← All posts

The country that un-invented the voting computer

In 2007, a Dutch government commission asked a simple question: can an ordinary citizen verify that a voting computer counted correctly? The answer changed how a country votes.

It is the autumn of 2006, and a group of Dutch activists called "Wij vertrouwen stemcomputers niet" — "We do not trust voting computers" — are standing in front of a television camera doing something that will embarrass a government.

They have obtained a Nedap voting machine, the same kind used across the Netherlands. On camera, they open it. They demonstrate that it can be manipulated. They show that its radio emissions can be detected from outside a polling booth, potentially revealing how someone voted. They are not researchers publishing in an academic journal. They are citizens, proving a point in public, on television, where the people who run elections have to watch.

The Dutch government did not dismiss them.

Within months, the government stripped approval from the machines in use and commissioned an independent advisory body — the Election Process Advisory Commission, chaired by F. Korthals Altes — to examine the entire question of how Dutch elections should be run. On September 27, 2007, that commission delivered its report. Its title was Stemmen met vertrouwen.

Voting with confidence.


What the commission actually said

The Korthals Altes commission did not produce a technical white paper for engineers. It produced a democratic argument.

It set out core requirements: transparency, checkability (controleerbaarheid), integrity, and ballot secrecy. It stated, with notable bluntness, that there are no secrets in the election process — that questions must be answerable and the answers must be checkable and verifiable. Not checkable in principle. Checkable by the public, in practice, without specialist knowledge.

Then it drew the line. Voting with paper ballots in a polling station is preferable from the standpoint of transparency and checkability. Any electronic method is acceptable only if it produces a paper vote the voter can personally check.

The voting machines in use did not produce that paper vote. They produced a number, stored in electronic memory, inside a sealed box, that an ordinary citizen had no way to verify. The commission concluded this was not good enough. The Dutch government agreed. The 1997 regulation that had approved voting machines was withdrawn.

The Netherlands went back to paper and pencil. Elections are now counted by hand.

That is an extraordinary thing for a modern, technologically sophisticated country to do. It is worth asking why they thought it was necessary — and what it means for every other country that did not follow them.


The thing the television cameras exposed

The activists' demonstration was not primarily about hacking. It was about a more fundamental problem: you cannot watch a computer think.

When a ballot goes into a paper box and is counted by a human being in a lit room, you can see the ballot. You can see the hand. You can dispute a judgment call. Every step is observable by anyone present — a candidate's representative, a journalist, a suspicious neighbor. The German Federal Constitutional Court put this precisely in its landmark 2009 ruling banning electronic voting machines: the essential steps of the voting and the determination of the result must be examinable by the citizen without any specialist knowledge. That is not a technical standard. It is a democratic one.

A voting computer fails it by design. You hand it your vote and it hands back a number. Between those two moments, something happened inside the machine that you cannot observe, and the machine does not show you its work.

The Dutch commission's answer was not "make better computers." It was "the requirement for public verifiability cannot be satisfied by any opaque machine, so remove the machines."

That is a harder conclusion than most governments have been willing to reach. But the logic is airtight.


What happens when there is no paper

To understand what the Netherlands escaped, look at what happened in Sarasota County, Florida in November 2006 — the same year the Dutch activists were making their television appearance.

Sarasota used paperless ES&S iVotronic touchscreen machines. On election night, the county reported roughly 18,000 undervotes in the race for Florida's 13th Congressional District — about 13 percent of all ballots cast showing no recorded choice for Congress. The race was decided by 369 votes.

There was nothing to recount.

The U.S. Government Accountability Office tested the machines and could not find a malfunction that explained the undervote. It also noted, carefully, that a voter-verified paper trail could have provided independent confirmation that the touchscreens recorded votes correctly. Without it, the question of what 18,000 voters intended was simply unanswerable. The result stood, and no one could prove it was right.

That is the no-paper gap in its starkest form: a close election, an anomaly that cannot be explained, and no independent record to check. Not a conspiracy. Not fraud. Just an irreducible uncertainty that eats at public confidence in exactly the races where public confidence matters most.

The Dutch commission had looked at this logical trap and decided: we will not build a system that can end up here. Paper is the insurance policy that makes the rest checkable.


Norway reaches a related conclusion, from a different angle

The Netherlands was not alone in stepping back from electronic voting after examining it closely.

Norway ran internet-voting pilots during the 2011 local elections and the 2013 parliamentary elections in twelve municipalities — carefully, as a supplement to paper voting, only during the advance-voting period. According to the responsible ministry, the pilots did not lead to increased turnout. The promised convenience dividend did not materialize.

In 2014, the Norwegian Ministry of Local Government and Modernisation decided to discontinue further internet-voting pilot projects. The government concluded that, absent broad political support for internet voting and given unresolved questions about whether votes could be verified as cast, it would be inappropriate to spend further time and money on additional pilots.

That phrase — unresolved questions about whether votes could be verified as cast — is doing a great deal of work. Norway is not a country with fragile institutions or a history of contested elections. It ran the pilots carefully, evaluated the results honestly, and concluded that if confidence that every vote is counted as cast cannot be secured, the channel is not worth the cost.

Notice what Norway and the Netherlands have in common: both made their decisions through transparent public processes, based on checkability as a non-negotiable requirement. Neither was responding to fraud. Both were responding to the impossibility of verifying that fraud had not occurred — which, it turns out, is the same problem.


The machine that couldn't be caught lying

For a sense of what "unverifiable" means at its most extreme, consider what Princeton researchers demonstrated in 2006. Working with a real Diebold AccuVote-TS touchscreen machine — then among the most widely deployed in the United States — Ariel Feldman, J. Alex Halderman, and Edward Felten showed that an attacker with about a minute of physical access could install malicious code that would steal votes, alter all logs and counters to stay internally consistent, and spread automatically to other machines through normal election activity.

The machine would not look broken. It would produce a tally. The tally would be internally coherent. Nothing in the machine's own records would flag a problem.

The only thing that could catch it would be a voter-verified paper record that the machine did not control — something the machine could not alter to match its own fraud. The AccuVote-TS did not produce one.

That is what the Dutch commission meant by "no secrets in the election process." If the record that proves the count is produced and stored entirely by the machine being audited, it is not an audit. It is the machine checking its own homework.


"We counted it by hand" is a reassurance, not a proof — unless the paper is there

Defenders of electronic systems often point to audits: hand counts, post-election reviews, risk-limiting audits. These are real improvements. Colorado ran the first statewide risk-limiting audit in 2017. Georgia hand-counted roughly five million presidential ballots in 2020, with the variation between the machine count and the hand count coming in at about a tenth of one percent.

But every one of these audit methods depends on the same thing: a durable paper record that the machine did not exclusively control. You cannot hand-count what was never printed. You cannot audit a memory card against itself.

Georgia's hand count worked because Georgia had voter-marked paper ballots. The hand count confirmed the machine tally because there was something independent to compare against.

Sarasota 2006 had no such comparison. Florida's 13th District had a 369-vote margin, 18,000 unexplained undervotes, and nothing to recount. The audit option was not available. It had been designed out of the system.

The Netherlands looked at this and made a choice: paper first, always, because without it the audit option you might desperately need does not exist.

There is a further complication that is worth naming directly. Even hand counts carry irreducible human error. The December 2020 hand audit in Antrim County, Michigan — a small county, roughly 15,700 ballots — produced a final count that still differed from the machine tabulation by about a dozen votes. Not thousands. Twelve. In a low-stakes county audit that confirmed an unambiguous result, that margin is harmless.

In a race decided by a handful of votes, a method that is itself off by a handful of votes cannot settle the question. "The hand count confirmed it" is a reassurance. It is not proof. The only thing that converts reassurance into proof is a system where anyone — not just the officials conducting the audit — can independently check the underlying records against a tamper-evident chain of custody.

That is the gap the Netherlands decided it could not live with. Paper plus a hand count is better than a black box. But paper plus a hand count plus a cryptographically verifiable chain of records that anyone can check is better still.


The deeper argument: replace trust with checkability

Every country that has stepped back from opaque voting technology has made the same observation, usually after a crisis: the problem is not that the machines are definitely wrong. The problem is that you cannot tell either way.

Germany's Constitutional Court said this in 2009, voiding the use of Nedap machines in the 2005 federal election. An election whose correctness rests on hidden software fails the public-verifiability test regardless of whether tampering is ever proven.

The Austrian Constitutional Court annulled the 2016 presidential runoff not because fraud was proven — it was not — but because the chain of custody for postal ballots had been broken in a way that made fraud impossible to rule out. The Court's logic: a result no one can verify is not a trustworthy result, even if the right person won.

Kenya's Supreme Court voided a presidential election in 2017 because the digital chain from polling station to national tally could not be checked against tamper-evident source records. The count could not be verified. The result was annulled.

The through-line is always the same. It is not about which party won. It is not about proving fraud. It is about whether the public — not the officials, not the vendor, not the Secretary of State — can independently check the count. When they cannot, the result rests on trust in the authority announcing it. And trust that cannot be tested is not confidence. It is deference.

The Dutch commission's lasting contribution was to insist on checkability as a prerequisite, not as a bonus feature. The result: a country that still votes with paper and pencil, whose elections can be observed from ballot to final tally by any citizen standing in the room, and whose government does not have to ask you to take its word for it.


What still cannot be verified — and what would fix it

Here is what is not yet solved, even in the Netherlands.

Hand-counted paper elections are verifiable in a strong sense: the ballots are physical objects, observed by multiple parties, and the count is watched in real time. But the process still relies on humans counting correctly, on complete chain-of-custody records for every ballot, and on the assumption that the ballots entering the count are the same ones voters marked. Human miscounts, incomplete custody logs, and late-stage substitution are all still possible.

The Dutch model is dramatically better than a paperless machine. It is not cryptographically provable in the sense that software-based end-to-end verifiable systems aspire to — systems where each voter can independently confirm their ballot was included in the final count without revealing how they voted, and where any observer can verify the total without seeing any individual's choices.

That gap matters most in close races. In a race decided by dozens of votes, a method that is itself off by a handful of votes cannot definitively settle who won. That is not an argument against paper. It is an argument for adding independent, mathematical verifiability on top of paper — for building a system where the public does not have to trust the count, because they can check it themselves.

The checkable fact is this: right now, in most jurisdictions, there is no such independent check available to you. The tally is published. An official says it is correct. A recount may or may not be available. The underlying audit trail may or may not be published in a form you can download and verify.

That is the verifiability gap — and it is closeable. What it takes is publishing precinct-level results instantly, in machine-readable form, against a tamper-evident chain of custody that any member of the public can independently reconcile. Not asking the public to trust the count. Showing them the count, in a form they can check.

The Netherlands walked back from the machine when it could not answer the question: can you prove this count is right?

That question is still waiting for a better answer than "trust us."


Curious how common the no-paper gap is globally? See the full picture across jurisdictions. Want the two-minute version of what verifiability means in practice? Start here. Or go deeper on what a real audit trail looks like — and what it doesn't — at our gaps page.


Sources