← All posts

Small, boring errors decide big elections more often than fraud does

In three Finnish towns in 2008, 232 people voted and their votes were simply never saved — no fraud, no hack, just a confirmation button nobody told them to press.

It is the morning of October 26, 2008, and in the Finnish town of Karkkila, a voter walks into a polling station, sits down at an electronic terminal, makes her choice, and pulls out her smartcard. She has done everything she was asked to do. She leaves believing she has voted.

She hasn't.

Her vote was never saved. The terminal required one final confirmation step — a brief pause, a button press — but the on-screen guidance didn't make this clear. Without that step, the system silently discarded her selection. The same thing happened in Kauniainen and Vihti. Across the three municipalities running Finland's e-voting pilot that day, 232 votes vanished into the machine without a sound.

No alarm. No error message. No way for the voter to know.


The failure nobody planned for

Finland is not a country associated with election chaos. It has one of the most stable democratic traditions in the world. The 2008 municipal e-voting pilot was a careful, limited experiment — three towns, supervised conditions, paper voting still available at the same stations.

And yet: 232 people left polling stations believing they had participated in a democratic process, when in fact they had not. Their intent had been recorded nowhere.

The Finnish Supreme Administrative Court (Korkein hallinto-oikeus) investigated and, on April 9, 2009, issued decision KHO:2009:39. The court found the deficiencies in voter instructions and machine design meant the elections in those three municipalities had to be re-held. Fresh elections were ordered. Finland did not proceed with electronic voting.

Read that sequence carefully. The error was not a cyberattack. It was not fraud. It was not a rogue official. It was a usability flaw — an interface that didn't tell people what they needed to do — combined with a system that had no way to warn a voter their action was incomplete. The method offered voters no independent confirmation that their ballot had been captured. So when it wasn't, nobody knew.

This is the kind of failure that election-integrity conversations almost never focus on. We have trained ourselves to watch for conspiracies. The mundane disasters walk right past us.


Why boring errors are the ones that actually decide elections

There is a persistent idea that close elections are threatened primarily by bad actors — someone stuffing ballots, someone altering a machine, someone bribing a precinct worker. That threat is real and documented. But it is not the most common way thin margins get decided by something other than votes.

The more common culprit is ordinary error. And ordinary error is, by definition, invisible until someone looks.

A fold line in the wrong place. Dust on a lens. A confirmation button nobody pressed. A memory card that wasn't updated. These are not dramatic, and that is precisely the problem.

Consider what the forensic audit of Windham, New Hampshire found in July 2021. After a disparity appeared between machine counts and a hand recount in a 2020 State Representative race, the New Hampshire legislature ordered a full forensic investigation under SB 43. The audit team — Harri Hursti, Mark Lindeman, and Philip Stark — traced the miscount to something almost comically mundane: a folding machine the town had leased for unrelated mailing purposes. It folded absentee ballots, but not along the ballot's printed score lines. The resulting crease ran through the oval vote targets. The AccuVote optical scanners read a substantial fraction of those creases as marked votes.

The team estimated that roughly 44 percent of folds through vote targets were interpreted as votes in November, with experimental rates ranging from about 20 to more than 72 percent depending on conditions. White powder residue had also built up inside the scanners, obstructing the lenses. No malware. No tampering. No fraud. Just physics.

The error was only discoverable because paper ballots existed. A hand examination could recover what the voter actually marked — because the paper was still there, still readable by human eyes. The audit report concluded the election was, for the most part, well run. But the machine count had been wrong. And the hand count that caught it was itself imperfect, as hand counts always are.


"The hand count confirmed it" is a reassurance, not a proof

Here is where the standard reassurance breaks down — and where we need to be honest rather than comforting.

In Antrim County, Michigan in 2020, a tabulation error caused incorrect unofficial results to be published. The cause was human: a configuration mistake, not fraud or malware. The error was caught because the numbers were glaringly implausible for the county. When officials conducted a full hand audit of every presidential ballot in December 2020, they found the certified machine total and the hand count still differed by about a dozen votes out of approximately 15,700 cast.

Twelve votes. From a hand count. The gold standard.

A method that is itself off by a handful of votes cannot definitively settle a race decided by a handful of votes.

This is not an accusation. It is a description of how human counting works. People miscategorize ambiguous marks. They lose count midway through a stack. They debate whether a stray pen stroke crosses an oval. The Windham audit noted exactly this: a hand count could "ascertain voter intent" that scanners had misread — but hand counting is also a human activity, subject to human judgment calls and human error.

Georgia's enormous 2020 hand count of roughly five million presidential ballots — across 41,881 batches, 159 counties, less than six days — affirmed the machine-tabulated outcome to within about a tenth of one percent. That is impressive at scale. It is also a reminder that "about a tenth of a percent" in a very close race is not zero. Colorado's statewide risk-limiting audits, the first of their kind when launched in 2017, offer a statistically principled approach to sizing the check against how close the race is — but even those audits depend on a paper record being accurate, and on the sampling being genuinely random.

The point is not that hand counts are worthless. They are essential. The point is that "a hand count confirmed it" and "the Secretary of State says it's fine" are claims, not proofs. In a race decided by dozens of votes, confirmation by a method that is itself uncertain by dozens of votes is a reassurance. It is not the same as independent verifiability.


The structural problem these two cases share

Finland 2008 and Windham 2020 look different on the surface — one is an e-voting terminal in a Nordic pilot program, the other is an optical scanner in a New England town. But they share the same underlying failure.

In both cases, the system produced a count that differed from the actual votes cast, and there was no real-time mechanism for anyone — voter, observer, or official — to detect this independently.

Finland's voters had no confirmation their ballot was captured. Windham's ballots had no way to flag that fold lines were corrupting the scan. In Finland, the gap was only found because officials could eventually compare the number of electronic voters recorded against the number of ballots expected. In Windham, it was only found because a hand recount produced a number different enough to prompt investigation — and then only fully explained because a forensic team spent months on it.

Both errors were caught after the fact. Both required significant effort to diagnose. In Finland's case, the only remedy was to redo the elections entirely. In Windham's case, the result stood — but the margin in the affected race had been wrong on election night, and the degree to which the final certified count accurately reflected voter intent is something that cannot be answered with certainty.

The villain in both stories is opacity. Not malice. Opacity.


What the courts have actually said about this

This isn't just a technical argument. Courts across multiple countries have arrived at the same conclusion from the constitutional end.

Germany's Federal Constitutional Court, ruling on March 3, 2009 — almost exactly two months before Finland's Supreme Administrative Court — held that electronic voting is only constitutionally legitimate when ordinary citizens, without specialist knowledge, can independently verify every essential step from ballot to result. The Court found that machines storing votes only in electronic memory, with no independently verifiable record, failed this standard. It voided the legal basis for the machines even without evidence of actual malfunction.

The Dutch government's Korthals Altes Commission, in its 2007 report Stemmen met vertrouwen (Voting with confidence), put the principle even more plainly: there are no secrets in the election process. Questions must be answerable, and the answers must be checkable and verifiable. The Netherlands dropped voting computers and returned to paper.

Kenya's Supreme Court annulled a presidential election in 2017 partly because results forms lacked consistent security features and the chain from polling station to national tally could not be independently verified. Malawi's courts voided a presidential result in 2020 because tally sheets had been altered with correction fluid — a mundane physical intervention, not a cyberattack — leaving no reliable record of what voters actually decided.

Notice what all these cases have in common. They are not about hackers. They are about the absence of a mechanism anyone outside the counting authority can use to check the count independently. Whether the failure mode is a usability flaw, a fold crease, correction fluid, or an unreadable QR barcode, the underlying problem is the same: the record that was supposed to prove the result couldn't be independently verified.


The deeper argument: verifiability catches honest error, not just fraud

The public conversation about election integrity is almost entirely framed around fraud. This is understandable but misleading. Fraud is a deliberate act, and deliberate acts leave traces — motives, patterns, beneficiaries. Honest errors leave nothing except a wrong number.

The implication is important: a system designed only to detect fraud will miss the errors that actually occur most often.

Finland's e-voting system wasn't designed to be hacked. It was designed to be convenient. It failed because its designers didn't build in a mechanism for voters to independently confirm their ballot was counted — and without that mechanism, a usability flaw became an undetectable loss of votes.

Windham's scanners weren't compromised. They were doing what they were programmed to do: read dark marks in specific locations. A fold crease is a dark mark in a specific location. Without independent verification of the physical ballots, the machine's output was treated as authoritative.

The remedy is not to distrust officials. Most election officials are doing genuinely difficult work with limited resources and intense scrutiny. The remedy is to stop building systems that require trusting anyone — and to build systems where the count is checkable by anyone, independently, without needing to believe a particular person or institution.

That means paper ballots the voter actually marks and can see counted. It means audits designed by statisticians to catch errors at the scale they would have to occur to change an outcome — which is what Colorado's risk-limiting audit framework attempts. It means precinct-level results published instantly, in machine-readable form, so anyone with a spreadsheet can reconstruct the tally and flag anomalies faster than any official audit. It means cryptographic commitments that let independent verifiers confirm the tally without being able to see individual votes.

It does not mean trusting the scanner. It does not mean trusting the official who says the audit confirmed it. It means designing the system so that trust is not the variable.


What is still not verifiable — and what would make it checkable

Here is what we do not know, and cannot know, from the Finland and Windham cases even now:

In Finland's three municipalities, we know 232 votes were lost. We do not know who those voters intended to support. We do not know whether those 232 votes would have changed any individual race outcome. We know fresh elections were held. We do not know whether the re-run electorate was identical in composition or turnout to the original one. The court did the right thing. That still leaves real uncertainty about what the original electorate actually decided.

In Windham, we know fold creases caused miscounts. We know the forensic team did excellent work diagnosing the cause. We know the hand count recovered voter intent for the examined ballots. We do not know whether similar fold effects occurred in previous elections with the same equipment. We do not know the exact error rate for each ballot batch. The result was certified. The method that certified it carried its own irreducible uncertainty.

These are not accusations. They are the honest residue of relying on detection after the fact rather than verification in real time.

What would make it checkable? A voting method where each voter receives an anonymous token — not traceable to their identity — that they can use to verify their specific ballot appears in the final tally, correctly, without revealing how they voted. This is what cryptographically verifiable end-to-end voting systems attempt to provide. The voter doesn't have to trust the terminal, the scanner, the official, or the vendor. They check for themselves.

That technology exists. It is not yet standard anywhere at scale. And until it is, every close election decided by a few dozen votes is an open question wearing a confident suit.


The shareable takeaway is this: the biggest threat to a close election is not a hacker in a foreign country — it is a fold line nobody noticed, an interface nobody explained, an error nobody flagged because the system was never built to flag it. The fix is not better officials or louder audits. It is verifiability that works for everyone, that requires no one's trust, and that catches the boring failures before they become the permanent record.

See how common this verification gap is across the world →

Read the two-minute version →

Explore the full gap database →


Sources