← All posts

When one company builds, runs, and vouches for the vote

On August 2, 2017, the company that built Venezuela's voting machines told the world — publicly, in plain English — that the official turnout figure was a lie. No opposition party said it. The vendor did.

It is the evening of July 30, 2017, and Venezuela's National Electoral Council has just announced a number: 7.5 million people voted in the National Constituent Assembly election. The announcement was designed to confer legitimacy. An elected superbody would rewrite the constitution. The government needed the turnout to look decisive.

Forty-eight hours later, Smartmatic — the London-registered company that had built and operated Venezuela's automated voting infrastructure since 2004 — issued a public statement. Its chief executive said the company knew "without any doubt" that the announced turnout figure had been manipulated, and estimated the gap between actual and announced participation at "at least one million votes." Smartmatic said it could not endorse the official numbers.

Then Smartmatic walked away. It withdrew from Venezuela's subsequent 2017 regional and municipal elections and ceased all business in the country by 2018.

Read that again slowly: the vendor who built the system, ran the system, and certified the system's output declared the system's output was wrong.


The moment the chain of trust ate itself

Here is why that scene is so structurally important, and why it reaches far beyond Venezuela.

In most countries, the chain of trust in an electronic election runs like this: voters trust the machines; officials trust the vendor's certification; observers trust the officials; the public is asked to trust all of the above. The architecture is a tower, and every stone rests on the one below it.

In Venezuela in 2017, every stone was the same stone. The National Electoral Council did not own an independent audit trail. There was no cryptographic record a third party could check. There were no paper ballots Smartmatic could point to as contradicting the official total. The only party positioned to know whether the turnout figure was accurate was the party that had produced it: the vendor. And that vendor, having reached the end of whatever contractual or reputational calculation it was making, said: no.

When the vendor is simultaneously the builder, the operator, and the sole verifier, there is no such thing as an independent check — there is only a single point of trust that can fail all at once.

The public, the opposition, international observers — none of them had access to data that would let them confirm or refute either claim. The official number. The vendor's counter-claim. Both were assertions. Neither was provable from outside.

That is the problem this post is about.


Trust concentration is a design decision, not an accident

The Venezuela case is extreme. But the underlying structure — one vendor holding the critical knowledge about how the count works — appears in milder forms in functioning democracies.

Consider what a U.S. federal court found about Georgia's voting system in October 2020. In Curling v. Raffensperger, the Northern District of Georgia reviewed expert testimony about the state's Dominion ballot-marking devices and reached a finding that has not received nearly enough attention: the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter."

The court also quoted the National Academies' 2018 conclusion that no technical mechanism currently exists to ensure a vote-counting application produces accurate results, and that testing alone cannot ensure systems have not been compromised.

A voter stands in front of the machine. She makes her selections. A sheet of paper prints. She sees her candidates' names in human-readable text. She thinks she has verified her ballot. But what the tabulator actually counts is a two-dimensional barcode — and she has no way to read it. Neither does the poll worker. Neither does the party observer standing five feet away.

The court understood the problem and declined to order last-minute relief, given the proximity of the election. That is a defensible judicial judgment about disruption. But notice what it did not do: it did not find the problem did not exist. The unreadable QR code is a permanent feature of a system architecture in which the tabulation logic is, for all practical purposes, invisible to everyone except the vendor.

This is trust concentration of a different kind than Venezuela's — but it is trust concentration.


What "certification" actually certifies

Both cases share a common origin story: the idea that a vendor's system, once certified, can be trusted to run the count.

The U.S. Government Accountability Office looked hard at that assumption in its 2005 report (GAO-05-956). It found that documented problems with electronic voting systems had raised questions about their security and reliability, and that federal efforts to improve those systems were underway — but that key activities remained incomplete. Certification was still being built as a process even as elections ran on the systems it was supposed to validate.

Ireland discovered the same gap earlier. An independent Commission on Electronic Voting, examining the Nedap/Powervote system the government had procured, concluded it was "not in a position to recommend with the requisite degree of confidence the use of the chosen system." Critically, the Commission's finding was not that the system would fail — it was that it had not been proven to the Commission's satisfaction that it would work. The inability to verify was itself the disqualifying condition. Ireland spent €52 million on machines that were formally scrapped in 2009.

Notice what links these cases: the burden of proof was on the wrong party. Officials and vendors were asked to demonstrate trustworthiness to an independent body — and the independent body's conclusion mattered. That is the correct structure. The problem is that it is the exception, not the rule. In most jurisdictions, certification is a one-time test conducted before deployment. The system passes or fails once. It then runs in live elections — sometimes for a decade — without another independent check of equivalent rigor.

In that gap between the certification test and election day, a great deal can change. Software is updated. Configurations shift. Staff turn over. And the only party that knows, in real time, what the system is actually doing is the vendor.


The Georgia forensic episode: what insider access looks like

The Venezuela case involved a vendor blowing the whistle from outside. The Coffee County, Georgia episode in January 2021 illustrates a different version of the same structural vulnerability: what happens when someone with insider access decides to take, rather than disclose.

On January 7, 2021, a computer-forensics firm was admitted into the Coffee County elections office and made copies of the voting system software — the Election Management System server, poll pads, ballot-marking devices, scanners, and Georgia's statewide Dominion voting-system software. The Georgia Secretary of State's office later described this as unauthorized access that former county officials allowed in violation of state law. Several people connected to the episode subsequently pleaded guilty to charges. The event is documented in depositions in Curling v. Raffensperger.

Here is the architectural lesson: the entire jurisdiction's voting software was proprietary. Its security model depended on secrecy — on the code staying hidden. The moment someone with physical access decided to share it, the secrecy was gone. Everything that rested on it — the security model, the chain of trust, the certification's implicit promise — went with it.

Secrecy is not security. A system built to be verified by insiders alone is a system built to fail the moment an insider is compromised, coerced, or simply cooperative with someone they shouldn't be.

Open, independently inspectable code does not solve every problem. Certification, chain of custody, and rigorous post-election auditing still matter enormously. But open code at least removes the layer of opacity that makes the vendor or the official the sole arbiter of what the software is doing. Los Angeles County's VSAP system — the first publicly-owned, open-source election tally system certified under California's voting-system standards, certified in August 2018 — is a proof of concept that this is achievable. Whether open code is actually running on election day requires further verification (a point the Swiss Post/Scytl trapdoor episode demonstrates vividly). But opacity guarantees no one outside the vendor can check.


The deeper problem: "we verified it" is not the same as "you can verify it"

After the 2020 U.S. election, on November 12, 2020, a group of senior election-security officials published a joint statement declaring the election "the most secure in American history." The statement was signed by officials across the Election Infrastructure Government Coordinating Council and its Sector Coordinating Council partners, and published by the Cybersecurity and Infrastructure Security Agency.

Read it carefully, and you find something interesting. The statement's own reasoning for why it was confident rests substantially on the existence of paper records that allow recounts and audits. That is: the officials were saying, implicitly, that their confidence came from the audit mechanisms that let someone check the machines' output — not from trusting the machines on faith.

That is actually the correct argument. But it only holds where paper records are independently readable and audits are robust. In Georgia in 2020, a statewide hand count of roughly 5 million ballots — 41,881 batches examined across 159 counties in less than six days — confirmed the machine-tabulated outcome to within about a tenth of one percent. That is the kind of independent verification that makes confidence defensible.

The problem is that the Georgia hand count worked because Georgia had voter-marked paper ballots from the 2019 and earlier systems that people could read with their eyes. A hand recount of a QR code ballot-marking-device system audits the barcode's output — not the voter's intent. The Curling court said exactly this: the QR code cannot be read and verified by the voter. If a machine encodes the wrong candidate in the barcode while printing the right name in human-readable text, the audit will confirm the machine's encoding, not the voter's choice.

A recount is only as trustworthy as the record it is counting. A "confirmed by hand count" on a ballot no one could read in the first place is a reassurance, not a proof.


What independent verifiability actually requires

The German Federal Constitutional Court drew the line in 2009, in a ruling on Nedap voting machines used in the 2005 Bundestag election. The Court held that the use of electronic voting machines requires that "the essential steps of the voting and of the determination of the result can be examined by the citizen reliably and without any specialist knowledge of the subject." The machines stored votes only in electronic memory, with no record voters could check. They failed this standard.

"Without any specialist knowledge." That is the operative phrase. Verifiability is not satisfied by telling the public that experts reviewed the system. It is not satisfied by a vendor's internal testing. It is not satisfied by an official statement that everything checked out. It is satisfied when the record produced is one that any interested citizen — not just a computer scientist, not just a certified auditor, not just the vendor — can examine and confirm matches what was intended.

That is a high bar. But it is the correct bar. And the cases above show what happens when it is not met.

In Venezuela, the vendor was the only party with the knowledge to compare the announced turnout to what the machines recorded — and when the vendor and the government disagreed, there was nothing a citizen could check to settle it.

In Georgia, the court found a system in which the tabulation artifact cannot be read by the voter who produced it.

In Coffee County, the secrecy that substituted for openness proved brittle the moment an insider chose otherwise.

The throughline is the same in each case. The choice is not between a trustworthy vendor and an untrustworthy one. The choice is between a system architecture that requires trust in a single party and one that makes trust unnecessary because anyone can check.


What would make any of this checkable?

So here is the question to close on — and it is not rhetorical.

After Venezuela 2017: Smartmatic said the turnout was inflated by at least a million votes. The government said it was accurate. There is, to date, no independent audit trail a third party could use to resolve that dispute. No publicly verifiable cryptographic record. No paper ballots. No precinct-level data that could be reconciled against a chain of custody. If you wanted to verify either claim from outside both parties, you could not. That gap — the specific, technical absence of a verifiable record — is what a well-designed system would fill.

After Curling v. Raffensperger: the court found the QR code unreadable by the voter. Georgia has since moved toward fuller use of hand-marked paper ballots in some contexts. But the question of whether any jurisdiction's tabulation software correctly translates human-readable ballot markings into counts — and whether that translation can be independently verified by someone other than the vendor — remains open in most places.

The answer is not "trust officials more" or "trust vendors less." The answer is systems designed so that neither officials nor vendors need to be trusted, because the record they produce can be checked by anyone willing to do the arithmetic.

That means cryptographically verifiable audit trails. Precinct-level results published in machine-readable form the moment they are final. Open, reproducibly buildable code. Independent adversarial testing — not as a one-time certification but as an ongoing practice. And ballot records that a voter can verify and a citizen can audit without needing to know who built the machine or what the vendor's incentives were.

Venezuela in 2017 is the clearest possible illustration of why concentration of trust in a vendor is a category error. The question it leaves open — the question that applies everywhere — is whether your jurisdiction's system would let anyone find out if the same thing happened there.

See how this gap appears across different countries and systems · Read the 2-minute version of what independent verifiability requires · Explore documented cases where the count couldn't be verified


Sources