The Build Journal
On the public ledger–reader ballots, each sealed by a hash. Not one of them can be read.
Research Supplement

The Build Journal

PriceOne voteCast it in section 6 and check it yourself.

The Glass Ballot Box

An election is not just a count. It is a claim that needs evidence.

Every election asks millions of people to accept something enormous: that their individual choices were turned, correctly, into one result. Most voters see only two moments, the vote they cast and the winner announced. Everything between is a sealed box of machines, software, memory cards, storage rooms and people.

When that box is trusted, it works. When trust breaks, facts alone rarely repair it, because the public is no longer asking who won. It is asking how anyone can know the system did not lie.

This paper looks at a different design, sometimes called a glass ballot box. The votes stay secret. The proof that they were counted correctly becomes public, so anyone can check it. One of the figures is a live public ledger you can vote on.

Continued in section 1

1The trust problem

If Democracy Runs on Trust, What Happens When Trust Runs Out?

An election is not just counting. It is evidence.

Every election asks the public to accept that millions of private choices became one correct outcome. Most of us never see the path in between. We see the input, our own vote, and the output, the result. The rest is a chain of procedures, machines, software, storage and people that voters have no way to inspect.

That is normally fine. People trust the officials, the observers and the rules. But once doubt spreads, more facts do not fully fix it, because the public is no longer only asking who won. It is asking how anyone can be sure the system did not get it wrong, or lie. Follow one ballot and you can see where that doubt gets in.

The booth

You make your choice. This is the only step you can see with your own eyes, and the only one you can personally vouch for.

The machine

A machine or a scanner records your vote. You trust that it captured what you meant. You cannot look inside.

Storage and transport

Records are written to memory cards or boxed as paper and moved. Each handover is a point where you depend on people and procedures you will never meet.

The tally

Software adds everything up. Unless it is audited, the public sees only the totals it prints.

The result

A winner is announced. In a black-box election, the evidence the public holds at this point is close to nothing: trust is doing all the work.

The glass version

Now run the same journey with evidence attached. Your ballot leaves the booth sealed, with a receipt code. The sealed ballot is published. Anyone can check that the published ballots add up to the result. Watch the evidence meter fill.

That is the core of the crisis. An election is not just a count. It is a public claim, and claims need evidence. The rest of this paper asks how much evidence an election can produce without ever revealing how any one person voted.

2Black boxes

Black Box Elections

“Trust me” is not a security model.

In most voting systems today, a voter cannot independently confirm three things: that their vote was recorded the way they meant it, that it was included in the count, and that the count matches the recorded votes.

Even when officials do everything right, there is a visibility gap. Nobody can personally follow their ballot, so the system leans on institutional trust, reputation and reassurance after the fact. Computer security stopped working that way a long time ago. Good security assumes that things will fail, and builds systems where failures can be detected and proved.

The cryptographer Ronald Rivest and his colleague John Wack put the idea in one sentence: a voting system should be software independent, meaning that no undetected bug or tampering in its software can produce an undetected change in the result.1 The statistician Philip Stark and the computer scientist David Wagner went further and called for evidence-based elections: an election should produce convincing evidence that it found the real winners, or say that it cannot.2

The question becomes whether elections can move from trust to verification. Try weighing it yourself.

Suppose a losing side disputes a result decided by 2.0 percentage points. With a black box, the only answer officials can give is “please trust us”. With paper records and an audit, they could check about 15,000 randomly chosen ballots and give the dispute a statistical answer.

Drag the margin. The audit size comes from the BRAVO method in section 8, at a 5% risk limit.

3The idea

The Glass Ballot Box

The path is visible. The voter stays anonymous.

A glass ballot box does not mean transparent votes. That would destroy the secret ballot, which democracies fought hard for. It means transparent proof. The goal is easy to state and hard to build: let voters and the public check that an election was counted correctly, without letting anyone learn how a particular person voted.

Systems built this way are called end-to-end verifiable. The election produces evidence that the tally is right, and each voter can check that their own ballot is in it.3 Cast a ballot below and look at what the public is shown.

Proofs are public. Choices stay private.

Pick an option and seal it. Then switch between what you know and what the public can see.

How it works: your choice is combined with a long random number and run through SHA-256, a one-way function. The public sees only the result, a commitment that cannot be reversed. Real systems use encryption so ballots can later be counted without being opened, as section 7 shows.

The idea has been studied for more than four decades, since David Chaum's 1981 work on untraceable communication, which introduced the mix network.4 It is no longer only theory. In November 2009 voters in Takoma Park, Maryland, elected their mayor and city council with Scantegrity II, the first time an end-to-end verifiable system with ballot privacy was used in a binding government election; 1,728 people voted.5

4The checks

The Three Proofs

What “verifiable” actually means.

Verifiable voting usually comes down to three checks. Cast as intended: the voter can confirm the system captured what they meant. Recorded as cast: the voter can confirm their ballot made it into the public record. Tallied as recorded: anyone can confirm the published ballots were counted correctly.

The last one is the real shift. Verification stops being private. It becomes public, and the result becomes something that can be checked independently by anyone, including people who distrust the officials. Run all three.

Run the audit

Each check answers a different doubt. Run them in any order.

The first check is the trickiest, because a voter cannot see inside the machine. The cryptographer Josh Benaloh proposed an elegant answer in 2006.6 After the machine seals your ballot, it asks whether you want to cast it or challenge it. If you challenge, the machine must open that sealed ballot and prove what it contained; that ballot is then spoiled, and you vote again. A machine cannot know in advance which ballots will be challenged, so if it cheats it risks being caught every time.

Catch the cheating machine

This machine quietly changes some votes. You decide which ballots to challenge. Then see how quickly random challenges corner a cheat.

Note: the machine here alters each ballot with the probability you set. The curve assumes each voter challenges independently.

If just 10% of voters challenge, a machine that alters 50 ballots gets away with it 0.52% of the time. Here c is the share of voters who challenge and n is the number of altered ballots.

Drag either number.

5The paradox

Receipts Without Vote-Selling

A receipt is useful, until it becomes a weapon.

The obvious idea is to give every voter a receipt so they can prove their vote was counted. It has a dangerous side effect. If the receipt shows who you voted for, then vote-buying becomes enforceable, coercion becomes easier and the secret ballot collapses. A boss, a gang or a family member can demand to see it.

So the receipt has to be designed with care. It should let you check that your ballot was included without letting you prove to anyone else how you voted. That is the paradox a glass ballot box sets out to solve: you can check the system, but you cannot sell your vote. Play the buyer.

Try to buy a vote

You are offering money for votes. Ask the voter for proof, under each kind of receipt.

Note: the property that blocks this is called receipt-freeness. Stronger designs also aim for coercion resistance, protecting voters even from someone standing beside them.

Real systems use several tricks to keep receipts private: codes printed in invisible ink that only reveal a random confirmation code, as in Scantegrity, or tracking codes linked to an encrypted ballot that a voter cannot decrypt alone, as in Microsoft's ElectionGuard.5,7 In every case the receipt proves inclusion, not content.

6The record

The Public Record

Where verification lives.

Verifiable designs publish a public record of sealed ballots and the mathematical proofs that go with them. Anyone can audit the tally from that record without learning how individuals voted. This is the glass part: you can see that the ballots exist, you can see they were processed correctly, and you can see that the result follows from the record. Elections move from “please trust us” to “here is the evidence”.

The record below is real. It runs on a small server built for this paper. Cast a ballot on the phone: your browser seals it, the server adds it to a hash chain, and you can then check, on your own device, that every ballot on the ledger is linked correctly and that yours is among them.

The reader ledger, live

Choose what an election you could trust should protect first. Your choice never leaves your device; only a sealed commitment does.

How it works: commitment = SHA-256(election, choice, a random 128-bit nonce). Each ledger entry's hash = SHA-256(previous hash, election, position, commitment, time), starting from “GENESIS”. This demonstration proves inclusion and integrity. It is not coercion-resistant: anyone you showed your saved nonce to could check your choice, which a real election must prevent.

The ledger is a hash chain, an idea that goes back to Stuart Haber and Scott Stornetta's 1991 method for time-stamping documents so nobody could backdate them.8 Each entry carries the fingerprint of the one before it. Change any past entry and every fingerprint after it stops matching. Try it.

Rewrite history, if you can

Edit any block. The fingerprints are recomputed with real SHA-256 as you type.

7The ledger question

Where Blockchain Fits, and Where It Doesn't

Immutability is not the same as correctness.

Blockchain keeps coming up in election debates because it is tamper-evident: once something is written, history is hard to rewrite. But elections need far more than a tamper-evident log. They need secure vote capture, secrecy, resistance to coercion, correct counting and auditability.

If a compromised device records the wrong vote, a blockchain will preserve that wrong record perfectly, forever. That is not a hypothetical. When researchers at MIT examined Voatz, a blockchain-based voting app used by some overseas voters in West Virginia's 2018 election, they found weaknesses in the phone app and servers that could have let attackers alter or expose votes before anything reached the chain.9 The clean way to put it: a ledger can be one way to host the public record, but verifiability is the actual security idea. Test the layers.

Which layer saves the election?

Switch the layers on and off, then cast a test vote for A.

If ballots are sealed, how can anyone count them? One answer is homomorphic encryption, used in systems such as Helios and ElectionGuard.7,10 With exponential ElGamal encryption, multiplying sealed ballots together produces a sealed total. Only the total is ever decrypted.11

Count votes without opening them

Six voters answer yes or no. Seal the ballots, multiply the ciphertexts, and decrypt only the total. The numbers are real, just small.

Note: a toy key with a 23-bit prime so the arithmetic is readable. Real elections use 2,048-bit or larger groups, add proofs that each ballot holds a 0 or a 1, and split the decryption key among several trustees.

The other classic answer is the mix network. Sealed ballots pass through a series of servers. Each one shuffles the batch and re-randomises every ballot so it looks completely different, then proves it did so honestly. After a few rounds nobody, including the servers, can link a ballot to the voter who cast it, but the ballots can be opened and counted.4 Try to keep your eye on yours.

Follow your ballot

Your ballot is highlighted. Send the batch through three mix servers and try to track it.

8The backbone

Paper and Risk-Limiting Audits

Cryptographic evidence is powerful. Paper evidence is grounding.

Much election security rests on a practical foundation: paper ballots a human can read, or a paper record the voter has checked, plus audits that can catch a wrong outcome. A risk-limiting audit manually checks a random sample of paper ballots. It is designed so that if the reported winner is wrong, the audit is very likely to say so. If the evidence is weak, the sample grows, up to a full hand count.12

The point is not paper against cryptography. The point is evidence that cannot be faked at scale. One widely used method, BRAVO, was published by Mark Lindeman, Philip Stark and Vincent Yates in 2012.14 It draws ballots one at a time and keeps a running score:

Here s is the winner's reported share of the two-way vote and \alpha is the risk limit, the largest chance the audit is allowed to confirm a wrong outcome. The authors found that across 255 US state presidential contests from 1992 to 2008, the median expected sample was just 307 ballots per state.14 Run one.

Audit an election

Set the margin and the risk limit, then draw ballots. Or make the reported result wrong and see if the audit notices.

Method: BRAVO ballot-polling audit for a two-candidate contest (Lindeman, Stark and Yates, 2012). Ballots are simulated from the true shares you set.

With a reported margin of 10.0 points and a risk limit of 5%, a BRAVO audit expects to check about 598 ballots if the result is right. Halve the margin and the work roughly quadruples.

Wald's approximation for the expected sample size: ln(1/α) divided by [s ln 2s + (1 − s) ln 2(1 − s)].

India runs the world's largest elections on electronic voting machines, first tried in 1982 and used in every constituency since 2004, with paper audit trails (VVPATs) added from 2013. In April 2024 its Supreme Court rejected petitions to count every VVPAT slip, keeping the check of five randomly chosen machines per assembly segment, while ordering symbol-loading units to be sealed and allowing losing candidates to request checks of the machines' burnt memory.15 The debate is exactly the one this paper describes: how much evidence is enough, and who gets to see it.

9Today

What Exists Today

Not just theory: an engineering direction.

Verifiable election designs have been studied for decades, and modern toolkits now make parts of them practical: publishing evidence, supporting voter checks, improving audits and strengthening transparency without giving up secrecy. Helios, released in 2008, made open-audit voting available on the web for low-coercion settings such as university and society elections.10 In November 2022 voters in Preston, Idaho, could choose to vote with ElectionGuard in a general election, a pilot run with Microsoft, Hart InterCivic, MITRE and Enhanced Voting.7

Online voting is a separate and harder question. Estonia has offered internet voting since 2005, and in its 2023 parliamentary election more than half of all votes, 51%, were cast online.16 Many security researchers remain wary of internet voting for high-stakes elections; a 2018 report from the US National Academies recommended paper ballots and risk-limiting audits and advised against internet voting until much stronger guarantees exist.17

None of this means the world has solved voting. It means there is a credible path from opaque systems to evidence-producing ones, and from disputes settled by trust to disputes settled by verification. Walk through how we got here.

From the secret ballot to public proof

Drag along the timeline, or press play.

10The way forward

Democracy Upgrades From Trust to Evidence

The goal is not flashier elections. It is elections that are harder to dispute dishonestly.

A healthy future looks something like this: paper records as an anchor of truth, audits that scale confidence with evidence, and cryptographic verification that lets anyone check the tally without exposing a single vote. Each layer covers the others' blind spots. Paper survives software failures. Audits turn paper into statistical confidence. Cryptographic proofs let every voter and every observer check the arithmetic.

The real test is what happens on the night a result is challenged. Pick a system and face the dispute.

The night the result is challenged

Choose a system, then answer each claim the losing side makes.

The result is a new standard for public trust, and it fits on one line.

You don't have to believe the system. You can verify it.

11Try it

The Working Prototype

A full election simulator built alongside the paper.

Alongside this paper I built a working prototype of the ideas in it: candidates, commitment-based ballots, an append-only hash chain stored in a real database, receipt look-up, chain verification, an election snapshot when polls close, and exportable audit proofs. It runs on Cloudflare Workers with a D1 database. You can open it, cast ballots, close the election and audit it yourself.

Open the prototype Glass Ballot Box: election simulator Cast, seal, verify and audit an election end to end.

Sources

  1. Rivest, R. L., & Wack, J. P. (2006). On the notion of “software independence” in voting systems. NIST TGDC; later published as Rivest, R. L. (2008). On the notion of software independence in voting systems. Philosophical Transactions of the Royal Society A, 366(1881), 3759–3767.
  2. Stark, P. B., & Wagner, D. A. (2012). Evidence-based elections. IEEE Security & Privacy, 10(5), 33–41.
  3. Benaloh, J., Rivest, R., Ryan, P. Y. A., Stark, P., Teague, V., & Vora, P. (2015). End-to-end verifiability. arXiv:1504.03778.
  4. Chaum, D. (1981). Untraceable electronic mail, return addresses, and digital pseudonyms. Communications of the ACM, 24(2), 84–90.
  5. Carback, R., Chaum, D., Clark, J., Conway, J., Essex, A., Herrnson, P. S., Mayberry, T., Popoveniuc, S., Rivest, R. L., Shen, E., Sherman, A. T., & Vora, P. L. (2010). Scantegrity II municipal election at Takoma Park: The first E2E binding governmental election with ballot privacy. Proceedings of the 19th USENIX Security Symposium.
  6. Benaloh, J. (2006). Simple verifiable elections. Proceedings of the USENIX/ACCURATE Electronic Voting Technology Workshop (EVT '06).
  7. ElectionGuard. (2022). Preston, Idaho, 2022: first use of ElectionGuard in a general election. electionguard.vote
  8. Haber, S., & Stornetta, W. S. (1991). How to time-stamp a digital document. Journal of Cryptology, 3(2), 99–111.
  9. Specter, M. A., Koppel, J., & Weitzner, D. (2020). The ballot is busted before the blockchain: A security analysis of Voatz, the first internet voting application used in U.S. federal elections. Proceedings of the 29th USENIX Security Symposium.
  10. Adida, B. (2008). Helios: Web-based open-audit voting. Proceedings of the 17th USENIX Security Symposium.
  11. ElGamal, T. (1985). A public key cryptosystem and a signature scheme based on discrete logarithms. IEEE Transactions on Information Theory, 31(4), 469–472; Cramer, R., Gennaro, R., & Schoenmakers, B. (1997). A secure and optimally efficient multi-authority election scheme. EUROCRYPT '97.
  12. Lindeman, M., & Stark, P. B. (2012). A gentle introduction to risk-limiting audits. IEEE Security & Privacy, 10(5), 42–49.
  13. Colorado Secretary of State. (2017, November 22). Colorado completes first risk-limiting audit ever [Press release].
  14. Lindeman, M., Stark, P. B., & Yates, V. S. (2012). BRAVO: Ballot-polling risk-limiting audits to verify outcomes. Proceedings of the Electronic Voting Technology Workshop / Workshop on Trustworthy Elections (EVT/WOTE '12).
  15. Supreme Court of India. (2024, April 26). Association for Democratic Reforms v. Election Commission of India, Writ Petition (Civil) No. 434 of 2023; Election Commission of India, EVM and VVPAT manual and FAQs.
  16. ERR News. (2023, March 5). Estonia sets new e-voting record at Riigikogu 2023 elections. news.err.ee
  17. National Academies of Sciences, Engineering, and Medicine. (2018). Securing the Vote: Protecting American Democracy. The National Academies Press. doi.org/10.17226/25120

Credits

Research this paper builds on

Josh Benaloh; Ronald Rivest and John Wack; Philip Stark and David Wagner; Mark Lindeman and Vincent Yates; David Chaum; Ben Adida; Taher ElGamal; Ronald Cramer, Rosario Gennaro and Berry Schoenmakers; Stuart Haber and W. Scott Stornetta; Michael Specter, James Koppel and Daniel Weitzner; the Scantegrity team; the ElectionGuard team; the National Academies committee on the future of voting.

The prototype

Built by the author on Cloudflare Workers, the Hono framework and a D1 database. The live ledger in section 6 talks to the same server.

Type and tools

Set in UnifrakturMaguntia, Noto Serif Display, Source Serif 4, Libre Franklin and IBM Plex Mono, under the SIL Open Font License. Mathematics by KaTeX. Hashing uses your browser's built-in Web Crypto. No trackers, no ads.

About the paper

Written in June 2025. It contains no generated images.

Cite this paper

Raj, A. (2025, June). The glass ballot box: Verifiable voting without giving up the secret ballot. The Build Journal Research Supplement, No. 2. https://abhnv.in/p2/
@article{raj2025glassballot,
  author  = {Raj, Abhinav},
  title   = {The Glass Ballot Box: Verifiable Voting Without Giving Up the Secret Ballot},
  journal = {The Build Journal Research Supplement},
  number  = {2},
  year    = {2025},
  month   = jun,
  url     = {https://abhnv.in/p2/}
}

More from the supplement