← All posts

When a 'recount' just re-reads the same barcode

Georgia counted five million ballots by hand and called it a recount — but if the scanner reads a QR code you can't decode, what exactly did anyone just count?

It is November 2020, and somewhere in a Gwinnett County, Georgia polling station, a voter has just finished making her choices on a Dominion ballot-marking device. The machine prints a sheet of paper. She holds it. There is human-readable text — her candidate's name, her choices laid out in plain English. There is also a QR code, roughly the size of a postage stamp, in the corner.

She cannot read the QR code. No one in the room can read the QR code with the naked eye.

She feeds the sheet into a scanner. The scanner reads the QR code. The QR code, not the text, determines how her vote is tabulated.

Six weeks later, Georgia counts those sheets by hand in what will be called a historic audit — one of the largest manual recounts ever conducted. Roughly five million ballots, examined by human eyes across 159 counties. Officials announce the count confirms the machine result. Media declare it a vindication.

Here is the question nobody asked loudly enough: what did those humans actually look at?


The federal court that asked the uncomfortable question

On October 11, 2020 — three weeks before Election Day — a federal judge in Atlanta was reading expert testimony that most voters will never encounter.

In Curling v. Raffensperger, the U.S. District Court for the Northern District of Georgia reviewed the security and verifiability of Georgia's Dominion ballot-marking device system. The court heard from Dr. J. Alex Halderman, one of the country's leading election-security researchers, who described how a cyberattack could feasibly swap or delete votes by altering the QR barcode used for tabulation.

More precisely, and more durably, the court found that the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter."

The court also quoted the National Academies of Sciences, Engineering, and Medicine's 2018 conclusion: no technical mechanism currently exists to ensure a vote-counting application produces accurate results, and testing alone cannot ensure systems have not been compromised.

The judge declined to order emergency relief — switching an entire state's voting infrastructure weeks before a presidential election would have introduced a different category of chaos. That was a reasonable call under the circumstances. But the legal outcome does not resolve the underlying problem. The court identified it, named it, and left it open. Read the full opinion here.


What a recount actually recounts

Here is the mechanism, stated as simply as possible.

A ballot-marking device (BMD) works like this: you touch a screen, make your selections, and the machine prints a ballot. That ballot contains two representations of your choices. One is human-readable text. The other is a machine-readable QR code. When the ballot enters a scanner, the scanner reads the QR code. The QR code is what the tabulation software processes. The human-readable text is not what gets counted.

Now conduct a hand recount. Workers pick up each printed ballot and read — what? The human-readable text. They tally based on what the ballot says in words.

If the QR code and the human-readable text agree, the hand count confirms the machine count. Good. But the recount did not verify the QR code. It verified the text. The question the recount cannot answer is whether the QR code — the thing that was actually tabulated — matched what the voter chose.

A compromised BMD could, in theory, print human-readable text saying "Candidate A" while encoding a vote for Candidate B in the QR code. The voter, glancing at the text, sees their choice represented correctly. The scanner tabulates Candidate B. A subsequent hand count reads the text and also counts Candidate A. Machine total and hand count both say Candidate A — and the fraud, if there was one, is invisible in both.

That is not a paranoid fantasy. It is the attack surface the federal court in Curling was describing.

A paper printout is not the same as a voter-verifiable record. If the thing being counted is not the thing the voter can inspect, "we counted the paper" and "we verified the vote" are two different sentences.


Georgia's five-million-ballot audit: what it proved, and what it didn't

Georgia's November 2020 risk-limiting audit became a full hand count because the margin was narrow enough to require it. Roughly 41,881 batches, 159 counties, about five million ballots examined by human hands in under six days. The hand count confirmed the machine-tabulated outcome to within about a tenth of a percent.

That is genuinely impressive as a logistical achievement. It is also a meaningful finding — it means the human-readable text on the printed ballots, tallied by hand, matched the machine total. If there had been a systematic, large-scale discrepancy, it would have surfaced.

But notice what "matched" means here. The human-readable text matched the machine total. That is consistent with two explanations: the QR codes were accurate and matched the text, or the QR codes were systematically corrupted in a way that also corrupted the machine total, and the hand count of the text confirmed the corruption rather than catching it.

The hand audit cannot distinguish between these two scenarios. It was not designed to. It checked the text against the total. It did not decode and individually verify every QR code.

This is not a reason to disbelieve the Georgia result. There is no evidence of large-scale QR code tampering in Georgia's 2020 election. But "no evidence of tampering" is not the same as "the system would have caught tampering." The Curling court's point was exactly this: a system whose auditing mechanism cannot close the loop between the tabulated artifact and the voter's verified intent is not fully auditable, regardless of how many humans touch the paper.

Antrim County, Michigan in 2020 showed a version of this at a smaller scale: wrong numbers were published, caught only because they were absurd — a reliably Republican county showing the opposing candidate ahead by thousands of votes. When the county's hand count ran, it differed from the corrected machine tally by about a dozen votes out of roughly 15,700. A dozen votes. In a close race, a method that is itself off by a dozen votes cannot definitively settle a question decided by fewer than a dozen. 'The audit confirmed it' is a reassurance; it is not proof.


The irreducible error in "just count by hand"

There is a romantic idea that a hand count is always the gold standard — that human eyes are the ultimate check. This is partly true and partly misleading.

Hand counts introduce their own error rates. Tally fatigue. Ambiguous marks. Different readers making different calls on a ballot with a light mark. Adjudication decisions that vary from table to table. The Windham, New Hampshire forensic audit in 2021 found that when AccuVote scanners misread ballots — because a fold crease happened to pass through a vote target — a hand count could recover voter intent that the machine had lost. In that case, paper ballots existed and a hand count improved on the machine result. Good.

But Windham also illustrates the floor, not the ceiling. The error was found because auditors had a durable physical ballot — a mark made directly by the voter — to go back to. The scanner's misread of a fold crease was detectable because the underlying intent was still physically present on the paper.

In a BMD system, there is no directly voter-marked mark to recover. The voter touched a screen. The machine printed a representation of that touch. If the representation is wrong — in the QR code, in the software, in the tabulation — there is no original mark to compare it against. The printout is not the voter's mark. It is the machine's transcription of the voter's mark, and it is the only record that exists.

This is the structural gap that the Curling court identified. It is also why Colorado's risk-limiting audit model — the first statewide RLA, completed in 2017 — works better when applied to hand-marked paper ballots. An RLA gives you a statistical confidence level that the reported outcome is correct, sized to the closeness of the race. But it requires a trustworthy paper record to audit against. If the record itself is the machine's output rather than the voter's direct mark, you are auditing the machine's honesty, not the voter's intent.


Why "the voter saw the text" isn't enough

Officials and vendors will point out — correctly — that voters are encouraged to review the printed ballot before casting it. If the text is wrong, the voter can reject the ballot and start again.

This is true. It is also an incomplete defense, for two reasons.

First, behavioral reality. Most voters do not carefully read every line of a printed ballot summary, especially in a busy polling place with a line behind them. Research on human verification behavior in security contexts is consistent: users routinely accept automatically generated summaries without checking them character by character. A system that relies on 100% of voters performing a careful audit of machine output is a system that has already delegated most of its verification burden to people who are distracted, hurried, and untrained.

Second, and more fundamentally: even a voter who reads and approves the text has not verified the QR code. She has confirmed the text matches her choices. She has not confirmed the QR code does. The scanner does not tabulate the text. The voter verified one thing; the system counted another. Those are not the same verification.

The German Federal Constitutional Court captured this logic precisely in 2009 when it struck down electronic voting machines on the grounds that the essential steps of voting and counting must be examinable by ordinary citizens without specialist knowledge. The court found that a system whose correctness rests on trusting hidden processes fails the public-verifiability test — regardless of whether tampering has ever been proven. The principle applies equally to a QR code no ordinary citizen can decode.

The Dutch came to the same conclusion in 2007, when the government's independent commission on elections stated that there are no secrets in the election process and that answers must be checkable and verifiable by anyone — and recommended scrapping voting computers in favor of paper ballots a human can read directly.


The real gap: what would "auditable" actually mean?

An auditable ballot record is one where what was counted is the same thing the voter could verify — and where an independent check can confirm the two are identical.

For hand-marked paper ballots, this closes naturally. The voter marks the paper. The scanner reads the paper. An auditor examines the paper. The voter's mark, the machine's reading, and the auditor's reading all refer to the same physical object. Discrepancies between the machine and the auditor indicate a scanning error; both can be checked against the same source.

For a BMD system printing QR codes, this loop is broken. The voter verifies text. The machine tabulates a barcode. An auditor reads text. Nobody — not the voter, not the auditor — independently checks whether the barcode said what the text said.

Closing that loop requires one of two things. Either: the QR code is printed in a form the voter and auditor can independently decode (a human-readable encoding, or a separate independent display that decodes it in real time). Or: the tabulation software and the QR encoding are themselves open, independently inspectable, and subject to adversarial testing — so that the encoding step can be verified to be honest before any vote is cast.

Los Angeles County's Voting Solutions for All People (VSAP) system, certified by California in 2018 as the first publicly-owned, open-source election tally system, is an example of the transparency-by-design principle: if the code is public and independently auditable, the encoding step can be examined by outsiders rather than trusted on the vendor's say-so. Open code is not sufficient on its own — implementation, chain of custody, and independent testing all still matter — but it removes the core opacity.

Brazil's Superior Electoral Court runs an annual public adversarial security test: qualified citizens are invited to try to break the voting machines, findings are used to improve the system, and fixes are re-checked. That is a structural commitment to independent verification, not a one-time certification.

The alternative — a closed, proprietary system certified once and thereafter trusted — is the model the Curling court implicitly indicted, and that the Coffee County breach in 2021 made viscerally concrete: the proprietary software Georgia relied on for security through secrecy was copied and distributed in a single afternoon.


What is still not verifiable — and what would make it checkable

Here is where the Georgia 2020 story stands today, told honestly.

The hand count confirmed that the human-readable text on roughly five million printed ballots matched the machine tabulation. That is a meaningful data point. It is not a complete audit. The gap between "the text matched" and "the QR codes accurately encoded the voter's choices" has not been independently closed by any public process.

The Curling case itself was later dismissed on standing grounds in 2024. The procedural outcome does not address the technical finding. A court's inability to grant relief — because an election is too close, or standing is too narrow — does not mean the underlying vulnerability has been fixed.

What would actually close the gap?

  • Real-time, independent decoding of QR codes at the polling place, displayed to the voter before the ballot is cast, using hardware or software independent of the BMD vendor.
  • Open, publicly inspectable source code for the encoding step, subject to adversarial review by researchers who are not employed by or contracted to the vendor.
  • Routine, independent statistical sampling of QR codes post-election, decoded by independent tools, compared to the corresponding human-readable text, published at the precinct level in machine-readable form for anyone to download and check.
  • RLAs applied to hand-marked paper ballots wherever possible — so the artifact being audited is the voter's direct mark, not a machine's transcription.

None of these require assuming that any official is dishonest. They require only that we stop treating "the officials checked it" as the end of the verification chain, and start treating independent, public checkability as the standard every system has to meet.

The recount that re-reads the barcode is not a recount. It is a reproduction.

A real audit goes back to what the voter actually verified. Right now, in most jurisdictions using ballot-marking devices, that standard is not being met — and no official statement changes that fact.

See how this gap appears across voting systems worldwide →

Read the two-minute version of the auditable ballot problem →


Sources