'The most secure election in history' — a claim worth examining, not just repeating
On November 12, 2020, the most authoritative election-security statement in American history was published — and its entire argument rested on something the officials couldn't fully control.
On November 12, 2020, nine days after polls closed, a group of senior election-security officials sat down and wrote a statement. It was, by any measure, a remarkable document — not for what it claimed, but for how it claimed it.
"The November 3rd election was the most secure in American history."
The statement was published by the Cybersecurity and Infrastructure Security Agency. It was signed by the Election Infrastructure Government Coordinating Council and its Sector Coordinating Council partners — a coalition of federal, state, and local officials and private-sector election-technology experts. These were not partisans. These were the people whose job it was to know.
And yet, buried inside their reassurance was an admission so quiet that almost nobody noticed it.
The statement pointed to "paper records of votes" as the foundation of its confidence. Officials were, it said, "reviewing and double-checking the entire election process prior to finalizing results." It noted that those paper records "allow for recounts and audits." And that, implicitly, was why the election could be called secure.
Not the officials. Not the certification. Not the hardware. The paper — and the ability to check it independently.
The statement's own logic said: trust us because you could, in principle, verify us.
That is a very different claim than most people read it as. And unpacking the difference is the whole argument.
What an assurance actually is
There is a version of "this was the most secure election in American history" that is an appeal to authority. Believe us; we're the experts. It's the most common form of official reassurance, and it is the weakest.
There is another version that is an empirical claim: here is the evidence, here is the method by which you could check it, here is what we found. That is a falsifiable claim — the kind science runs on, the kind courts demand.
The CISA statement gestured at the second version while most of its audience heard the first.
The distinction matters enormously, because the two versions carry completely different implications. An appeal to authority collapses the moment the authority is doubted. An evidence-based claim survives the doubters — it tells them where to look. If an assertion's only defense is the credibility of the person making it, then undermining the person is enough to undermine the assertion. But if the assertion rests on independently verifiable evidence, it doesn't matter who you trust: you can check.
The CISA statement's authors understood this, at least structurally. They built their case on paper records. Paper records are verifiable by anyone with eyes. You don't need to trust the Secretary of State if you can look at the ballot yourself.
The question worth asking — and that this post is asking — is: was that verification actually available? And where it wasn't, what does the assurance actually prove?
The infrastructure the statement rested on
To understand what paper records can and cannot do, you need to know what happened in the weeks after November 3, 2020 — not the political story, but the mechanical one.
Georgia conducted what became, in effect, a full hand count of roughly five million presidential ballots across 159 counties, examining 41,881 batches over less than six days. The hand count affirmed the machine-tabulated outcome: the variation between the original count and the hand count was about a tenth of one percent. That is real verification. It is the CISA statement's logic playing out in practice — paper records existed, and humans checked them.
Colorado had, in 2017, become the first state to complete a statewide risk-limiting audit — a procedure that provides strong statistical evidence the reported outcome is correct, sized to the closeness of the race. Colorado started at a 9 percent risk limit and later tightened it to 3 percent. These are not symbolic exercises. They are the thing the CISA statement implied when it said paper records "allow for recounts and audits."
But not every state had this infrastructure in place in 2020. Not every jurisdiction used voter-marked paper ballots. And even where paper existed, the CISA statement's confidence rested on a precondition — that the paper could actually be checked against the machine count — that was not universally satisfied.
What happens when the paper can't be read
In October 2020, a federal district court in Atlanta read expert testimony that most voters in Georgia had never seen and still haven't.
The case was Curling v. Raffensperger. The court examined Georgia's Dominion ballot-marking devices — the touchscreen machines voters used to select their choices, which then printed a ballot the voter placed in a scanner. The printed ballot included a QR code. The QR code is what the scanner tabulated.
The court found that the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter." It quoted the National Academies' 2018 conclusion that no technical mechanism currently ensures a vote-counting application produces accurate results, and that testing alone cannot ensure systems have not been compromised.
Think about what that means for the CISA statement's logic. The statement's confidence rested on paper records enabling audits. But in Georgia in 2020, the "paper record" was a ballot whose tabulated content — the QR code — was unreadable by human eyes. You could recount the paper. You could look at the human-readable text printed above the code. But the thing the machine actually counted was a two-dimensional barcode that no voter, and no hand-counter, could verify by sight.
A paper trail is not the same as a voter-verifiable record. The artifact that is counted has to be the same artifact the voter can inspect.
The court, given the proximity to the election, declined to order a switch to hand-marked paper ballots. It weighed disruption against risk. That is a judgment call courts sometimes have to make. But the finding — that the record was not fully verifiable — did not go away because a court declined emergency relief.
The irreducible error in the gold standard
There is a further problem, and it cuts even deeper.
The CISA statement pointed to hand recounts and audits as the backstop. Georgia did exactly that. But a hand count is not error-free.
In Antrim County, Michigan, on November 4, 2020, the county published unofficial results that showed a result wildly inconsistent with the county's political character. The error was real — caused by a programming mistake when the system was reconfigured after a last-minute ballot change — and it was corrected. On December 17, a full hand audit tallied every presidential ballot by hand.
The hand count still differed from the machine tabulation by about a dozen votes out of roughly 15,700 cast.
Twelve votes. Not fraud. Not malice. Just the irreducible noise of human beings sorting paper under time pressure, making judgment calls about ambiguous marks, miscounting a stack and recounting it, adjudicating a crease.
Twelve votes in a county of 15,700 is about 0.08 percent. That sounds reassuring. But Antrim County was not a close race. In a jurisdiction where the margin is twelve votes — and there are always some — a hand count that is itself off by a dozen votes cannot definitively settle the question. A method that carries its own error cannot fully verify a result decided within that error band.
This is the deeper argument for stronger verification — not because hand counts are bad, but because even the best manual method has a floor below which it cannot resolve uncertainty. In a race decided by a handful of votes, what you need is not a recount: you need a system designed so the count was verifiable as it happened, with a cryptographic or independently auditable record that doesn't depend on human sorters getting every ballot right at 2 a.m.
The evidence from beyond America's borders
The CISA statement was specifically about the 2020 U.S. election. But the questions it raises — what makes an assurance meaningful, what makes a count verifiable — are not American questions.
In Windham, New Hampshire, a forensic audit ordered by the state legislature in 2021 traced a significant miscount to fold lines on absentee ballots. A folding machine had creased ballots across the vote targets; the optical scanners read a substantial fraction of those crease marks as filled ovals. About 44 percent of folds through vote targets were read as votes in November. No malware. No tampering. No fraud. Just a fold in the wrong place and dust on a lens. The error was only discovered because durable paper ballots existed and a hand count could recover voter intent.
The lesson from Windham is the same lesson as the CISA statement's logic, stated more plainly: the paper isn't the security feature. The ability to independently verify the paper against what the machines counted — routinely, rigorously, and by parties who aren't the officials being audited — is the security feature.
Go further. In 2009, Germany's Federal Constitutional Court struck down the use of electronic voting machines in the 2005 Bundestag election. The judgment held that electronic vote-counting is legitimate only when ordinary citizens, not just experts, can independently verify each essential step from ballot to result. Because the machines stored votes only in electronic memory with no independently verifiable record, they failed the public-verifiability standard. The court's phrase is worth carrying: the "public nature of elections" under the German Basic Law is not satisfied by a system whose correctness depends on trusting hidden software.
The Dutch government's election commission reached the same conclusion in 2007. Its report — Stemmen met vertrouwen, "Voting with Confidence" — stated plainly that "there are no secrets in the election process" and that questions must be "answerable and the answers checkable and verifiable." The Netherlands returned to paper ballots and manual counting. The regulation approving voting machines was withdrawn.
The CISA statement and the German Constitutional Court were, at bottom, making the same argument. The difference was that the German court was willing to draw the hard conclusion: if you cannot verify it, it is not verifiable, and 'trust us' is not a substitute.
What the statement cannot tell you
Here is what the CISA statement actually established, taken at its strongest:
As of November 12, 2020, the officials involved had found no evidence that any voting system deleted, lost, or changed votes, or was compromised. No evidence is genuinely meaningful. It is not nothing.
Here is what it could not establish:
- Whether every jurisdiction's paper records were sufficient for meaningful independent verification.
- Whether the QR-coded ballots in Georgia constituted a voter-verifiable record in the relevant sense.
- Whether errors below the detection threshold of hand counts occurred and affected close races.
- Whether the audits conducted were sized and designed to catch errors at the margin that would have mattered.
- Whether the processes could be independently reproduced by someone with no access to the officials, the vendors, or the counting infrastructure.
An assurance whose strength depends entirely on trusting the assessors is only as strong as your trust in the assessors. The CISA statement was written by sincere professionals trying to stabilize a volatile moment. There is every reason to believe it was honest. But sincerity is not the same as verifiability, and stability is not the same as proof.
The statement's own logic pointed toward a world in which the answer to "was this election accurate?" could be given not by officials but by anyone with access to the paper and the precinct-level data. That world exists, partially, in Colorado's risk-limiting audit framework. It exists in Georgia's hand count. It exists in Idaho's precinct-level downloadable results. But it does not exist uniformly, and where it doesn't exist, the CISA statement is resting its case on infrastructure that hasn't been fully built.
The question no authority can answer for you
Here is the test: could you — right now, today — independently verify the result of a close race in your jurisdiction?
Not by calling the Secretary of State. Not by reading a press release. But by downloading precinct-level machine-readable results, matching them to the certified totals, checking the audit log, and comparing the paper ballot count to the tabulator output.
In some places, yes. The EAC has urged officials to make results downloadable in common formats — .csv, .xml — with clear documentation of which ballot types each report includes. Some states already report at the precinct level. The infrastructure for real verifiability exists and is spreading.
In others, no. And in those places, the CISA statement's confidence is borrowed confidence — borrowed from the paper records and audits of jurisdictions that did the work, applied as a blanket assurance to a country where the work is still unfinished.
The most secure election in American history may well have been exactly that. But a claim of security you cannot independently check is a claim that depends on the authority of the person making it — and that is precisely the kind of authority that elections are supposed to make unnecessary.
The fix is not skepticism of the officials who wrote the statement. The fix is building systems where no one needs to trust the officials — because the record is public, machine-readable, cryptographically auditable, and available to anyone who wants to check.
That is verifiability. That is what the CISA statement was implicitly reaching for. And it is not yet fully here.
Read about how this gap shows up across different systems worldwide — and what closing it actually requires — at /atlas. For a two-minute version of the verifiability argument, see /simple. If you want to dig into specific documented cases, start at /gaps.
Sources
- Joint Statement, Election Infrastructure Government Coordinating Council & Sector Coordinating Council (Nov. 12, 2020) (CISA)
- Curling v. Raffensperger, No. 1:17-cv-2989-AT, Opinion and Order (N.D. Ga. Oct. 11, 2020) (Justia)
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia
- Colorado Secretary of State — A new kind of election audit: Colorado is first to complete it
- Michigan Department of State — Final numbers from Antrim County audit affirm accuracy of election results
- New Hampshire SB 43 Forensic Audit Report (July 2021), Hursti, Lindeman & Stark (via Internet Archive)
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Adviescommissie inrichting verkiezingsproces (Commissie Korthals Altes), 'Stemmen met vertrouwen', 27 September 2007 (Kiesraad)
- U.S. Election Assistance Commission — Why Do Election Results Change After Election Night?
- Colorado Secretary of State — Risk-Limiting Audit (RLA) FAQs