Why Certified Electronic Voting Is Impossible

Digital signatures compromise ballot secrecy by linking identity to choice, a flaw blockchain cannot fix.

English · Original discussion in Spanish · Published

Why Certified Electronic Voting Is Impossible
Why Certified Electronic Voting Does Not Exist

Certified electronic voting does not exist. Nor does it seem anyone is interested in making it happen. Some argue that the problem it solves—not leaving home on a Sunday—is trivial compared to the one it creates: a verifiable vote is, by design, a traceable vote. This would not be a system failure, but the system itself. Around this contradiction lies a years-long debate mixing cryptography, institutional distrust, and a strong belief that technology fixes politics.

What Proposing Certificate-Based Voting Actually Means

The starting premise seems reasonable. If a digital certificate works for filing taxes or identifying oneself to public administration, why not for voting? It would require only a computer, an electronic signature from Spain's national mint (Fábrica Nacional de Moneda y Timbre), or standard ID systems. One click, vote cast.

Variations build on this base. A blockchain network where results are visible in real time and immutable. Terminals with five buttons at polling stations, requiring just a DNI and a press. And the parallel with postal voting appears immediately: if you can vote days earlier at an office, what difference does it make to vote from your living room? The short answer is that the difference lies in the envelope, though not a paper one.

Why a Signed Vote Cannot Be Secret

Because an electronic signature does exactly the opposite of what a vote requires. It authenticates the signer, guarantees content integrity, and provides non-repudiation, meaning it records who signed what. The digital envelope is not an opaque box: it is a data structure with traceability. If the system knows that ballot came from your certificate, someone can reconstruct the path.

For many participants, there is no room for interpretation here: once authentication exists, anonymity is impossible, and no layer of encryption or good faith fixes that. You can disguise it, split it into two databases, or promise no one will cross-reference them. But the association exists at some point in the process, and whoever controls that point controls the vote.

Blockchain Secures the Count, Not Identity

Blockchain technology has fruta merit: it makes a count tamper-proof. What it does not do is verify that the voter is a real person and not a program firing votes using stolen census data. Record immutability does not solve voter authenticity, which is precisely the core of the problem.

There is also a second effect, less technical and more uncomfortable. Paper voting is controlled bottom-up: thousands of transparent urns, tables watched by people, minutes that can be checked. An electronic system concentrates control in a single point. Whoever gives the order changes everything. That asymmetry—distributed versus centralized—weighs more than any encryption.

Questions No Electronic System Answers

The most useful summary of the discussion is a checklist. Each item seems solvable separately; together, they outline the problem:

  • How do you guarantee no one votes twice?
  • How do you guarantee the vote is secret?
  • How do you guarantee only eligible voters participate?
  • How do you guarantee no one alters the emitted content?
  • How does the voter know their vote was cast and not deleted?
  • How do you audit the machines executing the process with guarantees?

The full breakdown, with eight questions, circulates in the debate and isn't dismissed with a headline. The most repeated answer to the last question is the usual one: trust the operator. And trust is exactly what an electoral system cannot demand.

Postal Voting, Digital Divide, and Convenience Arguments

Postal voting is used as evidence both for and against. For, because it proves non-presential suffrage already exists. Against, because, according to one participant, it requires putting a name and address on the envelope, so whoever opens it early can see what's inside. A digitally signed vote would be that same envelope, but with fewer steps and more logging.

The real cost of voting in person has also been quantified: five minutes each way, about ten at the polling station, plus waits, totaling nearly one hour. For those who would vote from the sofa, that hour is the argument. For those who don't know how to turn on a computer, that hour is the only way to participate, and the debate warns that any system eliminating it excludes part of the electorate without solving it with an instruction manual.

The Only Technical Solution Described

At least one scheme exists, attributed to the Pirate Party, aiming for the impossible: encrypting the receipt with the voter's private key and the vote with the administration's public key, so anyone can count and the voter can verify their vote was counted, without anyone—even the administration—knowing how each person voted. The idea is solid on paper.

The problem is not algorithmic, but one of guarantees. Tax returns can be audited without anonymity; the ballot box cannot. The tax system doesn't need secrecy; the vote does. That difference turns a solved problem into an open one that has persisted for decades, with no Nobel Prize in sight.

Given this landscape, electronic voting will likely continue in pilot versions, lab tests, and campaign promises, but not in an official booth with legal effects. The reason won't be lack of technology. It will be that no one has explained how to audit a system that simultaneously knows who you are and pretends not to.

Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication. Read the full discussion (200 replies).

More summaries

All summaries in English →

Back