THE HONEST CASE ON VOTING SECURITY
What we are not claiming — and the path to earning it.
Why this page exists
Most proposals that involve digital voting begin by telling you the technology is ready. This one begins by telling you it is not.
Election security experts overwhelmingly agree that secure internet voting does not currently exist. That consensus is correct, and this movement says so on its own pages rather than waiting to be caught. A framework built on continuous, verified public participation cannot be more honest than its weakest claim, so this page states the weakest claim plainly: the infrastructure the Fourth Branch ultimately requires has not been built, by us or by anyone. What follows is not a promise that it works. It is the standard it must meet before it is allowed to exist, and the reasons every safeguard in that standard is there.
Promises are not mechanisms. This page sets the test any mechanism must pass.
Most proposals that involve digital voting begin by telling you the technology is ready. This one begins by telling you it is not.
Election security experts overwhelmingly agree that secure internet voting does not currently exist. That consensus is correct, and this movement says so on its own pages rather than waiting to be caught. A framework built on continuous, verified public participation cannot be more honest than its weakest claim, so this page states the weakest claim plainly: the infrastructure the Fourth Branch ultimately requires has not been built, by us or by anyone. What follows is not a promise that it works. It is the standard it must meet before it is allowed to exist, and the reasons every safeguard in that standard is there.
Promises are not mechanisms. This page sets the test any mechanism must pass.
What this page covers
This standard applies to every voting-related mechanism in the AP Framework: public-election access where legally permitted, the People's Vote infrastructure, verified public sentiment, and any identity-verification system used to support them. Where public elections are concerned, the standard is highest: no marked ballot may be returned over the internet unless and until independent experts can verify its secrecy, security, and auditability together under adversarial conditions. Nothing below blurs that line.
This standard applies to every voting-related mechanism in the AP Framework: public-election access where legally permitted, the People's Vote infrastructure, verified public sentiment, and any identity-verification system used to support them. Where public elections are concerned, the standard is highest: no marked ballot may be returned over the internet unless and until independent experts can verify its secrecy, security, and auditability together under adversarial conditions. Nothing below blurs that line.
The expert consensus, stated plainly
In 2018, the National Academies of Sciences, Engineering, and Medicine published Securing the Vote: Protecting American Democracy, the most authoritative single statement of expert consensus on U.S. election security. Its core findings: the technology to support secure internet voting does not exist at present, though it may in the future; all elections should use human-readable paper ballots; and marked ballots should not be returned over the internet, because no current technology can guarantee their secrecy, security, and verifiability at once.
In 2020, MIT researchers analyzing the first internet-voting app used in U.S. federal elections stated the same consensus in plainer words: running a secure election over the internet is not possible today.
We do not dispute either finding. We build on both. When this framework says the implementation is earned, not assumed, it is restating the National Academies' own position: not now, possibly later, only with robust guarantees.
One nuance in that consensus is worth keeping precise. The National Academies distinguishes the two halves of internet involvement: electronic delivery of blank ballots can be acceptable under current practice, while returning marked ballots electronically carries the unresolved security, secrecy, and coercion risks this page exists to address. Any proposal that conflates the two is hiding the hard problem inside the easy one.
In 2018, the National Academies of Sciences, Engineering, and Medicine published Securing the Vote: Protecting American Democracy, the most authoritative single statement of expert consensus on U.S. election security. Its core findings: the technology to support secure internet voting does not exist at present, though it may in the future; all elections should use human-readable paper ballots; and marked ballots should not be returned over the internet, because no current technology can guarantee their secrecy, security, and verifiability at once.
In 2020, MIT researchers analyzing the first internet-voting app used in U.S. federal elections stated the same consensus in plainer words: running a secure election over the internet is not possible today.
We do not dispute either finding. We build on both. When this framework says the implementation is earned, not assumed, it is restating the National Academies' own position: not now, possibly later, only with robust guarantees.
One nuance in that consensus is worth keeping precise. The National Academies distinguishes the two halves of internet involvement: electronic delivery of blank ballots can be acceptable under current practice, while returning marked ballots electronically carries the unresolved security, secrecy, and coercion risks this page exists to address. Any proposal that conflates the two is hiding the hard problem inside the easy one.
Why internet voting is not ready
Three problems remain unsolved, and honesty requires naming them rather than gesturing at them.
Client-side malware. A voter's phone or computer is not a controlled environment. Software the voter never sees can read or alter a ballot before it is transmitted, and no server-side security can detect what happened on the device.
Coercion outside the polling place. The private voting booth is a security feature, not a formality. A ballot cast at home can be cast under observation, pressure, or purchase, and the system cannot tell the difference.
The secrecy and verifiability tension. A voter should be able to verify their vote was counted as cast, and no one else should be able to link that vote to that voter. Satisfying both at once, at scale, under adversarial conditions, is an open research problem, not an engineering detail.
Any proposal that does not name these three problems is either unaware of them or hoping you are.
Three problems remain unsolved, and honesty requires naming them rather than gesturing at them.
Client-side malware. A voter's phone or computer is not a controlled environment. Software the voter never sees can read or alter a ballot before it is transmitted, and no server-side security can detect what happened on the device.
Coercion outside the polling place. The private voting booth is a security feature, not a formality. A ballot cast at home can be cast under observation, pressure, or purchase, and the system cannot tell the difference.
The secrecy and verifiability tension. A voter should be able to verify their vote was counted as cast, and no one else should be able to link that vote to that voter. Satisfying both at once, at scale, under adversarial conditions, is an open research problem, not an engineering detail.
Any proposal that does not name these three problems is either unaware of them or hoping you are.
What this framework requires instead
Because the technology is not ready, every voting-related mechanism in this framework is bound by six safeguards. They are requirements, not aspirations. A deployment that violates any one of them is a deployment this framework opposes, including its own.
1. Pilot before scale, and pilots are voluntary. Every component is tested locally first, expanded only on published evidence, and every result is published, including failures. Pilots begin with populations the current system already underserves: overseas military voters, citizens with disabilities, and rural voters. That does not mean applying a lower security standard to them. It means offering voluntary, paper-backed, independently audited access options in parallel with existing voting methods, never as a replacement until evidence justifies it. No underserved group is used as a lower-security test population, and no existing paper-based option is removed because a pilot exists. Switzerland's federally capped, deliberately slow e-voting trials, suspended in 2019 when public source-code review exposed flaws and resumed only under stricter rules, are the working model: security before speed, and the willingness to stop.
2. Paper backs every vote. No digital vote exists without a human-readable paper record. If digital and paper conflict, paper wins. Always. And "paper record" means something specific: the record must be voter-verifiable at the moment of casting, durable, independently auditable, and legally controlling in any recount or challenge. A printout no voter checks and no court can rely on is a prop, not a safeguard. This is the National Academies' central recommendation, and it is the one safeguard this framework will not trade for any convenience.
3. Open-source software only. All election code is publicly auditable. Security that depends on secrecy of the code is security no citizen can verify, and a democracy's counting machinery cannot ask to be trusted on faith. Switzerland's experience cuts both ways here and we cite both: public code review exposed real flaws, which is embarrassing for a vendor and exactly the point for a democracy.
4. Independent audits, before and after. Third-party security researchers, civil-rights organizations, and accessibility advocates review every component before deployment and after it. The researchers who found the flaws in the Voatz app were outsiders working without the vendor's cooperation. This framework's position is that they should never have to be.
5. Multi-modal authentication, with mandatory demographic-equity testing. Identity verification must use multiple factors. Facial recognition alone is prohibited. In 2019, the National Institute of Standards and Technology tested 189 face-recognition algorithms across more than 18 million images and found demographic differentials in most of them, with false-positive rates for some groups running ten to one hundred times higher than others. An authentication system that fails darker-skinned or older citizens at higher rates is a literacy test administered by an algorithm. So the rule is binding: a system that cannot demonstrate the absence of material disparate error rates across demographic groups, at the actual deployment threshold and verified by published independent testing, does not deploy. The bias audits are published either way.
6. Nonprofit, publicly governed infrastructure. No private company controls the identity or voting stack. The principle is the one this framework states everywhere: no profit motive belongs in the ownership of the right to vote. The rule that enforces it is precise: no private vendor may hold exclusive, proprietary, or unauditable control over any part of the infrastructure. Vendors may supply equipment and services under public contract; they may never own the system, obscure its code, or become the party a democracy has to trust. Where this site references existing commercial identity systems, they are named as proof-of-concept placeholders only. The lesson is already on the record: the MIT analysis of Voatz found privacy exposure tied to third-party identity verification, reinforcing why a production system must be publicly governed, privacy-preserving, and structurally independent of proprietary control. The production system must be nonprofit, open-source, and publicly governed.
Because the technology is not ready, every voting-related mechanism in this framework is bound by six safeguards. They are requirements, not aspirations. A deployment that violates any one of them is a deployment this framework opposes, including its own.
1. Pilot before scale, and pilots are voluntary. Every component is tested locally first, expanded only on published evidence, and every result is published, including failures. Pilots begin with populations the current system already underserves: overseas military voters, citizens with disabilities, and rural voters. That does not mean applying a lower security standard to them. It means offering voluntary, paper-backed, independently audited access options in parallel with existing voting methods, never as a replacement until evidence justifies it. No underserved group is used as a lower-security test population, and no existing paper-based option is removed because a pilot exists. Switzerland's federally capped, deliberately slow e-voting trials, suspended in 2019 when public source-code review exposed flaws and resumed only under stricter rules, are the working model: security before speed, and the willingness to stop.
2. Paper backs every vote. No digital vote exists without a human-readable paper record. If digital and paper conflict, paper wins. Always. And "paper record" means something specific: the record must be voter-verifiable at the moment of casting, durable, independently auditable, and legally controlling in any recount or challenge. A printout no voter checks and no court can rely on is a prop, not a safeguard. This is the National Academies' central recommendation, and it is the one safeguard this framework will not trade for any convenience.
3. Open-source software only. All election code is publicly auditable. Security that depends on secrecy of the code is security no citizen can verify, and a democracy's counting machinery cannot ask to be trusted on faith. Switzerland's experience cuts both ways here and we cite both: public code review exposed real flaws, which is embarrassing for a vendor and exactly the point for a democracy.
4. Independent audits, before and after. Third-party security researchers, civil-rights organizations, and accessibility advocates review every component before deployment and after it. The researchers who found the flaws in the Voatz app were outsiders working without the vendor's cooperation. This framework's position is that they should never have to be.
5. Multi-modal authentication, with mandatory demographic-equity testing. Identity verification must use multiple factors. Facial recognition alone is prohibited. In 2019, the National Institute of Standards and Technology tested 189 face-recognition algorithms across more than 18 million images and found demographic differentials in most of them, with false-positive rates for some groups running ten to one hundred times higher than others. An authentication system that fails darker-skinned or older citizens at higher rates is a literacy test administered by an algorithm. So the rule is binding: a system that cannot demonstrate the absence of material disparate error rates across demographic groups, at the actual deployment threshold and verified by published independent testing, does not deploy. The bias audits are published either way.
6. Nonprofit, publicly governed infrastructure. No private company controls the identity or voting stack. The principle is the one this framework states everywhere: no profit motive belongs in the ownership of the right to vote. The rule that enforces it is precise: no private vendor may hold exclusive, proprietary, or unauditable control over any part of the infrastructure. Vendors may supply equipment and services under public contract; they may never own the system, obscure its code, or become the party a democracy has to trust. Where this site references existing commercial identity systems, they are named as proof-of-concept placeholders only. The lesson is already on the record: the MIT analysis of Voatz found privacy exposure tied to third-party identity verification, reinforcing why a production system must be publicly governed, privacy-preserving, and structurally independent of proprietary control. The production system must be nonprofit, open-source, and publicly governed.
Who governs this, and who can stop it
A safeguard without an enforcer is a press release. Under this framework, the Election Security and Audit Board oversees the technical security, accessibility, and paper-trail integrity of any verified voting infrastructure, and holds the authority to authorize or halt pilot expansion based on evidence. Its members are nominated by independent technical and disability-rights organizations, not by politicians, and confirmed by the Citizen Confirmation Panel, a randomly selected citizen body. Appointment models, terms, funding, and removal standards are detailed on the governance page. The short version: the body with the power to expand this system is also the body with the power, and the obligation, to stop it.
A safeguard without an enforcer is a press release. Under this framework, the Election Security and Audit Board oversees the technical security, accessibility, and paper-trail integrity of any verified voting infrastructure, and holds the authority to authorize or halt pilot expansion based on evidence. Its members are nominated by independent technical and disability-rights organizations, not by politicians, and confirmed by the Citizen Confirmation Panel, a randomly selected citizen body. Appointment models, terms, funding, and removal standards are detailed on the governance page. The short version: the body with the power to expand this system is also the body with the power, and the obligation, to stop it.
Where writing ends and engineering begins
One more honest boundary. This page is a standard, not a system. Everything above can be written by a private citizen; none of it can be built by one. Building it requires professional cryptographers, election administrators, security engineers, accessibility experts, and the sustained adversarial review of the research community, working in public, over years. This movement's role is to define the standard the work must meet and to insist that the work be funded, published, and independently verified. How that research is funded is an open design question this framework has not yet answered; it is named here as open rather than dressed up to look more finished than it is. Anyone who tells you the hard part is the writing has not met the hard part.
One more honest boundary. This page is a standard, not a system. Everything above can be written by a private citizen; none of it can be built by one. Building it requires professional cryptographers, election administrators, security engineers, accessibility experts, and the sustained adversarial review of the research community, working in public, over years. This movement's role is to define the standard the work must meet and to insist that the work be funded, published, and independently verified. How that research is funded is an open design question this framework has not yet answered; it is named here as open rather than dressed up to look more finished than it is. Anyone who tells you the hard part is the writing has not met the hard part.
The commitment in writing
If secure, large-scale digital voting never becomes technically achievable to a standard independent experts can verify, that portion of this framework should not be implemented. The constitutional principle, that citizens have a right to be counted and answered, survives without any particular technology, and no technology that cannot earn public trust has a claim on it.
You will not find the word "unhackable" anywhere in the Party's current framework or positions, because no honest engineer would write it. Our own 2024 archive preserves earlier language we no longer use, kept unedited on The Record as proof the standard evolved, not as a claim we still stand behind. The burden of proof stays on us at every stage.
If secure, large-scale digital voting never becomes technically achievable to a standard independent experts can verify, that portion of this framework should not be implemented. The constitutional principle, that citizens have a right to be counted and answered, survives without any particular technology, and no technology that cannot earn public trust has a claim on it.
You will not find the word "unhackable" anywhere in the Party's current framework or positions, because no honest engineer would write it. Our own 2024 archive preserves earlier language we no longer use, kept unedited on The Record as proof the standard evolved, not as a claim we still stand behind. The burden of proof stays on us at every stage.
The strongest opposing case
The strongest case against everything above is not that our safeguards are too weak. It is that no safeguards are strong enough, and the answer is paper, permanently. Paper is auditable, coercion-resistant at the polling place, understandable by every citizen, and has no zero-day vulnerabilities. Every layer of technology added to voting is a layer of attack surface added to democracy.
We concede most of that argument, which is why paper backs every vote under this framework and wins every conflict. What the pure-paper position has to answer is who paper-only leaves behind: the deployed service member whose ballot arrives late or not at all, the citizen whose disability makes a polling place or a hand-marked ballot a barrier, the rural voter hours from the nearest drop-off. These are not hypothetical people; they are the populations the pilots begin with. The proposal is not paper versus digital. It is paper-backed access for citizens the paper-only system demonstrably underserves, expanded only as fast as evidence permits, and stopped the moment evidence says stop.
The strongest case against everything above is not that our safeguards are too weak. It is that no safeguards are strong enough, and the answer is paper, permanently. Paper is auditable, coercion-resistant at the polling place, understandable by every citizen, and has no zero-day vulnerabilities. Every layer of technology added to voting is a layer of attack surface added to democracy.
We concede most of that argument, which is why paper backs every vote under this framework and wins every conflict. What the pure-paper position has to answer is who paper-only leaves behind: the deployed service member whose ballot arrives late or not at all, the citizen whose disability makes a polling place or a hand-marked ballot a barrier, the rural voter hours from the nearest drop-off. These are not hypothetical people; they are the populations the pilots begin with. The proposal is not paper versus digital. It is paper-backed access for citizens the paper-only system demonstrably underserves, expanded only as fast as evidence permits, and stopped the moment evidence says stop.
How this connects to the rest of the framework
This page is the security posture behind the mechanisms described on the Framework (the Nine Amendments and the People's Vote infrastructure). The full precedent base, including Estonia, Switzerland, Brazil, Voatz, Aadhaar, and the NIST findings, with sources, lives on Sources & Evidence. The governance and funding of the Election Security and Audit Board are detailed on How It's Funded & Who Governs It. Our earlier, weaker security language is preserved unedited on The Record. The question of rights and auditability when no human is the decision-maker is carried by AI & Digital Governance, and the demographic-equity rule on this page is an application of the boundary set by Civil Rights.
This page is the security posture behind the mechanisms described on the Framework (the Nine Amendments and the People's Vote infrastructure). The full precedent base, including Estonia, Switzerland, Brazil, Voatz, Aadhaar, and the NIST findings, with sources, lives on Sources & Evidence. The governance and funding of the Election Security and Audit Board are detailed on How It's Funded & Who Governs It. Our earlier, weaker security language is preserved unedited on The Record. The question of rights and auditability when no human is the decision-maker is carried by AI & Digital Governance, and the demographic-equity rule on this page is an application of the boundary set by Civil Rights.
Sources
- National Academies of Sciences, Engineering, and Medicine, Securing the Vote: Protecting American Democracy(2018). https://nap.nationalacademies.org/catalog/25120/securing-the-vote-protecting-american-democracy
- Specter, Koppel, Weitzner, The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, USENIX Security 2020. https://www.usenix.org/conference/usenixsecurity20/presentation/specter
- MIT News, "MIT researchers identify security vulnerabilities in voting app" (Feb. 2020). https://news.mit.edu/2020/voting-voatz-app-hack-issues-0213
- NIST, Face Recognition Vendor Test Part 3: Demographic Effects, NISTIR 8280 (2019). https://www.nist.gov/publications/face-recognition-vendor-test-part-3-demographic-effects
- Swiss Federal Chancellery, e-voting overview (caps and "security before speed"). https://www.bk.admin.ch/bk/en/home/politische-rechte/e-voting.html
- OSCE/ODIHR, Estonia 2023 parliamentary elections final report. https://www.osce.org/odihr/elections/estonia/551179
Not left. Not right. Altruist.
Long live everyone’s freedom of voice.
Long live everyone’s freedom of voice.