← All posts

The paperless voting machine: a receipt-less transaction with democracy

In Sarasota County in 2006, 18,000 votes vanished into machines that left nothing to recount. A federal court in 2020 found the same problem wearing a newer disguise.

Somewhere in a Florida precinct in November 2006, a voter touches a screen, watches the summary page, and presses "Cast Ballot." The machine beeps. A counter ticks up somewhere in memory. And then — nothing. No paper. No stub. No independently verifiable proof that the vote the machine just recorded is the vote the voter actually intended.

That moment repeated itself 18,412 times in Sarasota County alone.

The race it affected — Florida's 13th Congressional District — was decided by 369 votes. And because every machine in Sarasota County was a paperless ES&S iVotronic touchscreen, there was nothing on earth to recount. Not a stub, not a slip, not a roll of thermal paper behind a locked panel. Just a number inside a box, and the word of the box.

That is the cleanest possible illustration of the problem this post is about. But it is not the most dangerous version of it. The most dangerous version came fourteen years later, and it involved paper.


The receipt that doesn't mean what you think

There is a common assumption in discussions about voting technology: if a machine prints something, the problem of verifiability is solved. Paper exists. Recount it.

That assumption is wrong, and a federal court in Atlanta said so with unusual bluntness.

On October 11, 2020, U.S. District Judge Amy Totenberg issued an opinion in Curling v. Raffensperger examining Georgia's Dominion ballot-marking device system — the machines that replaced Georgia's old paperless touchscreens. The new system does produce a piece of paper. A voter approaches the BMD, makes their choices on a touchscreen, and the machine prints a ballot. That ballot is then fed into a tabulator to be counted.

But here is what the court found: the ballot the machine prints contains a QR code, and that QR code is what the tabulator actually reads to determine the vote. The human-readable text on the printed ballot — the candidate names — is not what gets counted. The barcode is.

The court's own words: the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter."

You cannot read a QR code with your eyes. You almost certainly did not try. So when you reviewed your printed ballot summary at the polling place and pressed confirm, you verified the human-readable text — and took the machine's word for what it encoded in the barcode.

This is not a theoretical concern. The court quoted expert testimony from Dr. J. Alex Halderman describing the practical feasibility of a cyberattack that could alter the QR codes — swapping or deleting votes — while leaving the human-readable summary unchanged. You would see the right candidate names. The barcode would say something else. The tabulator would count the barcode.

The court also cited the National Academies' 2018 conclusion that no technical mechanism currently exists to ensure a vote-counting application produces accurate results and that testing alone cannot ensure systems have not been compromised.

The court ultimately declined to order last-minute relief — the 2020 election was weeks away, and switching voting methods mid-campaign carries its own risks. That is a defensible judgment under impossible time pressure. But the finding stands regardless: Georgia had paper, and the paper was not voter-verifiable.

This is the upgraded version of Sarasota's problem. Sarasota had no paper at all. Georgia had paper that said one thing while the counted record said something else.


Why "no paper" is the floor, not the ceiling

To understand why these two cases form a single argument, start with what an audit actually requires.

When election officials or courts want to verify a machine count, they need two independent artifacts: the machine's output, and something the voter themselves confirmed was correct. If those two things match, you have corroboration. If they diverge, you have a problem worth investigating. If only one artifact exists — the machine's output — there is nothing to corroborate against. You are auditing the machine's answer by asking the machine.

In Sarasota, the paperless iVotronic produced a single artifact. When questions arose about the 13% undervote rate — far higher than adjacent counties using paper ballots — the U.S. Government Accountability Office conducted tests on the machines. Those tests did not find a malfunction that explained the undervote, while explicitly noting that a voter-verified paper trail could have provided independent confirmation that the touchscreens recorded votes correctly. The GAO was not saying the machines malfunctioned. It was saying no one could prove they hadn't, because there was nothing to check against.

That is not a clean bill of health. That is a confession of unverifiability.

In Georgia, the artifact problem is more subtle. The printed ballot exists, but the voter-readable portion and the machine-readable portion are not the same record. A voter can confirm the human text. A tabulator reads the barcode. These are two different encodings of (supposedly) the same data, generated by a machine whose software the voter cannot inspect and whose output the voter cannot independently cross-check. An audit of Georgia's paper ballots is technically an audit of the barcodes — confirming that the barcodes were consistently tabulated, not that they were correctly generated in the first place.

A paper trail is only a verification tool if the artifact you're checking is the same artifact the voter confirmed.


What independent verification actually looks like

The contrast is instructive. Georgia's statewide hand count in 2020 — roughly five million presidential ballots, hand-tallied across 159 counties in less than six days — was meaningful and valuable precisely because it confirmed the machine tally to within about a tenth of one percent. That hand count is the strongest case for paper ballots anyone could make: when a real, durable record exists, a close race can be independently checked at scale.

But notice what made that work. Georgia was also using hand-marked paper ballots for many voters alongside the BMD system. Hand-marked ballots in Georgia's 2020 race were voter-verified in the truest sense: the voter put pen to paper, circled a name or filled an oval, and the marked paper went directly into a sealed box. No intermediate encoding. No QR code. The human mark is the record.

The hand count worked because there was a genuine second artifact — voter intent, expressed directly on paper — that could be compared to the machine tally. When the two aligned, confidence was warranted.

Colorado provides another model. When Colorado became the first state to complete a statewide risk-limiting audit in November 2017, it worked for the same reason: hand-marked paper ballots gave auditors something to check the machines against. An RLA doesn't just spot-check a fixed percentage of ballots. It adjusts the sample size based on the margin — demanding more hand-checking in close races and less in lopsided ones, calibrated to a stated statistical confidence level. In a race decided by hundreds of votes, it looks at enough ballots to say, with defined probability, whether the machine outcome is correct.

That is a powerful tool. It is also entirely dependent on the paper trail being trustworthy — on the record in the sealed ballot box being what the voter actually intended, not an encoding produced by a machine the voter couldn't inspect.


The German standard, and why the U.S. keeps not meeting it

In March 2009, eight judges in Karlsruhe settled a question that should probably have been settled before voting computers were deployed anywhere: when does an electronic counting system satisfy the requirements of a democratic election?

The German Federal Constitutional Court's answer was direct. Electronic voting is constitutional only when "the essential steps of the voting and of the determination of the result can be examined by the citizen reliably and without any specialist knowledge." The Nedap machines used in Germany's 2005 federal election failed this test. They stored votes in electronic memory with no independently verifiable record a voter could check. The court declared the Federal Voting Machines Ordinance unconstitutional.

Notice what the court did not say. It did not say the machines had malfunctioned. It did not say votes had been changed. It said that a system whose correctness rests on trusting hidden software fails the public verifiability test regardless of whether tampering is ever proven.

The Dutch government's Election Process Advisory Commission reached the same place in 2007, in its report "Stemmen met vertrouwen" ("Voting with confidence"). The commission was blunt: "there are no secrets in the election process." Transparency and checkability were non-negotiable. Any electronic method was acceptable only if it produced a paper vote the voter could confirm. The Netherlands went back to paper and manual counting.

Ireland's Commission on Electronic Voting, reviewing Nedap/Powervote machines the government had already purchased, concluded something subtler but equally important: it was not making a finding that the system would not work. It was making a finding that the system had not been proven to work to the commission's satisfaction. When accuracy and secrecy cannot be independently verified, the correct default is not deployment.

These are three independent countries arriving at the same position: the burden of proof runs in one direction. A voting system must prove to ordinary citizens that it works correctly — not ask citizens to trust the manufacturer's word or the government's certification.

Apply that standard to Sarasota. Apply it to the QR-coded BMDs in Curling. The standard is not met.


The irreducible problem with "trust the officials"

There is a version of the response to all of this that sounds reasonable: election officials reviewed the systems. Vendors certified them. Auditors tested them. Nothing was found.

This is the argument that collapses under its own weight, and the CISA "most secure election in American history" statement from November 2020 is actually the clearest example of why.

That statement — issued by serious, career officials — declared there was "no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised." It explicitly cited paper records and the ability to recount and audit as the foundation of its confidence.

Read that again. The statement's own argument for trustworthiness was: we have paper records that allow recounts and audits. The officials who certified the election as secure grounded that certification in the existence of independently verifiable paper. They were not saying "trust the software." They were saying "trust the paper audit."

Which means the question for any system — Sarasota's iVotronics, Georgia's QR-coded BMDs, any paperless DRE anywhere — is exactly the one the officials themselves would have to ask: where is the independently verifiable record?

When there isn't one, "the audit confirmed it" is a circular claim. When the paper record can't be read by the voter, "we recounted the paper" confirms only that the barcodes were consistently tabulated, not that they were correctly generated. When the hand count differs from the machine count by a dozen votes in a race decided by dozens of votes — as happened in the Antrim County, Michigan audit — "the hand count confirmed it" is a reassurance carrying its own margin of error.

The GAO found in 2005 that federal efforts to improve voting system security were under way but that key activities remained incomplete. That was not the conclusion of a partisan critic. It was the conclusion of career federal auditors. And the gap they identified — the distance between "certified" and "verifiable by the public" — has not fully closed in the two decades since.


The fix is specific, not symbolic

None of this is an argument for distrust as a permanent condition. It is an argument for what would replace distrust with something better.

The fix has two components, and both are necessary.

The first is a durable, voter-verified record — not a machine-generated summary the voter confirms on a screen, and not a barcode the voter cannot read. A hand-marked paper ballot, or a ballot-marking device that produces a human-readable paper record where the human-readable text is what gets counted and tabulated, and the voter confirms it before it leaves their hands. The record the voter checks must be the record that gets audited. The Netherlands, Germany, and Ireland arrived at this conclusion through policy commissions and constitutional courts. Colorado and Georgia's 2020 hand count demonstrate it works in practice.

The second is independent, adversarial verification — not a pre-election certification by a single authority, but ongoing public scrutiny. Brazil's election authority invites qualified members of the public to try to break its voting machines before every general election. Washington D.C.'s 2010 internet voting pilot was abandoned because that kind of open testing worked: a University of Michigan team compromised the system in roughly 48 hours, changing ballots, reading votes, and demonstrating the attack to officials. The attack was caught because the system was open to testing, not because a certification body had cleared it.

India's Supreme Court, in its April 2024 ruling on electronic voting machines, declined to scrap the country's entire EVM system — but tightened the rules around paper verification, sealed storage of symbol-loading units, and candidate-requested microcontroller verification. Even a court that upheld an electronic system tightened the independently checkable parts.

The throughline is not paper for its own sake. It is a record the voter confirmed, preserved in tamper-evident form, auditable by anyone with the access rules, checked by independent parties who are not the officials announcing the result.

That is verifiability. An official saying "it was fine" is not.


What remains unverifiable — and what would change it

Here is the honest conclusion, stated as plainly as possible.

In any jurisdiction that used paperless DRE machines — every vote cast on an iVotronic, every Diebold AccuVote-TS, any machine that stored votes in electronic memory without a voter-verified paper record — the count cannot be independently confirmed. Not now. Not ever. Those votes exist only in the machine's memory, and the only record of them is what the machine says. The 18,412 undervotes in Sarasota County remain unexplained. They may have been voter choices. They may have been a software glitch. There is no way to know, because there is nothing to check.

In any jurisdiction where ballot-marking devices produce QR codes that voters cannot read, the tabulated count is an audit of the machine's encoding, not an audit of voter intent. The human-readable text and the scanned barcode may agree perfectly, or they may not. Without a parallel hand tally of the human-readable text — not the barcode — there is no independent check.

What would change this?

Precinct-level results, published the moment each precinct closes, in machine-readable formats anyone can download and cross-check against the totals reported by officials. A voter-verifiable paper record, retained and auditable, where what gets counted is what the voter read and confirmed. Public adversarial testing of the systems before they run in real elections. Risk-limiting audits that are sized to the margin, not to a political comfort level.

None of these require trusting any official, any vendor, or any political party. That is the point. The fix for "trust us" is a system designed so that you don't have to.

Until then, the beep of a paperless touchscreen is a receipt-less transaction with democracy. You pressed the button. Something happened. You'll just have to take their word for it.

See how common the 'no paper to recount' gap is across the world →

Read the 2-minute version of this problem →

Explore specific verifiability gaps by system and jurisdiction →


Sources