← All posts

Why a paper trail isn't enough on its own

A Princeton professor plugged a real voting machine into his lab bench in 2006 and proved it could steal an election without leaving a single traceable fingerprint — and paper still wouldn't have saved it.

It took Ariel Feldman, J. Alex Halderman, and Edward Felten about a minute.

One minute of physical access to a real Diebold AccuVote-TS touchscreen voting machine — the kind that counted millions of American votes in the mid-2000s — and the Princeton researchers had installed malicious code that could silently redistribute votes between candidates. The code altered every internal counter, log, and record to stay internally consistent. It left no fingerprint. It could even spread from machine to machine automatically, the way a cold moves through an office, during ordinary pre-election setup routines.

They published their findings in 2006. The machines were still in use.

Here is the part that should stop you: when this kind of tampering was raised as a concern, the standard reassurance was that these machines would eventually be replaced by systems with a paper trail. Problem solved, case closed.

Except it isn't. Not even close.


The comforting lie we tell about paper

Paper is good. A physical ballot that a voter has marked and verified is genuinely better than a paperless touchscreen. Nobody serious disputes that. The Sarasota County, Florida race in 2006 ended with 18,000 missing votes and a margin of 369 — and because those touchscreens produced no paper record whatsoever, there was literally nothing independent to recount. Paper would have been better than that. Full stop.

But here is what the "paper fixes it" framing quietly skips over: a paper record only protects an election if someone is required to check it, and if that check can actually change the certified result.

Those two conditions — required, and binding — are not the default in most places. They are the exception. And without both, the paper sitting in those sealed bags after election night is a prop, not a safeguard.


What the Princeton machine really proved

Go back to that Diebold AccuVote-TS. Feldman, Halderman, and Felten weren't just demonstrating a theoretical vulnerability. They built a working vote-stealing virus on real hardware. The attack was undetectable by any internal audit log because the attack controlled the internal audit logs.

Now imagine that machine had also printed a paper record of each vote as it was cast — a so-called Voter Verified Paper Audit Trail, or VVPAT. Would that have stopped the attack?

Only if someone compared the paper to the machine totals. Only if that comparison was legally required, not optional. Only if a discrepancy would have triggered a binding investigation rather than a press release. And only if the sample of paper ballots examined was large enough to have a real statistical chance of catching a close-race manipulation.

In most states that deployed those machines, none of those conditions were met. The paper would have been printed, bagged, sealed, and locked in a storage room unless someone sued to open it. A paper trail that nobody is required to follow is just expensive recycling.

This is the gap the Princeton study actually exposed — not merely that a machine could be hacked, but that the entire verification architecture around it was hollow. The machine was unauditable by design, and the political and legal systems around it weren't demanding that it be audited at all.


The night Coffee County's entire voting system walked out the door

On January 7, 2021 — the day after Congress was scheduled to certify the presidential election — a computer-forensics firm was let into the Coffee County, Georgia elections office. What they copied wasn't just a file or two.

They took the Election Management System server. Poll pads. Ballot-marking devices. The scanner. And Georgia's statewide Dominion voting-system software.

All of it. One county. One day.

The Georgia Secretary of State's office called it unauthorized access that former county officials had enabled in violation of state law. The episode is documented in depositions filed in the federal Curling v. Raffensperger case. Several people connected to it later pleaded guilty to charges related to the broader effort to overturn Georgia's 2020 results.

Here is what the Coffee County episode makes viscerally clear: the security model that said "the software is proprietary and therefore safe" died in that office on January 7th. Secrecy is not a security architecture. Once someone with keys lets you in the door, the secret is out — and in this case, the software then spread beyond Coffee County entirely.

But here is the part that connects directly to the paper-trail question: Georgia does use paper ballots. It has paper. It ran a massive hand count of nearly 5 million presidential ballots in 2020. The paper exists.

The Coffee County breach happened anyway — because paper protects the count, not the software environment, and not the chain of custody of the system that generates and marks those ballots in the first place. If your ballot-marking device has been compromised, the paper it prints may faithfully record what the compromised device told it to print. The paper is only as trustworthy as the process that created it — and that process lived on servers that just got copied and walked out of an elections office in a small Georgia county.


When the audit isn't allowed to matter

Let's grant that you have paper ballots, honestly marked by voters who verified them before they left the booth. You're still not protected unless the audit is binding.

This is where the "non-binding audit" gap becomes concrete. Several states and jurisdictions have passed post-election audit requirements that look rigorous on paper — a random sample of precincts, a hand count, a comparison — but include no mechanism for the audit to change the certified result. The audit is reported. Discrepancies are noted. And then the certified result stands.

Think about what that means in practice. If your audit is legally non-binding, then what it actually provides is a way for officials to say "we did the audit" while the audit cannot, under any scenario, affect the election's outcome. The act of auditing becomes a communications exercise — a ritual that confers legitimacy without providing accountability.

Compare that to what Colorado built. Starting in 2017, Colorado became the first state to complete a statewide risk-limiting audit — a process that statistically sizes the hand-check to the margin of the race. Close race? Examine more ballots. Lopsided race? Fewer ballots needed. The key feature: if the audit doesn't confirm the reported outcome at the required confidence level, you keep going. You examine more paper. The math won't let you stop early and call it done.

That is what "binding" looks like. The audit has teeth because it controls whether the result stands.

Without that structure, paper is a comfort object.


The hard lesson from Antrim and its dozen lost votes

In December 2020, after Antrim County, Michigan published wildly wrong unofficial results — results so implausible for a reliably Republican county that they were caught almost immediately — a full hand audit was conducted. Every presidential ballot, by hand. The Michigan Department of State certified the result.

But here is the number that tends to get quietly set aside in the celebratory "audit confirmed it" headlines: the hand count still differed from the machine tabulation by about a dozen votes out of roughly 15,700 cast.

Twelve votes. In a full, careful, legally supervised hand audit.

Now: in Antrim County in 2020, twelve votes was not a problem. The county-level presidential margin was not close, and no race that mattered was decided by a dozen votes in Antrim. The error was irrelevant to the outcome.

But think carefully about what "irrelevant to the outcome" is doing in that sentence. It is load-bearing. The hand count is only reassuring because the margin was big enough that the hand count's own error didn't matter. If the real margin had been eight votes, the hand count — the gold standard, the thing we hold up as proof — could not tell you who won. The very method used to verify the result is itself uncertain by roughly the same number of votes as the race being decided.

FactCheck.org's account of Antrim rightly focuses on debunking the conspiracy theories — there's no evidence of hacking or manipulation — but the twelve-vote discrepancy whispers something the reassuring headline doesn't say: even honest, well-run human hand counts have irreducible error. They always will. Ballots have ambiguous marks. Counters make mistakes. Adjudication involves judgment calls that two different people would decide differently.

"The audit confirmed it" is a reassurance. In a race decided by a handful of votes, using a method that is itself uncertain by a handful of votes, it cannot be proof.


What would actually make this checkable

Here is the honest version of what a genuine verification architecture requires. Not trust — verifiability.

First: paper that voters actually verified. Not paper printed by a machine and never examined by the voter, but a ballot or paper record the voter read and confirmed before it was cast. This is the foundational layer everything else depends on.

Second: audits that are required by law, not optional. If the audit only happens when a candidate requests it, or only when a race is close enough that a candidate can afford the legal fees to demand one, then in most elections, in most years, in most jurisdictions, there is no audit. The paper sits in storage until it is destroyed.

Third: audits that are statistically sized to the margin. A fixed-percentage spot check — "we looked at 3% of precincts" — provides very weak evidence in a close race. A risk-limiting audit, sized to the margin, provides defined statistical confidence. There is a meaningful difference between "we checked some stuff" and "there is a 97% probability the reported winner actually won."

Fourth: audits that can change the result. If the audit finds a discrepancy and the law says "note it and certify anyway," you have a paper record and you have an audit and you have nothing. The chain is only as strong as its weakest link, and a non-binding audit is a broken link.

Fifth — and this is where cryptographic verifiability enters the picture — the check shouldn't depend entirely on trusting the humans running the check. The Princeton researchers showed that a machine can manipulate its own records. Coffee County showed that proprietary software can be stolen, spread, and remain hidden inside black-box systems for months. The hand count in Antrim showed that human counters introduce their own errors.

The exit from this maze isn't to find a more trustworthy official. It is to build systems where the public — any member of the public, with no special access — can independently verify that their vote was included, unchanged, in the final tally. That is what end-to-end verifiable voting and cryptographic audit trails are designed to do. Not to replace paper, but to make the check genuinely independent of the people running the election.


The question that should keep you up at night

After every election, officials release statements confirming that audits were conducted and results were certified. Most of those statements are probably accurate. The people running elections in most places are conscientious civil servants doing difficult, underpaid work.

But "the Secretary of State says it confirmed" is a claim. It is not verification. The whole architecture of democratic legitimacy rests on the possibility that the official running the election might be wrong — or, in the worst case, might not be neutral. That possibility is not paranoia; it is the premise that makes independent checks necessary in the first place.

A paper trail that no one is required to check cannot catch a software attack like the one Princeton demonstrated. It cannot catch what happened in Coffee County. It cannot settle a race decided by fewer votes than the hand count's own error margin.

What you cannot verify, you can only trust. And trust is not a security architecture.

The paper in those sealed bags after election night is necessary. It is not sufficient. The gap between those two words is where most American elections currently live — and it is a gap that stronger audit law, statistical rigor, and cryptographically verifiable systems could close.

Most places haven't closed it yet.


See how common the 'non-binding audit' and 'no paper to recount' gaps are across jurisdictions — or read the two-minute version of why paper alone isn't enough. If you want to go deeper on what a risk-limiting audit actually does (and doesn't) prove, we've mapped the core verification gaps here.


Sources