eRightSoft All articles
Open Source Innovation

The Black Box Ballot: Why America's Voting Machines Resist Scrutiny — and How Open-Source Election Technology Could Change That

eRightSoft

In a functioning democracy, the act of counting votes should be among the most transparent operations a government performs. The ballot is, after all, the foundational instrument of popular sovereignty — the mechanism through which citizens exercise the authority that legitimizes every other function of the state. It is therefore remarkable, and more than a little troubling, that the technology used to record and tabulate those ballots in the United States is among the least transparent infrastructure in public life.

The majority of American elections are administered using voting systems built and maintained by a small number of private vendors. The source code running on these machines is treated as proprietary intellectual property. Independent security researchers cannot examine it without the vendor's permission — permission that is rarely granted and frequently conditioned on nondisclosure agreements that prevent researchers from publishing what they find. Election officials who want to understand how their own systems work must, in many cases, simply trust the vendor's word.

This arrangement is not a conspiracy. It is the predictable consequence of applying standard commercial software licensing practices to infrastructure that serves a fundamentally public purpose. But the consequences for democratic legitimacy are severe, and they are becoming impossible to ignore.

A Market Designed Against Accountability

The U.S. election technology market is extraordinarily concentrated. Three vendors — ES&S, Dominion Voting Systems, and Hart InterCivic — control an estimated 90 percent of the market for voting equipment. These companies sell or lease systems to counties and municipalities, provide maintenance contracts, and in many jurisdictions also manage the technical support that election officials depend on during the high-stakes hours of an election.

This concentration creates structural accountability problems that have nothing to do with any individual vendor's intentions. When a single company's systems are used across hundreds of jurisdictions in multiple states, a vulnerability in that company's software becomes a systemic national risk. When that company's source code is proprietary, the public has no independent mechanism to assess whether such a vulnerability exists.

The Voting System Testing and Certification Program, administered by the Election Assistance Commission (EAC), provides a federal review process for voting system hardware and software. But this process has significant limitations. Testing is conducted by accredited laboratories under contract — not by independent public researchers. Test results and technical documentation are often withheld from public view. And certification does not prevent vendors from deploying software updates between election cycles without full re-certification, a practice that has drawn criticism from security experts.

The result is a system in which the public is asked to trust election outcomes produced by technology it cannot examine, certified by a process it cannot fully observe, maintained by companies it did not choose.

What Open-Source Voting Would Actually Mean

The phrase "open-source voting" is sometimes misunderstood as a call to move elections online or to replace physical ballots with software-only systems. This mischaracterizes the actual proposals being advanced by election security researchers and civic technology advocates.

The most credible open-source election initiatives call for transparent, publicly auditable software running on standard hardware, combined with voter-verified paper audit trails (VVPATs) that allow election outcomes to be confirmed through physical ballot inspection. The goal is not to eliminate human oversight but to make the digital components of election administration as legible and verifiable as the paper components.

The VotingWorks project, a nonprofit organization based in the United States, has developed exactly this kind of system. Its flagship product, Arlo, is an open-source risk-limiting audit tool already in use in more than a dozen states. Its voting system software, VxSuite, is fully open-source, peer-reviewed by independent security researchers, and designed to run on commodity hardware rather than proprietary purpose-built machines. The entire codebase is publicly available on GitHub.

Colorado, which has been recognized as a national leader in election security, uses Arlo for its post-election audits. The state's combination of paper ballots, risk-limiting audits, and public transparency in audit methodology represents a model that election integrity advocates point to as proof that rigorous, verifiable elections are achievable without relying on proprietary systems.

The Researchers Knocking on Doors That Won't Open

The annual DEF CON Voting Village has, since 2017, brought together security researchers to examine publicly available voting equipment and identify vulnerabilities. The findings have been consistently alarming — and consistently disputed by vendors who argue that laboratory findings do not reflect real-world conditions.

This dispute illustrates the fundamental epistemological problem with proprietary election technology. When source code is not available for review, there is no shared evidentiary basis on which vendors and researchers can agree. The vendor says the system is secure. The researcher says it has vulnerabilities. Neither can fully demonstrate their claim to the public because the underlying code remains hidden.

Open-source software does not eliminate vulnerabilities — no software does. But it fundamentally changes the nature of security review. When code is public, the entire global community of security researchers can examine it. Vulnerabilities discovered by independent researchers can be disclosed, debated, and patched through a transparent process. The security argument for openness is not theoretical; it is the foundation of the most widely trusted cryptographic and security infrastructure on the internet.

Several prominent election security researchers — including those affiliated with the Cybersecurity and Infrastructure Security Agency (CISA) — have publicly endorsed the principle of open-source election software as a component of a comprehensive election security strategy. Their recommendations have not translated into policy, in part because the vendors whose products would be displaced have substantial lobbying presence and contractual relationships with the jurisdictions that would need to make the transition.

Political Obstacles and the Misinformation Dimension

Any honest account of barriers to open-source election adoption must grapple with the political environment in which election technology policy is made. The years since 2020 have seen a dramatic escalation in unfounded claims about election fraud, many of which have focused specifically on voting machine vendors. Dominion Voting Systems was the subject of defamatory claims so specific and so damaging that the company pursued — and won — a landmark defamation settlement against a major media organization.

This environment has created a perverse dynamic. Legitimate, technically grounded calls for greater election technology transparency are now routinely conflated, in public discourse, with bad-faith conspiracy theories that make precisely the opposite evidentiary demands. Election officials who might otherwise be sympathetic to open-source proposals are understandably wary of being associated with any narrative that questions the integrity of current systems.

Navigating this dynamic requires clarity about what open-source advocates are actually arguing. The case for transparent election technology is not a claim that current elections are fraudulent. It is a claim that democracy is better served by systems that can be verified than by systems that must be trusted — and that this principle applies regardless of who won the last election or who is expected to win the next one.

Building the Infrastructure Democracy Deserves

Several states have taken meaningful steps toward greater election technology transparency. California requires that voting system source code be made available to registered political parties for review. Michigan has expanded its post-election audit requirements. A small but growing number of jurisdictions have piloted or adopted open-source components in their election administration workflows.

But piecemeal progress is insufficient given the scale of the challenge. Federal investment in open-source election infrastructure — through the EAC, through CISA, or through dedicated congressional appropriations — could accelerate the development and deployment of publicly auditable voting systems in a way that no individual state or county can achieve alone.

The technical foundation for such systems already exists. VotingWorks and similar organizations have demonstrated that open, secure, paper-backed voting technology is not a future aspiration but a present reality. What remains is the institutional will to treat election infrastructure as public property rather than a commercial product — and to insist that the code counting America's votes be as open to scrutiny as the democratic principles those votes exist to uphold.

In a nation that regularly invokes transparency as a democratic value, the opacity of its own voting technology stands as a profound contradiction. Resolving that contradiction is not a partisan cause. It is a precondition for the kind of mutual trust that self-governance requires.

All articles

Related Articles

Captive by Design: How Proprietary Tech Traps Disabled Americans—and What Open Standards Can Do About It

Room by Room: Replace Your Surveillance Smart Home With Open-Source Automation That Puts You in Control

Taking Back the Feed: A Practical Guide to Open-Source Privacy Tools for Everyday Americans