those three elements and the machines go live. Elections are decided by a system no one outside the vendor's offices has meaningfully verified. The results are announced. Officials say the system is certified. And the question of whether it actually works disappears into the archive.
That is the live risk in every jurisdiction that uses proprietary, closed voting technology: the verification infrastructure is optional and episodic, not structural and continuous. An independent commission can be created or not created. A review can be funded generously or given a weekend and a stack of PDFs. An inconvenient finding can be accepted or quietly buried.
The fix is not to trust that the right commission will be created at the right moment. The fix is to build systems where the proof is not held inside a vendor's proprietary black box but is publicly inspectable, mathematically verifiable, and checkable by anyone — not just the experts the government chooses to hire this particular cycle.
Los Angeles County's VSAP system, certified by the California Secretary of State in 2018, is a concrete example of a different direction: publicly owned, open-source code that outside experts can inspect rather than merely being told about. That is not a complete solution — implementation, chain of custody, and ongoing audits all still matter — but it removes one core layer of opacity. The Irish Commission's problem, put simply, was that the vendor controlled what the Commission could see. Open-source code cannot play that game.
What the Irish warehouse actually teaches us
The 7,500 machines sat. They were never used. They were eventually sold for scrap — the Irish state is reported to have recovered a fraction of what it spent procuring them.
The optimistic reading of that story: the system worked. An independent commission did its job, reached an honest conclusion, and the government listened. No election was ever run on an unverified system. Democracy was protected.
The honest reading: Ireland got lucky — lucky to have created a commission with real independence, lucky the commission had the backbone to say "no," lucky the political cost of overriding that verdict was too high.
A system that depends on luck is not a system. It is a series of things that can go wrong.
The real lesson of the Nedap/Powervote machines sitting in their unopened boxes is not that Ireland made the right call — though it did. The lesson is that the right call required a chain of independent, institutional checks that could just as easily have not been there.
The default for an unproven system must be: don't deploy. Not "deploy and audit later." Not "deploy and trust the vendor." Not "deploy and wait for a problem to surface." Don't deploy. The burden of proof is on the technology, and it must be discharged before votes are cast — by independent reviewers with genuine access, not by the vendor's own documentation.
And "independent verification" cannot mean a single commission, convened once, whose conclusion can be accepted or ignored. It must mean published, machine-readable, cryptographically checkable evidence that any qualified observer — not just the ones the government hired — can inspect at any time.
Until that bar is met, "the system is certified" is a sentence that deserves exactly as much trust as the Irish Commission gave it.
Which is to say: not very much at all.
Want to see how the 'unverified certification' gap plays out across the world? Explore our global elections atlas. Or read the two-minute version of why certification claims need independent scrutiny: the gaps, explained. For a deeper look at what verifiable voting actually requires, start here.
Sources
- Commission on Electronic Voting — Interim Report on the Secrecy, Accuracy and Testing of the Chosen Electronic Voting System (Houses of the Oireachtas Library)
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Bundesverfassungsgericht, Press Release No. 19/2009 (English)
- Adviescommissie inrichting verkiezingsproces (Commissie Korthals Altes), 'Stemmen met vertrouwen', 27 September 2007
- GAO-05-956, 'Elections: Federal Efforts to Improve Security and Reliability of Electronic Voting Systems Are Under Way, but Key Activities Need to Be Completed' (Sept. 21, 2005)
- Feldman, Halderman & Felten — Security Analysis of the Diebold AccuVote-TS Voting Machine (USENIX/EVT)
- California Secretary of State news release (Aug. 21, 2018): certifying LA County VSAP Tally as California's first certified open-source election technology