← All posts

The 150-year-old invention your phone camera can quietly undo

A law passed in 1872 deliberately made your vote unprovable — and your phone camera can quietly undo 150 years of that protection in under three seconds.

It is the summer of 1871 in the Palace of Westminster, and a Scottish MP named George Young is standing at the despatch box defending a bill that almost nobody in the room fully wants. The landlords don't want it. Many of the sitting members don't want it. Because what the bill proposes — voting in secret, on a printed ballot, in a screened compartment — would destroy something those men had always relied on: the ability to watch how people voted, and to act accordingly.

Young's Ballot Bill would become the Ballot Act 1872. And the thing it was designed to destroy was a market.

Not a metaphorical market. A literal one — with prices, transactions, and enforcement. A vote was open, public, recorded in a book, and publishable. A landlord, employer, or party agent could stand at the poll, note how each man voted, and settle accounts afterwards. The secrecy the Act introduced was not a courtesy to the voter. It was a structural attack on the mechanics of vote-buying and intimidation. No proof of vote, no enforceable transaction. The market collapses when the delivery of the goods cannot be verified.

That is the idea that has protected elections for 150 years. And it is the idea that a modern smartphone camera can quietly dismantle.


The mechanism Parliament understood better than most people do today

Before 1872, voting in Britain worked roughly like this: you walked up to a poll, declared your candidate aloud or pointed at a name, a clerk wrote it in a book, and the book was published. The whole process was, in the language of the day, completely open. Which meant it was also completely coercible.

The Australian Electoral Commission's own history of the secret ballot puts it plainly: people "voted publicly, which left them vulnerable to intimidation and coercion." The so-called "Australian ballot" — a uniform, state-printed form, marked in a private booth — was adopted in the 1850s precisely to break that vulnerability. Britain followed with the Ballot Act in 1872. The United States adopted the model state by state over the following decades.

The security logic is elegant and surprisingly robust. A vote-buyer needs two things: payment and proof of delivery. Secrecy defeats the second. If a voter can never demonstrate, after the fact, that they voted as instructed, the buyer is making a bet with no enforcement mechanism. The transaction becomes unenforceable. And unenforceable transactions — as any economist will tell you — tend not to happen.

Ballot secrecy is not about privacy. It is about making the product unbuyable.

This is why a law about paper in a box from 1872 is still doing heavy structural work in every democracy that uses it. And it is why anything that restores provability — anything that lets a voter prove their specific choice to a third party — is not a feature. It is a security vulnerability.


What a court said out loud in 2016

The U.S. Court of Appeals for the First Circuit spelled this mechanism out with unusual clarity in Rideout v. Gardner, 838 F.3d 65 (1st Cir. 2016).

The case was about New Hampshire's ban on ballot selfies — photographs of a voter's own marked ballot. The state defended the ban by tracing the history directly: secret-ballot reforms were adopted to "combat widespread vote buying and voter intimidation." The argument was simple and historically accurate. A photograph of a marked ballot restores exactly what the Ballot Act destroyed: the ability of a voter to prove, to anyone, how they voted. The proof is the product. The product is what makes the market work.

The court struck the ban down on First Amendment grounds — it found no recent evidence that ballot photos had actually fueled vote-buying in New Hampshire and ruled the statute wasn't narrowly tailored. But the court did not dispute the underlying mechanism. It accepted the state's history and its logic. It just concluded the danger was theoretical rather than demonstrated in that jurisdiction at that moment.

That conclusion may be revisited elsewhere, in other courtrooms, in other years.

Because the mechanism the court accepted in theory is very much operational in practice — documented by international monitors, court judgments, and election observers across Europe and beyond.


The market that never closed

Consider what international election monitors have found, not in some distant authoritarian context, but in EU member states.

In Bulgaria's April 2023 parliamentary elections, the OSCE/ODIHR final report recorded "longstanding concerns over vote-buying and controlled voting," which were "present and reported" to the mission. Observers found that the secrecy of the ballot was compromised in 7 percent of their election-day observations. Law enforcement told the monitors that obtaining evidence of vote-buying remains challenging and that most cases don't progress past pre-trial.

That last sentence deserves a second read. In a European Union member state, in 2023, vote-buying is documented but mostly unprosecutable. Why? Because proving a transaction requires proving how someone voted. And if the ballot is truly secret, that proof is hard to come by.

Now ask: what would change if voters routinely photographed their marked ballots?

In Georgia's October 2024 parliamentary elections — the country, not the US state — OSCE/ODIHR found that issues with the secrecy of the vote were noted in over 30 percent of observations: compromised by how ballots were inserted into boxes, how they were marked in view of others, and by inadequate polling-station layouts. The mission found these issues "negatively impacted the integrity of the elections and eroded public trust."

Thirty percent is not an edge case. It is a structural failure of the protection that makes the 1872 design work.

In Albania's 2021 parliamentary elections, ODIHR documented "widespread" allegations of vote-buying by political parties. In Kyrgyzstan's 2017 presidential election, the mission urged authorities to "guarantee the right to a free and secret choice" and prevent any form of pressure on voters to disclose how they voted. In North Macedonia's 2025 local elections, observers noted "voter tracking on and around election day" alongside allegations of vote-buying and pressure on public-sector employees.

Voter tracking. That phrase is important. It means someone is keeping a record of who showed up — often checkable against instructions given in advance, with consequences applied afterward. It is the operational backbone of workplace coercion. And it works best when voters can be required to confirm their compliance.

The ballot selfie is not a novelty. In some contexts, it is a compliance receipt.


The specific gap the 1872 Act was always trying to close

Here is the thing about the Ballot Act's design that is easy to miss. It did not simply make voting private. It made votes unprovable — to anyone, in any direction, for any purpose, including the voter themselves.

That seems strange by modern standards. We are accustomed to systems that give us receipts. But the designers of the secret ballot understood that a receipt is exactly what a vote-buyer needs. The Ballot Act 1872 prescribes a sealed ballot box, specific offences protecting the integrity of the poll, and procedures designed so that no link can be established between a named voter and a marked ballot. The anonymity is architectural, not incidental.

The gap the Act was closing is this: in an open system, proof flows naturally from the structure. In a secret system, proof must be actively destroyed — the mechanism must be designed to make proof impossible.

When that mechanism fails — because a polling booth faces the wrong way, because a voter photographs their ballot, because a supervisor stands too close, because a tally sheet is visible — the market reopens. Not everywhere, not immediately, but the structural protection weakens.

This is documented at the far end of the spectrum by cases like Erlam & Ors v Rahman [2015] EWHC 1215 (QB), in which an Election Court voided a Tower Hamlets mayoral election after finding personation, postal-vote fraud, and bribery. The court found the election tainted by corrupt and illegal practices — and one of the enabling conditions was that postal voting moved ballots outside the controlled, secret environment of the polling station into spaces where the chain of custody was much harder to guarantee.

Postal voting is not the same as a ballot selfie. But the underlying problem is structurally identical: the ballot travels outside the protected space where it cannot be observed, and the protection breaks.


What 'secret' actually costs — and what it gets you

There is a real tension here that honest analysis cannot paper over.

Ballot secrecy has a genuine cost. It means you cannot verify your own vote was counted. It means you cannot prove to anyone — a court, a journalist, a curious researcher — that your specific paper ended up in the total. This is the same property that makes the ballot unbuyable, but it also makes the ballot unverifiable to the voter themselves.

This is not a design flaw. It is the design. And it is why the engineering challenge for modern voting systems is genuinely hard: you want a system that is simultaneously secret and verifiable — where the voter cannot prove their choice to a third party, but the election as a whole can be independently checked by anyone.

Those two requirements pull in opposite directions. Satisfying both at once requires cryptographic techniques that are more sophisticated than a paper ballot but potentially more powerful than any manual audit.

Here is where the comparison to manual recounts is instructive. When Georgia conducted its full hand count of roughly 5 million ballots in 2020, the variation between the machine tally and the hand count was about a tenth of one percent — a close match that provided genuine statistical confidence in the result. But in Antrim County, Michigan, a hand count of about 15,700 presidential ballots still differed from the machine tabulation by roughly a dozen votes. Twelve votes. In a small county where the error was caught because it was absurdly implausible.

A dozen votes in a close race is not noise. It is the margin.

The hand count is the gold standard of election verification — and it carries irreducible human error. It cannot settle a question decided by a handful of votes. And it cannot, by itself, guarantee that the ballot a voter marked is the ballot that was audited. The secrecy that protects voters from coercion also means no voter can trace their own ballot through the box, the scanner, and the final tally.

The answer is not to abandon secrecy in the name of verifiability. The answer is verifiability that does not require the voter to prove their specific vote — systems that allow independent mathematical confirmation of the aggregate result without exposing any individual choice.


The gap secrecy cannot close alone

The Ballot Act solved one problem — coercion and buying at the point of casting — brilliantly. But it left others open, and 150 years of election administration have been working around those gaps.

The Tower Hamlets case shows what happens when the vote travels outside the polling station: postal ballots, handled in uncontrolled environments, are where secrecy is hardest to enforce and where proxy pressure is most effective. North Carolina's 9th Congressional District saw a coordinated absentee-ballot scheme so extensive that the State Board of Elections unanimously ordered a new election in 2019 — a rare event in American electoral history. The mechanism was ballot collection and completion by operatives who could observe and control how ballots were marked or filled.

Secrecy at the booth does not help you if someone else fills in your ballot.

And a ballot selfie — or a phone camera turned toward a screen in a voting booth, or a photograph taken of a paper ballot before it is deposited — restores the very proof the 1872 Act spent so much effort eliminating. It does not matter whether the voter is a willing seller or a coerced employee. What matters is that the proof exists. Once it exists, it can be demanded.

The first-generation response to this problem — passing laws against ballot selfies — addresses only one channel. Coercion happens through many channels: witnessed marking, tracked turnout, photographed screens, screenshots of BMD confirmation pages. You cannot legislate your way to a structural solution. You need the architecture to enforce secrecy by design.

That is what the German Federal Constitutional Court recognized in 2009, when it struck down electronic voting machines because ordinary citizens could not independently verify the essential steps of the count. Not experts. Citizens. The Netherlands reached a similar conclusion and returned to paper. The question of what citizens can independently verify is the same question the 1872 designers were asking in reverse: what can be proven, by whom, to whom, with what consequences?


The honest answer to what is still unresolved

The Ballot Act created a structure where the proof a coercer needs simply does not exist. That structure is weakened every time secrecy fails — by bad booth layouts, by postal ballots marked under supervision, by photographs, by tracked turnout, by employer pressure backed by workplace monitoring.

None of those failure modes are new. Most of them were known to the architects of the 1872 Act. What is new is the phone camera in every pocket, and the ease with which a photograph can be taken, transmitted, and used as evidence of compliance.

The legal response — banning the selfie — is a patch on a structural problem.

The structural response is a voting system whose secrecy is enforced by its architecture rather than by a prohibition: where the ballot is anonymized before it enters the count, where the anonymization is mathematically verifiable by anyone without revealing individual votes, and where the aggregate result is independently checkable without requiring any voter to produce proof of their specific choice.

That system would make the ballot selfie useless as a coercion tool, because no one could link a voter's photograph to a ballot in the tally — even if the photograph existed. The proof that doesn't exist cannot be demanded.

What cannot currently be independently verified, by you, without trusting an official's assurance: whether your vote was counted as you marked it, whether the aggregate total reflects the actual ballots in the box, and whether the secrecy protections that were supposed to make vote-buying unenforceable are actually functioning in the polling stations and postal systems of the elections you vote in.

What would make it checkable: an open, publicly auditable system whose cryptography can be independently inspected — not by experts on behalf of the public, but by the public directly. That is the gap the 1872 Act opened, and that 150 years of administration have not closed.

See how this gap shows up across different countries →

Read the two-minute version of the verifiability problem →

Explore the full database of verified election-integrity cases →


Sources