RSS Amplifier

The Prob · Apr 12, 2026

The Three Ways to Trust an Election

0
Sign in to vote or save

Jeremy McKeown · The Prob

The Three Ways to Trust an Election
By Jeremy McKeown, Editor of CobbProb
April 2026

Most arguments about elections focus on machinery. They revolve around scanners, paper, software, certification, audits, and procurement. The discussion sounds technical, and often it is. But the technical vocabulary can obscure the real dispute. The deeper question is simpler. What kind of evidence is strong enough to make an election result trustworthy?

At a high level, confidence in election results takes one of three dominant forms. Real systems often combine these approaches, but each ultimately depends on one of these forms of evidence. A public can rely on what it can directly examine, as in hand-marked, hand-counted paper ballots. It can rely on a process designed to catch error after the fact, as in machine tabulation followed by risk-limiting audits. Or it can rely on systems that are proven through mathematics, as in cryptographic verification.

The first approach is older than the rest and easier to grasp. A voter marks a ballot. That ballot exists as a physical record. Human beings count it. It is slow. It takes effort. It is not immune to mistakes. But it has one quality the others cannot replicate. The central evidence does not live inside the counting system or within the institutions producing the result. Once a voter has verified a physical ballot, software cannot rewrite that artifact. It can be mishandled, lost, or miscounted. It cannot be silently altered by code. It is not perfect. It is a boundary.

“The core issue isn’t machines. It’s what kind of evidence you’re willing to accept.”

That boundary matters because election legitimacy has never depended on correctness alone. It has depended on whether correctness can be examined. The German Federal Constitutional Court made that point with unusual clarity in 2009 when it held that essential steps of an election must remain open to public examination without requiring specialized technical knowledge. The opinion was about electronic voting machines, but the principle extends beyond that case. A result may be accurate and still fail a public test if the public has no meaningful way to examine the basis for it.

The second approach dominates modern practice. Paper remains, but machines perform the initial count. After that, risk-limiting audits test whether the reported outcome is likely to be correct. This method does not resolve the trust problem. It manages it by increasing confidence that the reported outcome matches the underlying evidence. Risk-limiting audits establish a defined limit on the probability of missing a wrong outcome. It is a serious achievement, but it remains conditional. It depends on the integrity of the audit trail, on sound custody of ballots, and on the assumption that the records being examined correspond to actual voter intent.

“Risk-limiting audits improve confidence. They do not create the underlying evidence.”

The same limit appears in certification. Modern voting standards such as VVSG 2.0 address security, usability, accessibility, and auditability in system design. But certification can only show that a system met requirements under evaluation. It cannot prove what happened in a live election. Design assurance is not operational truth.

The third approach is the one gaining intellectual momentum. Here the promise is not procedure but proof. Systems such as ElectionGuard use encrypted ballots, cryptographic proofs, and end-to-end verifiability to show that a reported tally is mathematically consistent with the underlying records. Homomorphic techniques allow certain calculations to be performed without exposing the individual vote. In technical terms, this approach reduces reliance on any single person or office by embedding verifiability into the system itself. Notably, systems like ElectionGuard were already in development prior to the controversies of 2020.

This is where much of the current public debate becomes internally inconsistent. Many people have concluded that machine-based systems introduce risks they cannot verify on their own. From that premise, the logical conclusion is to return fully to hand-marked, hand-counted paper ballots. Yet most are unwilling to accept the practical limits of that approach at scale. The result is a middle position that rejects machines in principle but relies on them in practice. That tension exists because the third option remains poorly understood. If machines are used at all, the question is not whether they exist, but whether they are designed in a way that removes their ability to silently decide outcomes. Cryptographic verification represents the furthest development of that idea. It does not ask the public to trust machines. It attempts to make machines incapable of altering the result without detection.

“If machines are used at all, the question is not whether they exist, but whether they can silently decide outcomes.”

At this point, the form of evidence changes. In the first model, the evidence is a physical artifact. In the second, that artifact remains, but confidence is shaped by procedure and statistical testing. In the third, the evidence takes the form of proofs and protocols designed so that software cannot change the outcome without detection. The claim becomes stronger in one sense, and more distant in another. A result may be consistent with the system’s mathematics while being less accessible to direct public examination.

That tension reflects the concept of software independence, articulated by Ronald Rivest and John Wack. Their argument was that undetected software error should not be able to cause an undetectable change in an election outcome. That remains a useful idea in election security because it shifts attention from whether software exists to whether it can silently decide the result. But software independence does not resolve every civic concern. Detection is not the same as comprehension. The public may be told, truthfully, that a system can prove itself and still depend on specialists to interpret that proof. In stronger forms, such systems not only detect error, but allow the correct outcome to be recovered without re-running the election.

This is where many election debates lose clarity. The dispute is often framed as if the central issue were resistance to hacking. That matters, but it is not the whole issue. The harder question is what kind of evidence remains when doubt arrives. Doubt eventually arrives in every contested environment because races are close, administration is imperfect, institutions are distrusted, or the stakes are high enough that a losing side will examine every weakness it can find. At that point, claims about security are less useful than the character of the evidence itself.

Seen in that light, the three approaches are not interchangeable. They are different answers to the same civic problem. In the first, the evidence can be examined directly by any ordinary observer. In the second, confidence depends on procedures, including custody and audit processes, that extend beyond what individuals can verify on their own. In the third, the evidence takes the form of proofs that remove discretion from the outcome but require specialized expertise to fully evaluate. Each has strengths. Each imposes costs. Each asks the public to accept a different kind of dependence, particularly in how verification is tied to the institutions producing the result.

This framework is not an implementation plan. It does not specify what a jurisdiction should deploy next year, how budgets should be allocated, or how quickly systems should change. Those are operational questions, but they are downstream of a more basic decision. Before a system can be built or improved, there must be clarity about what kind of evidence is sufficient to justify the result.

That is why the usual question about elections can be misleading. The issue is not simply which method is most efficient, or most modern, or even most secure in the abstract. The issue is what kind of evidence the public is prepared to treat as sufficient, and whether it is willing to follow that choice to its logical conclusion. Physical artifacts that can be inspected by any ordinary observer. Audit processes that establish a strong likelihood that the declared winner is the real one. Or systems that are proven through mathematics, but whose proof must be interpreted through technical expertise.

“When doubt arrives - and it always does - what remains is not security claims, but evidence.”

The argument about election technology is rarely stated in these terms. It is usually broken into narrower disputes about standards, vendors, devices, and reforms. But underneath those disputes is a simpler decision. A public must decide whether legitimacy rests on what can be examined, what can be sampled, or what must be proven.

Disclaimer
This article is an opinion and educational analysis of election systems and verification methods. It is intended to clarify conceptual differences in how election outcomes can be validated and does not constitute legal advice, technical certification guidance, or an endorsement of any specific voting system, vendor, or policy.
While the discussion references real-world standards, technologies, and court decisions, it is not a comprehensive treatment of all factors involved in election administration. Readers should consult official sources, election authorities, and subject-matter experts when making decisions related to election policy or implementation.

No posts

Read the original on theprob.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.