'Trust us' vs. 'check for yourself': the only debate that matters in elections
On November 12, 2020, nine senior officials declared the election secure. The statement was true — and almost completely unfalsifiable. That gap is the whole problem.
On November 12, 2020, nine days after polls closed, a small group of senior American election-security officials sat down and wrote a statement. They were not partisans. They were professionals — from the Cybersecurity and Infrastructure Security Agency, from state and local election bodies, from the private sector. They had spent months watching for attacks on voting infrastructure. And they had something to say.
"The November 3rd election," they wrote, "was the most secure in American history."
Read that sentence slowly. It is a remarkable thing to claim. And the remarkable thing about it is not that it is wrong — there is no credible evidence it is. The remarkable thing is the form of the claim. It is an assertion by authority. It asks you to trust the people saying it.
That is exactly the wrong foundation for democratic legitimacy. And, buried in the statement's own logic, the officials seem to half-know it.
What the CISA statement actually says
Pull up the November 12, 2020 joint statement and read past the headline. The officials did not say "trust us." They offered a reason: "There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised."
And then they said something crucial: the statement emphasized the value of paper records of votes as enabling recounts and audits where needed.
There it is. Tucked into an assurance of security is an admission about how security is knowable. The statement's own confidence rests on the existence of independently checkable paper records — artifacts someone other than the authority could examine. Without those records, the assurance would be unfalsifiable: no one could check it at all.
An official 'it was secure' statement is a claim. What makes it worth anything is whether the public can independently verify it — or whether they must simply accept the word of the people who ran the election.
That is not a partisan point. It is a structural one. And it applies to any election, run by any party, in any country.
The question every election reduces to
Here is the thing about every major election dispute you have ever read about. Strip away the noise, the lawyers, the cable-news graphics. At the center of each one is always the same question:
Can the public independently check this, or must they take someone's word for it?
In Malawi in 2020, courts voided a presidential election because official tally sheets had been overwritten with correction fluid. The Electoral Commission declared a winner. The count looked like a count. But the source documents — the thing you would check the count against — had been quietly altered. Verifiability was gone, and with it, the result. The Supreme Court of Appeal confirmed the nullification.
In Venezuela in 2017, the company whose machines ran the election — Smartmatic — publicly said it knew "without any doubt" that the announced turnout had been manipulated by at least a million votes. The election authority declared a number. The vendor that produced the machines declared a different reality. Neither could be independently checked against a tamper-evident record anyone outside the government could access. The argument could not be resolved. It still has not been.
In Kenya in 2017, the Supreme Court annulled a presidential election because result forms from polling stations had not been electronically transmitted as required by law, the final tally sheet lacked a watermark or serial number, and the chairperson declared the winner before receiving all the underlying forms. The court's majority held that the chain of evidence required to independently verify the count had been broken. The result was not verifiable. It was annulled.
Three different countries. Three different technologies. One identical problem.
Germany's answer: if only an expert can check it, it isn't a real election
On March 3, 2009, eight judges in Karlsruhe produced a ruling that reframes the entire debate.
Germany's Federal Constitutional Court, in joined cases 2 BvC 3/07 and 2 BvC 4/07, struck down the use of computer-controlled Nedap voting machines in federal elections. Not because the machines had malfunctioned. Not because anyone could prove votes were changed. But because the machines stored votes only in electronic memory, with no independently verifiable record a citizen could check.
The Court's reasoning deserves to be read in the original. It held that the use of electronic voting machines requires that "the essential steps of the voting and of the determination of the result can be examined by the citizen reliably and without any specialist knowledge of the subject."
Without any specialist knowledge. A citizen — not a computer scientist, not a certified auditor, not a Secretary of State — must be able to see and check the essential steps of counting their own election.
This flows from what the Court called the principle of the Öffentlichkeit der Wahl — the public nature of elections — embedded in the German Basic Law. Elections are public acts. Their legitimacy derives from public visibility. A counting process that requires a software expert to evaluate is not publicly visible. It is privately trusted.
Germany's Constitutional Court did not ban electronic voting because machines are untrustworthy. It banned them because "trust me, I'm an expert" is structurally incompatible with democratic elections.
The Netherlands reached the same conclusion two years earlier through its own independent commission. The Korthals Altes report, Stemmen met vertrouwen — Voting with Confidence, set out core requirements for any voting system: transparency, checkability — controleerbaarheid — integrity, and ballot secrecy. Its conclusion was that there are no secrets in the election process, and that questions must be answerable and the answers checkable and verifiable. Paper won. Not as a nostalgic preference. As the only method that met the standard.
What trust-based assurances leave open
Go back to the CISA statement. The officials were right that paper records enable audits and recounts. But not every jurisdiction in 2020 had equally auditable paper records — and the statement does not distinguish between them.
Consider what a federal court found about Georgia's ballot-marking devices that same month. In Curling v. Raffensperger, the U.S. District Court for the Northern District of Georgia found that the Dominion system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter."
Think about that for a moment. There is paper. You can hold it. But the thing that actually determines your vote — the QR code — is unreadable by human eyes. If a machine were to silently alter the QR code while leaving the human-readable text untouched, you would have no way to detect it. A hand recount of the paper would recount the barcodes' output, not your intent.
This is not a conspiracy theory. It is a description of the system's architecture, confirmed by a federal court reviewing expert testimony.
The CISA statement is not wrong to point to paper records. But paper records are only as good as what is printed on them, and the public's ability to independently read and verify them. A paper trail that requires a barcode scanner to interpret is not the same as a paper trail a citizen with normal eyesight can check.
The statement also does not say: "and here is where you can download every precinct's results to verify the totals yourself." The U.S. Election Assistance Commission's own guidance urges officials to make results downloadable in machine-readable formats like .csv and .xml. Some states comply; some do not. The assurance that the election was secure is not the same as a published, machine-readable record anyone can reconcile.
What 'verification' actually has to mean
Here is what independent verifiability requires — and what it does not.
It does not mean paranoia. It does not mean that officials are liars. The Antrim County, Michigan error in 2020 — where wrong results were published briefly — was caused by a human programming mistake, not fraud. It was caught not by an internal safeguard but because the result was implausibly wrong for a county whose politics everyone knew. A subtler error, in a closer race, in a county without an obvious prior baseline, might not have attracted the same scrutiny.
And even the hand count meant to confirm the fix was off by about a dozen votes. In a race decided by dozens of votes, a verification method that is itself off by dozens of votes is not a proof. It is a better approximation with its own irreducible error.
Real verifiability means three things:
First, the record that is counted must be the same record the voter can inspect. A ballot the voter marked by hand, or a ballot-marking-device printout in plain human-readable text that the voter can verify before depositing it, satisfies this. A QR code does not.
Second, the results must be published in a form anyone can check, without asking permission. Precinct-level, machine-readable, timestamped, downloadable. Idaho does this already. So do most states, according to NCSL. But doing it better — instantly, for every precinct, in a format anyone can reconcile against the reported total — is the difference between a claim and a proof.
Third, independent adversarial testing must be built into the system, not bolted on after disputes arise. Brazil's Superior Electoral Court has run an official Public Security Test since 2009, inviting any qualified citizen to probe its voting machines and software before each election cycle. Findings are fixed and retested. This is not certification theater — it is the opposite of "trust us." It is "come try to break it, and here are the rules."
Contrast that with what happened in New South Wales in 2015: a security review had cleared the iVote online system, roughly 280,000 votes had already been cast, and independent researchers found serious flaws while the election was still running — including a verification mechanism that could itself be gamed. Or Switzerland in 2019, where publication of source code for independent review allowed cryptographers to find a trapdoor in the shuffle proof that would have let an authority generate a valid-looking cryptographic proof while having actually altered votes. The flaw was unfindable in a closed system and findable in an open one.
The pattern is consistent across every case: verifiability by outsiders catches what internal certification misses.
The thing that cannot be checked
Here is what is still not verifiable — and what would make it verifiable.
The CISA statement said there was no evidence voting systems were compromised. That is true. It is also unfalsifiable in many jurisdictions, because the audit capacity varies enormously. Colorado completed the first statewide risk-limiting audit in 2017 — a mathematically rigorous procedure that statistically confirms the reported outcome or catches it with defined confidence. Georgia conducted a full hand count of roughly 5 million ballots in 2020 that confirmed the machine tally to within a tenth of a percent. These are meaningful checks.
But other jurisdictions rely on less. And even Georgia's hand count — impressive in scale — audited paper ballots some of whose human-readable text might not have matched the QR codes that were tabulated, because the hand count read the human text, not the barcodes.
India's Supreme Court, in its April 2024 judgment, declined to scrap electronic voting but tightened the rules: symbol-loading units must be sealed and stored for 45 days after results, and candidates may request verification of the microcontroller's burned memory in 5% of machines if they dispute an outcome. A court that upheld an electronic system still found it necessary to strengthen the physical chain of custody and expand independent inspection rights. Because confidence flows from checkable evidence — not from the announcement of a result.
The question is not whether the 2020 election was secure. The question is whether you can check that, independently, without taking anyone's word for it.
For many races, in many jurisdictions, you still cannot.
That is not a stable foundation for democratic legitimacy. The fix is not a better statement from officials. The fix is a system that publishes instant, precinct-level, machine-readable results anyone can download and verify — and whose counting software anyone can inspect.
'Most secure in American history' is a starting point for a conversation about what checkable security actually looks like. It is not the end of one.
See how common this verifiability gap is across the world — browse the global election-integrity atlas. Or read the two-minute version of what makes a voting system independently verifiable — start here. If you want to dig into specific cases where the gap mattered — explore our database.
Sources
- Joint Statement, Election Infrastructure Government Coordinating Council & Sector Coordinating Council (Nov. 12, 2020) (CISA)
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Adviescommissie inrichting verkiezingsproces, 'Stemmen met vertrouwen', 27 September 2007
- Curling v. Raffensperger, No. 1:17-cv-2989-AT, Opinion and Order (N.D. Ga. Oct. 11, 2020)
- Supreme Court of Kenya, Presidential Election Petition No. 1 of 2017 (Odinga v IEBC), Judgment of 20 September 2017
- Supreme Court of Appeal of Malawi, Mutharika & Electoral Commission v Chilima & Chakwera, MSCA Constitutional Appeal No. 1 of 2020
- Smartmatic, 'Statement on the recent Constituent Assembly Election in Venezuela' (2 August 2017)
- Michigan Department of State — Final numbers from Antrim County audit
- Colorado Secretary of State — A new kind of election audit: Colorado is first to complete it
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia
- Halderman, Teague — The New South Wales iVote System: Security Failures and Verification Flaws in a Live Online Election (arXiv:1504.05646)
- Lewis, Pereira, Teague — Ceci n'est pas une preuve (trapdoor commitments in the Scytl-SwissPost Internet voting system), 2019
- Tribunal Superior Eleitoral (Brazil) — Teste Público de Segurança dos Sistemas Eleitorais
- Supreme Court of India — Association for Democratic Reforms v. Election Commission of India, 2024 INSC 341
- U.S. Election Assistance Commission — Election Results Reporting Quick Start Guide
- Idaho Secretary of State — Election Results (precinct-level maps + downloadable data)