It Doesn't Take a Thief: Optical-Scan Voting Systems Fail Even Without Adversaries
Abstract
Optical-scan voting systems and their supporting ecosystem of people, processes, and technology are fallible. While a substantial body of work examines adversarial threats to such systems, we have encountered jurisdictions where the possibility of tabulator error is not fully internalized. Stakeholders there often find hypothetical attacks unconvincing, but some are persuaded by real-world accounts of equipment and procedural failures. This paper introduces a taxonomy of non-adversarial failure modes organized into intuitive categories: recording votes on paper, reading votes from the paper, combining votes as read into a reported outcome, and testing and verifying, all illustrated with documented incidents. We map common verification mechanisms against this taxonomy, identifying gaps that no paper-based audit can detect or correct, most notably failures that compromise the trustworthiness of the paper trail, such as giving voters the wrong ballot style (omitting contests they are eligible for, or including ones they are not), using ballot-marking devices to record votes, or failing to keep voted ballots secure and organized.
Cite
@article{arxiv.2607.27101,
title = {It Doesn't Take a Thief: Optical-Scan Voting Systems Fail Even Without Adversaries},
author = {Aleksander Essex and Philip B. Stark},
journal= {arXiv preprint arXiv:2607.27101},
year = {2026}
}
Comments
to appear in Proceedings of E-Vote-ID 2026, LNCS, Springer, Cham