Not all paper trails are equal: the receipt you can read vs. the one you can't
You voted. The machine printed a receipt with your choices—and a barcode you cannot read. A federal court confirmed: the barcode, not the words, is what gets counted.
It is the morning of November 3, 2020, and somewhere in a polling station in Gwinnett County, Georgia, a voter is standing in front of a Dominion ballot-marking device. She touches the screen. She makes her choices. The machine prints a paper ballot — a real, physical piece of paper she can hold. She can read candidate names on it. She feeds it into the scanner.
What she cannot read is the QR code printed alongside those names.
That barcode is what the scanner actually counts. Not the human-readable text. The barcode. And if something between her screen taps and that barcode went wrong — if software, malicious or merely buggy, encoded a different choice than the one she made — she would have no way to know. The paper in her hand, the thing she just "verified," would tell her nothing she could check.
That is not a hypothetical concern. A federal court said so, on the record, in October 2020.
A Court Reads the Receipt — and Finds It Unreadable
In Curling v. Raffensperger, the U.S. District Court for the Northern District of Georgia reviewed expert testimony about Georgia's Dominion ballot-marking-device system. The court's October 11, 2020 Opinion and Order was direct: the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter."
The court also quoted the National Academies' 2018 conclusion — that no technical mechanism currently exists to ensure a vote-counting application produces accurate results, and that testing alone cannot ensure a system has not been compromised.
Expert testimony, including from Dr. J. Alex Halderman, described the practical feasibility of a cyber attack that could swap or delete votes by altering the QR code. An attacker who got into the ballot-marking software — even briefly, even remotely — could encode a different choice without changing a single human-readable word on the printed page.
The court did not order Georgia to switch to hand-marked paper ballots before November 2020. The election was weeks away. Last-minute system changes carry their own risks, and courts weigh those. That is a reasonable judicial decision about timing. It is not a clean bill of health for the system.
The deeper point stands undisturbed: a paper trail you cannot read is not a voter-verifiable paper trail. It is a receipt for a transaction you cannot audit.
See how the QR-code gap fits a global pattern of unverifiable systems
What "Voter-Verified" Actually Means — and What It Doesn't
The phrase "voter-verified paper audit trail" — VVPAT — sounds reassuring. It implies that voters check something, that paper exists, that audits happen. In practice, those words can describe systems that are miles apart.
Think about what verification requires. The voter must be able to read the record. The record must encode intent — the actual choices the voter made — in a form the voter can confirm before casting it. And any audit of that record must count the human-readable intent, not a machine's translation of it.
A QR code fails all three tests simultaneously. The voter cannot read it. It encodes machine output, not directly visible intent. And an audit that scans the barcode is auditing the machine's encoding, not the voter's mind.
Now compare that with a hand-marked paper ballot. A voter marks an oval next to "Candidate X." The oval is the record. The voter can see it. An auditor can see it. A court can see it. No translation layer exists between the voter's act and the counted artifact. Georgia's 2020 hand count — in which 159 counties manually tallied roughly 5 million presidential ballots over less than six days — worked because those ballots were marked by hand and the human-readable mark was the vote. The variation between the machine count and the hand count was about a tenth of one percent, which is worth knowing, and the hand count confirmed the outcome to whatever confidence level a human manual process can deliver.
But notice what that hand count could not have done if Georgia had only QR-coded ballots in the box: it would have had to rescan the barcodes. Which means it would be auditing the machine with the machine. The paper in the box becomes merely a delivery mechanism for the barcode, and the barcode is the only record there is.
"Paper ballot" and "voter-verifiable ballot" are not synonyms. One describes the medium. The other describes whether the voter's intent is independently readable by a human being.
India Tries Something Different: The Slip You Actually See
Now travel 8,000 miles east.
India runs the world's largest democratic election — hundreds of millions of voters, electronic voting machines (EVMs) in every constituency, a country where logistics alone are a staggering challenge. For years, petitioners argued the EVMs should be scrapped entirely, or that every electronic vote should be cross-checked against paper. In April 2024, a Supreme Court bench of Justices Sanjiv Khanna and Dipankar Datta ruled on exactly those questions in Association for Democratic Reforms v. Election Commission of India.
The Court declined to order a return to paper ballots or 100% manual verification of VVPAT slips. But here is the key design detail: India's VVPAT produces a slip the voter can actually read.
After pressing a button on an Indian EVM, a paper slip prints behind a small glass window. The voter sees the candidate's name and symbol. They can confirm it matches what they pressed. The slip then falls into a sealed compartment — it is never in the voter's hands, so it cannot be photographed as a vote-buying receipt — but the voter has, in a real and direct sense, verified the record before it is sealed away.
That is categorically different from a QR code on a Georgia ballot. One is a human-readable confirmation. The other is an opaque encoding a voter is asked to trust.
The Indian Supreme Court did tighten the rules around that slip: it ordered symbol-loading units to be sealed and secured after the symbol-loading process, stored for at least 45 days post-result, and made available for microcontroller verification in 5% of EVMs per constituency if candidates request it on payment. The court was, in effect, building more rungs into the audit ladder, even while declining to require the top rung.
India's system is not without critics. The 2024 petitions raised legitimate questions about whether five randomly selected polling stations per constituency is a large enough VVPAT sample to catch a systematic compromise. Those questions are real. But the architecture of the VVPAT — a human-readable slip the voter sees before it is sealed — is doing something the Georgia QR code is not: it is giving the voter a moment of genuine, unmediated verification.
Read more about the VVPAT and global paper-trail standards at our gaps tracker
The Audit That Audits the Wrong Thing
Here is the question that follows from the QR-code problem, and it is harder than it looks.
When an election authority audits a ballot-marking-device election, what is it actually counting?
If the audit rescans the QR codes — even by feeding printed ballots through a different scanner — it is testing whether two machines agree. That is a useful check against certain hardware failures. It is not a check against software that encoded the wrong choice from the start, because both machines are reading the same barcode that the original software produced.
If the audit reads only the human-readable text and ignores the QR code, it is doing something strange: counting candidate names that are not the operative record. The scanner that ran on election night did not count those names. It counted the barcode. The human-readable text and the QR code can, in principle, diverge — and in a compromised system, that divergence is precisely the attack.
An audit that checks voter intent — the mark a human being made, or the slip a human being saw — is categorically different from an audit that recounts machine output. Germany's Constitutional Court put this principle in constitutional terms in 2009: the essential steps of voting and counting "can be examined by the citizen reliably and without any specialist knowledge." A citizen cannot read a QR code without specialist knowledge. A citizen can read a name on a slip.
The Dutch government's 2007 "Voting with confidence" commission concluded that any electronic method is acceptable only if it "produces a paper vote the voter can check." The emphasis is on the voter's ability to check — not the auditor's, not the vendor's, not the court-appointed expert's.
See the Germany 2009 ruling and the Dutch commission in our verified case library
The Receipt That Becomes a Weapon: One More Complication
There is a tension built into any voter-verifiable record, and India's VVPAT design navigates it deliberately.
The slip is readable. But it is never in the voter's hands.
That matters because a ballot you can take home — or photograph — is a ballot you can prove to a third party. And a ballot you can prove to a third party is a ballot a vote-buyer can require you to show them. Courts have been explicit about this mechanism. In Rideout v. Gardner, the U.S. Court of Appeals for the First Circuit traced the history: secret-ballot reforms were adopted specifically to prevent vote-buying by removing the buyer's ability to verify the purchase. A photograph of a marked ballot restores that verification and reopens the market.
India's VVPAT slip is visible to the voter but sealed before they leave the booth. You can confirm your vote. You cannot prove it to anyone else. That is the right balance: voter verification without the architecture of coercion.
A ballot-marking device that prints a full, human-readable paper ballot — the kind a voter feeds into a separate scanner — is a step forward from a QR-only system. But it creates a new question: can that paper be photographed? If so, by whom, and at what point in the process? The security properties of "voter-verifiable" depend on the physical handling of the paper, not just on what is printed on it.
Verifiability is a system property, not a feature. It requires readable records, sealed handling, independent audits of voter intent, and chain of custody that prevents both tampering and coercion. Each piece matters. Remove any one, and the guarantee collapses.
The Deeper Problem: Who Checks the Checker?
Georgia ran a hand count of 5 million ballots in 2020 and confirmed the machine result to within a tenth of a percent. That is real evidence about one election. The question Curling leaves open — and that the CISA "most secure election" statement from November 2020 does not answer — is what happens in a future election where the paper in the box is QR-coded ballots.
The CISA statement noted that paper records "enable recounts and audits where needed." That is true. But what the statement does not say — and what matters enormously — is what kind of record enables a meaningful audit. A QR code on a piece of paper is a paper record. It is not a voter-verifiable record.
If Georgia, or any state running ballot-marking devices, conducts a post-election audit that rescans QR codes, it has produced evidence that the machines were consistent with each other. Consistency is not correctness. The Princeton researchers who turned a Diebold AccuVote-TS into a vote-stealing virus in 2006 built code that altered all records, logs, and counters to stay internally consistent. An audit of internal consistency was exactly what that software was designed to survive.
The Coffee County episode in 2021 — where an entire jurisdiction's Dominion voting-system software was copied and leaked — showed how fragile closed-code security is in practice. Secrecy of the source code is not a security property. It is a convenience that evaporates the moment someone with access decides to share it.
The answer is not to assume any of these attacks happened. It is to build systems where it would not matter if they did — because the voter-readable record in the sealed box would contradict any compromised electronic output, and an independent hand audit of that record would surface the discrepancy.
That is the architecture the Georgia system cannot deliver, and the Indian VVPAT, imperfectly, is trying to.
What Would Actually Close the Gap
The test is simple enough to state, harder to implement, and not currently met by most ballot-marking device deployments in the United States.
A voter-verifiable paper record must be:
1. Human-readable at the moment of voting. The voter sees words and symbols — not a barcode — and can confirm they match their intent before the record is sealed.
2. The operative record for counting. The artifact that is hand-audited must be the same artifact the voter verified, not a machine translation of it. If the scanner counts a barcode, the audit must count something that proves the barcode matches the human-readable text.
3. Sealed before it can be proven to a third party. A receipt the voter controls is a coercion tool. A slip the voter sees but cannot take is a verification mechanism.
4. Subject to independent audits that count voter intent. Not machine-output audits. Not consistency checks. Audits where a human being reads what another human being marked, and the two numbers are compared against the machine's output.
None of this requires abandoning electronic assistance for voters who need it. Los Angeles County's VSAP was built as a publicly-owned, open-source system on exactly the premise that the software doing the counting should be inspectable by outsiders, not shielded as a vendor's trade secret. Inspectable software plus a human-readable sealed record plus an independent audit of voter intent is a different security architecture than inspectable software alone — and a completely different one from closed software plus a QR code.
What Is Still Not Verifiable — and What Would Make It So
Here is what the October 2020 Curling opinion does not settle, and what no official statement since has answered:
In any election run on QR-code ballot-marking devices where the post-election audit consisted of rescanning barcodes, there is no publicly available evidence that the human-readable candidate names on the printed ballots matched the QR codes that were actually counted. That comparison was not systematically performed. It may not be technically feasible to perform it after the fact if the ballots are not preserved in a format that allows independent human reading at scale.
The question is not whether fraud occurred. It is whether the system architecture makes that question answerable by anyone outside the vendor and the election authority. Right now, for QR-code BMD systems, the honest answer is: not fully.
What would make it checkable? A routine, pre-specified, publicly observable hand-read of a statistically significant random sample of printed ballots — not a rescan, a human read — comparing candidate names to the machine-reported totals, with the sample size and methodology published before the election, not chosen after.
That is not a partisan demand. It is the same standard the German Constitutional Court, the Dutch "Voting with confidence" commission, and the Indian Supreme Court all reached from different directions: the citizen must be able to check the essential steps, without specialist knowledge, using a record they verified themselves.
A QR code cannot be that record.
A paper trail only protects you if it records what you meant — in a language you can read.
See the global voter-verifiable paper gap across jurisdictions | Read the 2-minute version of this argument
Sources
- Curling v. Raffensperger, No. 1:17-cv-2989-AT, Opinion and Order (N.D. Ga. Oct. 11, 2020)
- Supreme Court of India — Association for Democratic Reforms v. Election Commission of India, 2024 INSC 341 (26 April 2024)
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Adviescommissie inrichting verkiezingsproces (Commissie Korthals Altes), 'Stemmen met vertrouwen', 27 September 2007
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia
- Joint Statement, Election Infrastructure Government Coordinating Council & Sector Coordinating Council (Nov. 12, 2020) (CISA)
- Feldman, Halderman & Felten — Security Analysis of the Diebold AccuVote-TS Voting Machine
- Lawfare — What the Heck Happened in Coffee County, Georgia?
- Rideout v. Gardner, No. 15-2021 (U.S. Court of Appeals, First Circuit, Sept. 28, 2016)
- California Secretary of State news release (Aug. 21, 2018): certifying LA County VSAP Tally