← All posts

The quiet pressure that decides elections before a single vote is counted

Someone offered a voter in Kyrgyzstan money for their ballot — and the only reason it worked is that the buyer could check.

It is the morning of October 15, 2017, and polling stations have just opened across Kyrgyzstan for the country's presidential election. By most measures, this is a functioning, competitive race. Eleven candidates. A field that includes a former prime minister. International monitors from the OSCE are watching.

And somewhere — in a constituency office, outside a polling station, in a quietly arranged meeting the night before — money is changing hands.

Not metaphorically. The OSCE/ODIHR Election Observation Mission would later document it plainly in its final report: cases of pressure on voters, vote-buying, and the misuse of public resources. The mission recommended that the authorities guarantee the right to a free and secret choice, and ensure that any form of pressure on voters to disclose how they voted is clearly prohibited with effective penalties.

That last phrase is the one worth pulling apart. Pressure to disclose how they voted.

It sounds like a procedural footnote. It isn't. It is the diagnosis of an entire attack on democracy — and understanding why tells you more about election security than almost any argument about software or servers.


The transaction that requires a receipt

Vote-buying is not complicated. Someone with money or power wants a particular outcome. They identify voters they can reach — employees, tenants, community members, people who owe them a favor — and they make an offer: vote for my candidate, and something good happens. Vote against, and something bad does.

The problem, from the buyer's perspective, is enforcement.

A vote is secret. You can take the money, walk into the booth, vote however you like, walk out, and no one is the wiser. The buyer cannot follow you in. The ballot does not have your name on it. The receipt for a vote cannot exist, by design.

This is not a bug in democratic systems. It is the central security feature.

If the buyer cannot verify the purchase, the market collapses. Every payment becomes an unenforceable bet. The only way vote-buying scales is if the secrecy fails — if voters can be watched, followed, photographed, or pressured into proving compliance.

Which is exactly what ODIHR documented in Kyrgyzstan. And in Albania's 2021 parliamentary elections, where the same mission found allegations of vote-buying by political parties were widespread, leading to investigations. And in Bulgaria's 2023 early parliamentary elections, where monitors recorded "longstanding concerns over vote-buying and controlled voting," with secrecy of the ballot compromised in 7 per cent of observed stations. And in Georgia's 2024 parliamentary elections, where ODIHR found issues with ballot secrecy in over 30 per cent of observed polling stations — including how ballots were marked, how they were deposited, and how polling stations were physically laid out.

The geography changes. The mechanism does not.


Why the secret ballot exists at all

This is not a new problem, which is the first thing to understand.

In the English market towns of the mid-1800s, voting was public. You walked up, declared your choice aloud, and the returning officer wrote it in a book. The book could be published. Your landlord, your employer, your creditor — anyone with power over you — knew exactly how you had voted. Intimidation was not a side effect of this system. It was built into its architecture.

The Australian ballot — state-printed, marked in a private compartment, deposited in a sealed box — was invented in the 1850s as a direct countermeasure. The Australian Electoral Commission records that because people "voted publicly, which left them vulnerable to intimidation and coercion," an independent electoral body was established and the secret ballot implemented. It then spread across democracies.

Britain codified it in the Ballot Act 1872 — precisely to end the open bribery and intimidation that public voting had enabled for centuries.

The insight is old, but its implications keep being rediscovered. In 2016, the U.S. Court of Appeals for the First Circuit reviewed New Hampshire's ban on photographing your own marked ballot. In Rideout v. Gardner, the court traced the history directly: secret-ballot reforms were adopted to "combat widespread vote buying and voter intimidation," practices that depend on a buyer or coercer being able to verify the vote. A photograph of your completed ballot restores that proof. It turns your vote back into a receipt. The court struck the ban on First Amendment grounds — but its analysis of why ballot secrecy matters as a security property is as clean a statement of the principle as you will find anywhere in law.

Secrecy defeats vote-buying because the buyer cannot verify the purchase. That is not a courtesy. It is a structural guarantee.

Any feature that lets a voter prove their specific choice to a third party — a photograph, an identifying mark, a traceable ballot — quietly reopens the market.


The coercer's operational problem

Go back to Kyrgyzstan, or Albania, or North Macedonia — where ODIHR's 2025 local elections report flagged not just vote-buying and pressure on public-sector employees, but voter tracking: the systematic recording of who voted and when, to monitor whether people complied.

Voter tracking is the operational backbone of workplace coercion. Your employer tells you to vote for a candidate. You go to the polling station. Someone checks you off a list. If you didn't show up, or showed up too briefly, the inference is that you defied the instruction. The threat is implicit: we will know.

But notice the limits of this approach. Tracking who voted does not tell the coercer how they voted. It only tells them that you went. The secret ballot still defeats the transaction at the moment of choice — if the booth is genuinely private, if no one can see the marked paper, if the ballot cannot be photographed, and if the depositing of the ballot cannot be observed.

ODIHR found all of those conditions failing in Georgia's 2024 election. Twenty-four per cent of observations revealed potential secrecy compromises from how ballots were inserted into boxes. Twelve per cent from how voters marked their ballots. Seven per cent from inadequate polling-station layouts. The secret ballot is not a law you pass. It is a physical, procedural, and architectural fact you either achieve or you don't.

When those conditions fail — when a voter can be seen, or when pressure to disclose follows them home — the enforcement mechanism is restored. The threat becomes credible. And money starts moving.


What makes coercion unenforceable

Here is the harder question: what would it actually take to make coercion structurally impossible?

Not just illegal. Not just discouraged. Structurally impossible, in the sense that no matter how hard a coercer tries, they cannot confirm compliance.

The classic answer is the physical secret ballot: a private marking area, no marks linking the paper to the voter, deposited in a sealed box no one can watch. That model, when it works, is genuinely powerful. Courts in England voided the 2014 Tower Hamlets mayoral election partly because postal ballots — moved outside the controlled polling-station environment — had been gathered, handled, and manipulated by third parties in ways the chain of custody could not rule out. The election court's judgment found practices including postal-vote fraud, bribery, and undue pressure. The moment the ballot leaves the booth, the privacy guarantee weakens.

Mexico's 2015 Colima gubernatorial election was voided by the Electoral Tribunal after finding that state officials had used public resources and intimidation to benefit a candidate — pressure from above, not from a street-level buyer, but the mechanism is identical: applying leverage to voters who cannot prove their vote was independent.

And the Philippines Supreme Court, in Nolasco v. COMELEC (1997), upheld the disqualification of a mayor-elect for vote-buying — envelopes containing money, distributed with the candidate's name attached. The court held that even the offer of payment constitutes the offense. Criminal penalties matter. But the deeper defense the court could not provide is architectural: if the vote could not be proven to the buyer, the envelope would have been useless from the start.

Criminal prosecution is the cleanup operation. Anonymity by design is the prevention.


The digital dimension

Now introduce technology, and the problem sharpens.

Digital systems can break ballot secrecy in ways a paper booth cannot. An internet-voting system that stores a link between your identity and your vote — even temporarily, even only server-side — is an attack surface for a coercer with access. A voting machine that produces a QR-coded receipt that only the machine can read is, as a federal court found in Curling v. Raffensperger, not a voter-verifiable record at all: the voter cannot confirm what the code says, and the hand count audits the machine's output, not the voter's intent.

Independent researchers who analyzed Estonia's i-voting system and published at ACM CCS 2014 found that a dishonest insider or well-resourced attacker could compromise vote integrity or voter privacy without detection. The system's design meant that even if a voter thought their ballot was secret, it might not be — not to an adversary with the right access.

This matters for coercion directly. If a government or employer has access to the infrastructure processing digital votes, they can potentially identify how individuals voted. The secret ballot fails not at the polling booth but at the server.

The question to ask of any voting system is not 'is it certified?' It is: 'can anyone — an employer, a political operative, a state-level attacker — link my identity to my choice after the fact?' If the answer is 'you'll have to trust the vendor and the officials,' the answer is not good enough.


The verifiability problem cuts both ways

Here is where the Kyrgyzstan story connects to a broader argument this blog has made in other contexts.

When we talk about verifiability in elections, we usually mean: can the public check that the count is correct? Can outsiders confirm that the machine totals match the paper? Can a losing candidate audit whether ballots were properly handled?

All of that matters enormously. Malawi's 2020 presidential election was voided because tally sheets had been overwritten with correction fluid and no one could confirm what the originals said. Kenya's 2017 presidential election was annulled because result forms had not been transmitted as required and the final tally form lacked consistent security features. The Supreme Court of Kenya held that an election whose results cannot be independently verified cannot be legally or democratically sound.

But there is a second kind of verifiability, running in the opposite direction, that is equally essential: the voter must not be verifiable to anyone else.

The two requirements are in tension, and designing a system that satisfies both simultaneously is genuinely hard. You want the count to be publicly auditable — every batch, every total, every step from ballot to result — while ensuring that no individual ballot can be traced to an individual voter. You want cryptographic certainty that all cast votes were counted, while ensuring the voter cannot generate a proof of their own vote to show a coercer.

This is not a theoretical problem. Switzerland's 2019 e-voting code review found a cryptographic trapdoor in the shuffle proof — a flaw that would have let an authority generate a proof that looks valid while actually concealing altered votes. The system's claimed verifiability was unfalsifiable until the source code was published and independent cryptographers looked. What they found was that the guarantee only held if you trusted the authority that held the trapdoor values — precisely the trust the cryptography was meant to replace.

Getting verifiability right, in both directions, requires independent scrutiny of the cryptography, not just the vote-count.


What still cannot be independently checked

Kyrgyzstan's 2017 election was assessed as competitive. Candidates could generally campaign freely. The result was not voided. The OSCE observers documented their concerns, made their recommendations, and filed their report.

But ODIHR's recommendations — guarantee the right to a free and secret choice, prohibit pressure to disclose, ensure effective penalties — are addressed to authorities. They are requests, not mechanisms. The same body made comparable recommendations in Albania, in Bulgaria, in Georgia, in North Macedonia. The pattern recurs because the underlying architecture that would make coercion unenforceable has not been built.

What would make it checkable by anyone, not just by official observers?

  • Voting systems whose anonymization is cryptographically provable and independently auditable, so that no insider access can link a ballot to a voter — and anyone can verify the proof.
  • Instant, precinct-level result publication in machine-readable formats, so that unexplained totals are caught before they harden into certified results, and before pressure can quietly shape them.
  • Physical polling-station standards that are enforceable and observable: private marking areas, sealed deposit, no photography of marked ballots.
  • Audit chains from individual ballot to national total that any observer — not just officials — can traverse and verify.

The case from Kyrgyzstan is not about a distant or exotic problem. It is about the structural logic of coercion: a threat only works if it can be enforced, and it can only be enforced if compliance can be checked. Remove the ability to check, and the threat collapses. The secret ballot was invented to do exactly that — 170 years ago, in Australian polling booths, and then in British market towns.

The question that remains open is whether modern voting systems — digital, networked, complex — actually deliver that guarantee, or whether they quietly hand it back to anyone with the right access.

No official statement answers that question. Only a system designed so the public can check it themselves.


Explore how common this gap is across elections worldwide at /atlas, or read the two-minute version of the core argument at /simple. For a full breakdown of where verifiability fails, visit /gaps.


Sources