The rule, exactly. Before an election each citizen chooses: to vote — or to take a payment and not vote in that election. The payment is a percentage of the median income, set by referendum; there is no fixed sum. One ballot is one vote, with no multiplier in the count; the vote is amplified only in that each ballot's share grows as others step out. The budget pays under law; a candidate never pays. Only a referendum of all citizens — simple majority, no quorum — introduces, changes or repeals the rule.
The protocol has been introduced nowhere and no pilot has been run: shares, turnout and outcome figures in the chapters are estimates, and the protocol promises nobody an election victory. If a chapter says otherwise, Exact Answers and the Charter are correct. For a candidate: ten questions and ten steps. For a citizen, a mayor, a finance officer, a donor, a journalist, a scholar, a lawyer: answers by role. Everything in force in one file: llms-full.txt.
Three Channels and a Parallel Count: Money, an Open Verifiable Vote, a Secret Ballot¶
Chapter: 08 — Implementation File: 08_048i · v1 · 20 September 2026 (the architect's proposal in response to 048h; verified against primary sources) Source: the architect's proposal: "I offer the voter three choices — take the money, vote openly by phone and verifiably, or vote the old way; this hinders nobody but makes elections far more verifiable. I have a vote token in my phone, and together with all my supporters I want to check on an external server how many of us there are in total; this is possible if they all re-submit an anonymous token to my candidate's server. Parallel control is entirely possible." Precedent: the Golos platform, Belarus, August 2020. Cryptographic basis: Chaum's blind signatures. Supplements 048f (double entry) and 048h (secrecy, verifiability, the price of coercion).
How to read this chapter (note of 02.10.2026). The text contains wording that is easy to misread: "a x2 vote", "x3", "the weight of a vote" are the arithmetic of a share, not a multiplier: every ballot counts as one; the efficiency bonus has been removed. The exact-answers sheet 1d and the charter 048m are in force.
1. The construction¶
Before an election the citizen has not two but three paths:
| Channel | What happens | What verifies it |
|---|---|---|
| B — take the money | Exit for the cycle, dividend into the account | Bank statement; the budget identity (048f) |
| A-open | A vote by phone; the voter receives a token confirming his choice | The token; a parallel count by supporters (§2) |
| A-secret | A paper ballot in the booth, as now | Nothing beyond today's: observers, protocols |
The key property: nobody loses anything. Whoever needs secrecy votes as now; the objection "secrecy is not a relic" (048h.4) does not touch this construction, because it does not abolish secrecy but adds a voluntary alternative beside it.
2. A parallel count by supporters¶
A voter who chose the open channel voluntarily hands his token to the candidate's server. The server sums. The result is not the full outcome but a lower bound: "at this polling station no fewer than N votes were cast for our candidate". If the official protocol shows fewer than N — falsification is proven by arithmetic, without experts, statistics or observers. This is a check in the spirit of the German court's requirement (048h.1), better than any cryptography: anyone can understand "more of us showed ourselves than you counted".
A precedent exists. In Belarus in August 2020 the Golos platform accepted ballot photographs through chat bots: more than 500 thousand photographs were received, the data covered about 23 % of polling stations, and at almost 300 stations the official protocols were below the number of ballots submitted — that is, the forgery was proven by the lower bound. The final report was published on 18 August 2020 together with the Zubr platform and the Honest People initiative. This is exactly the architect's scheme, assembled on the fly and without tokens.
3. The exit poll: the third channel already exists¶
The architect's argument: "if elections are secret, why then do exit polls exist? They are parallel elections, and almost everyone answers in them." An exit poll is a functioning, lawful and familiar precedent of a voluntary parallel count alongside the secret ballot. Checking against the data refines three things.
How many answer. In the US, in Edison Research exit polls roughly 40–50 % of those approached agree to take part; in 2004 — 53 %, earlier it was about 60 %. Not "almost everyone", but almost half — and with no benefit to themselves.
How they answer. Formally in confidence: the questionnaire is self-completed and dropped into a box. The architect's correction: "everyone sees the person, and psychologically it is NOT anonymous for him — and still he is not afraid". True, and it strengthens the argument: the poll is conducted face to face, at the exit of the polling station, in view of the neighbours; a person stops, takes a tablet or a form and tells a stranger what the law orders to be kept secret. He gains nothing from it. If fear of disclosure were widespread, the share agreeing would tend to zero, yet it has held at about half for decades. The construction of §2 is gentler than an exit poll: the token is actually anonymous, not merely on paper.
What it can and cannot do. Ukraine, the 2004 runoff: the exit poll showed 54 to 43 for Yushchenko, the official result 49.46 to 46.61 for Yanukovych; the discrepancy set off the protest, and the Supreme Court annulled the round's results. The exit poll worked as a detector although it had no legal force. Its weakness is single and systemic: it is an estimate from a sample, and uneven refusal breaks it. In 2004 the American exit polls overstated the margin for Kerry by 6.5 points because his voters answered more readily (by the organisers' own calculation, 56 % against 50 %); in 2020 the same recurred with Trump's supporters. A parallel count by tokens is free of that disease: it estimates nothing, it gives a lower bound, and a lower bound holds under any skew in who responded. Where an exit poll argues about the sample, a token presents arithmetic.
The reverse is telling too: exit polls are banned where a parallel count is feared — in Singapore for the whole election period.
Two corrections to the external model's conclusions. First: refusing to answer does not imply the person would have taken the money. Everyone an exit poll approaches has already come to vote, that is, by revealed behaviour they are group A; refusal correlates not with apathy but with distrust of the pollsters and with partisanship. Second: that half answer does not imply the rest need no secrecy — quite the opposite, the other half decline even anonymous disclosure. Hence a useful guide for a pilot: the share of the open channel among those who stay is of the order of half, and the secret channel is mandatory.
4. Why a token is better than a photograph¶
A photograph can be forged and can be devalued: photographed, then spoiled the ballot and took a new one. So a photo is weak proof in both directions. A token issued by the electoral system cannot be forged, but then two properties are needed: the candidate's server must be unable to inflate its own count, and the token must not lead to a person. Both come from a blind signature (Chaum): the system signs the token without seeing it, one per voter; the token presented later verifies as genuine but is not linked to whom it was issued. One token — one vote, without a name.
The boundary: if the falsifier is the electoral system itself, it may refuse to issue tokens. Then the Golos variant remains — photographs, weaker but workable. A refusal to issue tokens when the open channel is permitted is already a signal.
The photograph after AI. The architect added an argument that did not yet exist in 2020: "better that after the photo any AI draws in that place whatever the authorities need; and proving the photo is fake is very hard if the prompt is copied and executed exactly." Right: a picture of a clean ballot in which a generative model puts a mark in the required box is indistinguishable from a real one for whoever receives it — and the recipient is not an expert but a department head or a vote buyers' foreman, who himself needs a report rather than the truth. The consequence is wider than the Russian case (056d.7b): a photograph of a ballot has ceased to be proof of a vote, and control rests on it both in coercion and in vote buying. The buyer and the boss are left either to take a person's word or to escort him to the ballot box, which is costly and conspicuous. The secrecy of the ballot, which the camera phone had been eroding for twenty years, is partly restored by the same phone.
The reverse side, and it bears on this section directly: the photograph as evidence against falsification is devalued too. The "Golos" scheme (§2) worked because half a million pictures were hard to declare fakes; today that objection would be the first to be raised, and there is nothing to rebut it with. So the section's conclusion becomes harsher: the photograph is no longer a fallback for when tokens are not issued but next to nothing; a parallel count needs a sign that cannot be generated — the signature of the electoral system, that is, a token. 🟡
The architect's objection to the "reverse side": "but here the incentive and the malice differ: why would a person, at risk to himself, supply a fake photo?" For the individual the objection is right, and the symmetry the assistant drew is incomplete. A fake goes to a boss from someone who gains by it and risks nothing; there is no reason to send a fake to a parallel-count platform — a person takes a risk so that his real vote is counted, not for the sake of a picture. Honest senders there are the overwhelming majority. The vulnerability lies elsewhere — not with the sender but with the collector and his adversary. A losing candidate will be accused of having generated the half-million pictures himself: in 2020 that was technically impossible, today one operator does it in an evening. And the authorities can themselves flood the platform with fakes, then display them and devalue everything collected. So the conclusion is refined: the weight is carried not by the picture but by the number of different real people behind the pictures. "Golos" even then tied each submission to a phone number, and it is this, not the photographs, that would remain as proof today: half a million live numbers cannot be generated. The photograph turns into an attachment to a person's statement; a token remains better because it gives the same without disclosing the number. 🟡
5. How this adds up with the protocol¶
Double entry closes the B share, tokens close the A-open share. Only A-secret stays in the dark. The field for manipulation is already reduced after the protocol (048h.2); the third channel reduces it once more, and now it is measurable: the share of secret ballots is the ceiling of what can be painted, and the painting must not drop below the lower bounds presented for each candidate.
Coercion. The open channel gives a boss what he wanted: proof. But the comparison must be made with the system in force (048h.6): photographing a ballot is lawful in 25 US states and unlawful in 13, and technically possible everywhere. Under the protocol the direct attack "vote openly for my man" costs the instigator D plus a risk premium, and the coerced person has the exit into B (048h.5). That is, the main protection is not secrecy but the floor price of a vote.
5b. The arithmetic of the ceiling: tokens plus the register of those who took the sum¶
Amendment of 30.09.2026 (048k §3). The term of the late payment is not thirty days but the whole cycle. The architect's decision: the person who chose nothing "is our controller, and his money waits for him until the next election". By coming for it at any moment he checks whether anyone voted on his record. The 20–30 % discount stays.
The architect's summing-up: "votes with a token become verifiable — that is the most important thing; and if control of those who took the money is added, the amount of manipulation falls sharply, mathematically." This can be written as one formula and worked through on an example.
Any forgery of the result is made out of records that nobody but the commission can check. After the protocol there are two kinds of such records: secret ballots and "empty places" — people who are on the roll, did not take the sum and did not come to vote. Everything else is checked by the person himself: whoever took the sum sees the payment, whoever voted openly holds a token.
The ceiling on forgery = (secret ballots + those who neither took the sum nor turned up) / all votes cast.
Hence a rule of control which the architect stated separately (29.09.2026): "those who do nothing are a glaring risk zone; it is such an illogical choice that this is exactly where all the machinations can be." After the protocol, staying away and taking nothing is a choice worse than both buttons at once (001c §3), so the "empty places" are not a norm but an anomaly, and they must be checked first: by the late payment, by reconciling the remainder, and by comparing the share of "did nothing" with neighbouring precincts and past cycles.
An example with a hundred people on the roll (the shares are notional):
| Today | After the protocol | |
|---|---|---|
| Took the sum — checked by every recipient and the treasury | — | 55 |
| Voted openly, with a token — checked by the voter himself and his candidate's counters | — | 30 |
| Voted secretly | 50 | 10 |
| On the roll but took no part at all — the reserve for stuffing | 50 | 5 |
| Records that can be forged without their owner noticing | 100 of 100 | 15 of 100 |
| The ceiling on forgery as a share of votes cast | not bounded by arithmetic; in practice 10–15 points (013d.6c) | in theory 15 of 45 (forty cast and five stuffed), that is, about a third, if the entire secret channel is forged |
The last row requires an honest reading: with ten secret to thirty open, the theoretical ceiling is higher than today's practical one. But it is a ceiling of quite a different kind. Today 10–15 points are added without trace. After the protocol, forging the secret channel leaves a trace by itself: the same station has open votes with a known distribution, and if the secret ballots diverge sharply from them, that is visible with no observer at all; besides, each candidate knows his lower bound from tokens, and a total below it is impossible. The practical ceiling is a few points, and the smaller the secret channel's share, the lower it is. With five secret, thirty-five open and two "empty places" per hundred on the roll, the theoretical ceiling is about a sixth of the votes and the practical one single points.
The target configuration. The architect named the state he regards as the ideal: "10 % or fewer vote secretly, 40–50 % exit the election; with that split the accuracy of elections will be at its maximum and differ sharply from today's variants." By the formula above, with three "empty places" per hundred on the roll:
| Exit | Secret among those voting | Records on the roll that the person himself checks | Votes confirmed by a token | Theoretical ceiling on forgery |
|---|---|---|---|---|
| 40 % | 10 % | 91 of 100 | 90 % | about 15 % |
| 40 % | 5 % | 94 of 100 | 95 % | about 10 % |
| 50 % | 10 % | 92 of 100 | 90 % | about 15 % |
| 50 % | 5 % | 95 of 100 | 95 % | about 11 % |
The comparison with today lies not in the "ceiling" column — in theory it is of the same order as today's practical 10–15 points — but in the other two. Today the number of records a person checks himself is nought out of a hundred; in the target configuration it is over ninety. And today 10–15 points are added without trace, whereas here the whole ceiling is concentrated in the secret channel, whose size is published and whose distribution is compared with the open votes at the same station: to use the ceiling in full one would have to draw the secret ballots in a way nobody voted openly. The practical ceiling in this configuration is single points. An exit share of 40–50 % coincides with the second phase of the forecast in 015b.6; in the first phase exit is expected to be higher, and verifiability only grows from that — whoever took the sum is always verifiable. What the share of the secret channel turns out to be is not a parameter but a result (§6b): ten per cent and less will come about where people have nothing to fear.
The practical ceiling: how much can be forged unnoticed. The architect corrected the reading of the table: "a theoretical ceiling on forgery of 15 % means they came to vote; and how much can be stuffed unnoticed into such a small volume? The field for manipulation narrows sharply in percentage terms, while the risk of the stuffing failing rises sharply." The correction is right, and the assistant had mixed two different things in one figure.
Secret ballots are real votes of real people who came and signed the roll. One cannot add to them: the number of ballots in the secret channel runs up against the number of signatures. They can only be substituted — real ones taken out and one's own put in — and that is an order of magnitude harder than stuffing: it needs access to ballots already cast, and the real ones have to go somewhere. Adding is possible only from the "empty places" — those three in a hundred who neither took the sum nor turned up. So the resource for stuffing shrinks from half the roll to a few per cent, and the rest of the "ceiling" requires substitution.
And in a small volume everything shows. A count for a polling station of a thousand people: 450 took the sum, 30 took no part, 520 voted, of whom 52 secretly and 468 openly. The open votes give a known distribution; the secret ones may differ from it by chance — with 52 ballots, by roughly seven points. To stay within two such deviations one can substitute no more than seven ballots or stuff no more than sixteen: each of these shifts a candidate's result at the station by roughly one and a half points. With five per cent secret it is about one point. Anything beyond that departs from the distribution so far that it is visible with no observer and triggers a repeat at the station.
| Today | The target configuration | |
|---|---|---|
| The resource for stuffing | 40–50 % of the roll — everyone who did not turn up | about 3 % of the roll |
| What can be done with the rest | the same thing: add | only substitute real ballots |
| The shift that goes unnoticed at a station | 10–15 points (013d.6c) | 1–3 points |
| What follows detection | usually nothing | a repeat at the station by a rule written in advance |
The field narrows by roughly an order of magnitude, while the price of failure rises from "nothing" to "a re-vote and a case". A caveat to the calculation: it assumes that those voting secretly are distributed roughly like those voting openly. That may not be so — the secret channel may more often be chosen by supporters of someone it is dangerous to back openly — and then the honest divergence is larger and the rule's threshold must allow for it; the comparison should be made not with the open votes of the same station but with the divergence at neighbouring stations and in past cycles.
Closing the "empty places" too. The architect proposed what to do with the last resource for stuffing: "technically one can go and survey these 3 % or check with them somehow. Or offer them the dividend after the election — they did not turn up anyway." The second variant is stronger than it looks. Today a person in whose name a ballot was stuffed does not know it and cannot find out. If someone who neither took the sum nor voted is allowed to claim it after the election, every stuffed ballot acquires a witness with a personal interest: he comes for the money, and the system replies "you voted". The forgery is exposed not by an observer or a statistician but by the person himself, and he is owed a sum for it. Stuffing in the name of an "empty place" becomes as dangerous as in the name of someone who took the money: a conflict of two records arises in both cases, only a little later.
Two conditions so that the device does not break the rest. First: the late payment must be noticeably smaller than the ordinary one — say, half. Otherwise it pays everyone to wait: not to choose in advance, to watch the campaign and either vote or collect the sum later; then the number of refusals before polling day, on which the detection of vote buying rests (019d.4b), disappears, and the budget identity drifts (048f.3). Half is enough to make a person come and not enough to make waiting better than choosing in time. Second: the dispute "I did not vote — yet there is a signature on the roll" is settled by comparing the signature and the document, and a false statement made for the sake of a payment is punishable like any false statement; for the open channel there is no dispute at all — there is a token.
The architect clarified the purpose of the device: "voting is no longer possible, only collecting the money; and this is not for the payment but for the fear of falsification — nobody knows who will come and who will not." This is more precise than what is written above, and it changes the count. The device works not through the number who come but through uncertainty: whoever stuffs ballots must guess in advance, for every name, whether that person will later come for the sum, and one mistake is enough — there is a forgery with a living victim and his statement. If only one in ten of the "empty places" comes for the late sum, stuffing sixteen ballots (the practical ceiling for a station of a thousand people, see above) is exposed with a probability of about 80 %; if one in five — about 97 %; even at one in twenty — more than half. Today that probability is zero. Hence the answer on size: since the aim is fear and not payment, the sum can be small, and it costs the state almost nothing — few come, yet it acts on everyone.
The first condition nevertheless stands, and the assistant does not withdraw it. After the election one indeed cannot vote, but before polling day a person is free not to choose: to watch the campaign through, decide on the day whether to go, and if he did not go — collect the sum later. With a late payment equal to the ordinary one such waiting costs nothing, and nobody has any reason to choose the sum in advance. A reduced late sum removes this without harming the fear: the probability of exposure depends on whether anyone comes at all, not on how much he is paid. 🟡
The architect objected to this too: "sure, he won't come for his wages — the weather, laziness, the election is more interesting to him. People won't come for money? But fine, let it be a 20–30 % penalty." In substance he is right, and the assistant overrated the threat. A person who needs the money takes it at once rather than keeping a choice open for the sake of the campaign: that is how people behave with any payment, and the whole exit forecast is built on exactly this (015b.6). The only one likely to wait is someone who meant to vote anyway and never thought of taking the sum — and he does not affect the refusal gauge. So "half" in the first condition is over-insurance; a discount of 20–30 % is enough: it closes the residual case and leaves the late sum large enough for people to come for it. The exact size is a parameter for the pilot. 🟡
The first variant — "go and check" — is needed too, but for something else. Three per cent is an assumption for a clean roll. Where rolls have not been reconciled for a long time there are more "empty places": they list people who have left and people who have died, and this is the oldest resource for stuffing. A citizen who has left will take the sum if he is entitled to it and will thereby turn from an "empty place" into a verifiable record; a dead person will come for nothing. So after the very first cycle the remainder for whom nobody came either before the election or after it is a ready-made list for reconciliation: not suspects but records that most likely no longer exist. The protocol cleans voter rolls as a by-product — by paying every living person to check in. 🟡
Why rolls are not reconciled. The architect observed that the difficulty here is imaginary: "someone who has left can be found today by phone or through relatives; with the dead it is simpler still. So it is odd that the rolls were not reconciled. It suits those in power." Technically he is right: death is registered by the state itself, and matching two of its own registers is a matter of one query; the whole street knows who has left. In Moldova the State Register of Voters lists about 3.3 million people against 2.4 million residents in the 2024 census — children included; the gap is explained by those who have left (about 292 thousand with no registered domicile) and residents of the left bank of the Dniester (more than 268 thousand), while observers note from election to election that dead and inactive records remain on the lists. Since reconciliation is cheap and yet has not been completed for decades, the matter is not difficulty but interest: whoever keeps the list and counts the votes has no reason to remove records that can be signed for. The protocol reverses this interest: money now stands behind every record, and a surplus record becomes not a resource but evidence — either a living person comes for it or nobody does, and both are visible. And, as the architect reminded, the yardstick is the same as everywhere in this section: "it all works as it is today, and we are only improving it" — elections with dirty rolls are today recognised as valid, and any cleaning, even incomplete, is a step from that point, not from an ideal register. 🟡
What these figures mean. The architect's reaction: "this is some kind of horror: nobody knows who governs a whole country; with such an approach the level of governance is no surprise." The assistant adds precision so that the argument is not stronger than the facts. Most of the gap is not forgery: these are living citizens with the right to vote who have left or live on the left bank, and their records cannot be taken away. The horror lies elsewhere. Adults physically present in the country number about 1.9 million (an estimate from the census), records — 3.3 million; about 1.6 million voted in the 2025 parliamentary election. So more than a million records belong to people whom nobody expects at the station and whose absence nobody will notice — and today nobody, an honest commission included, can tell a living emigrant among them from a dead person. This is not proof of stuffing; it is the size of the field on which stuffing is possible without witnesses; with outcomes decided by tens of thousands of votes, the field is tens of times larger than the margin. The protocol does not abolish the field — those who left remain citizens — it marks it out: behind every record there is either a vote, or the sum, or silence, and the silence is counted station by station. 🟡
The second interest — the treasury. The architect carried the thought through: "but they can collect the money remotely, and if they did not — then something is not clean here. Those who have left and are no longer citizens must also be accounted for lawfully, or excluded from voting on some lawful terms; that is exactly what will take elections and record-keeping to a new level. The state will not want to pay money to all and sundry, and after the protocol the records will be one hundred per cent." There are two new arguments here, and both are right. First: coming to a polling station is costly for someone who has left, while collecting the sum remotely is not; so a record's silence stops being normal and becomes a signal. A living person who is owed money and answered neither for a vote nor for the sum is a rarity; a station with many such records singles itself out. The second argument is stronger: a clean roll acquires an owner inside the state itself. Today a surplus record costs nobody anything, and the finance ministry has no business with the voter register. When a payment stands behind every record, a dirty register becomes an expenditure line, and the treasury begins to do what it does with pensions: demand confirmation, match against deaths and renunciations of citizenship. Which of those who left are entitled to the sum, and on what terms, is decided by the country's law, not the protocol; but it will have to be decided explicitly, and that in itself is a step forward from today's silence.
The assistant's caveat on "one hundred per cent". Money pulls the records both ways: a record that is paid for becomes prey — people will try to collect the sum for a dead or departed relative just as others' pensions are collected today. So remote payment requires the same identification as the open voting channel, and confirmation that the person is alive. The comparison still favours the protocol: pension systems cope with this task with losses of fractions of a per cent, because the payer watches over it; the voter register does not cope, because nobody watches. The realistic target is the accuracy of pension records, not one hundred per cent. 🟡
The architect replied to the caveat: "even if money is collected for the dead, that is good: the payment is not fatal for the budget, and stuffing a ballot is ruled out completely." The assistant agrees, and this is the best formulation of the whole device. A record for which the sum has been taken is closed to stuffing as securely as the record of someone who exited honestly: any ballot in its name produces a conflict of two records. So a fraudster who collected money for a dead uncle does, without wishing to, an observer's work. The protocol changes the kind of crime: instead of theft of power — petty theft of money. The first today leaves no trace, has no victim and is almost never punished; the second leaves a payment trail, has a victim in the treasury and is investigated in the way states investigate best. The cost to the budget is capped by the number of dead records; the cost of stuffing to a country is capped by nothing.
And the second point: "strange people who neither vote nor take the money clearly need checking, because they are de facto no longer citizens." Here the assistant agrees halfway. A check is needed — but of the record, not the person, with the same boundary as was drawn for those who refused the sum (019d.4b). The question to a record is administrative: is the person alive, where is he, is the document valid; the answer is a correction of the register. Neither voting nor taking the money is a right and has no bearing on citizenship: a living person who simply wanted neither is confirmed by one letter and stays on the roll. If silence becomes grounds for treating someone as "not a citizen", those in power gain a way of removing inconvenient people from the rolls, and people gain a reason to fear the register; both are worse than a dirty roll. What to do with a record nobody has answered for over several cycles — for example, move it to inactive with restoration on first request, as many registers do — is for the country's law to decide. 🟡
Who will ask about a dirty roll. The architect added: "and the losers will have enormous questions — why are there so many dead and departed on the list; and they may even get the election annulled. But that is, in essence, forgery of documents and negligence — it is not our question." Both halves are right. The losers have questions today too, but nothing to ask them with: there is no figure, only a suspicion. The protocol supplies the figure — for every station one can see how many records nobody came for, neither for a vote nor for the sum, neither before the election nor after — and supplies someone who gains from presenting it: the losing side has that interest always, under any government. And the boundary is drawn correctly: the protocol neither investigates nor punishes. A signature for a dead person is forgery, an unreconciled register is negligence; statutes and courts for both have long existed, and what they lacked was not law but evidence. The protocol delivers the evidence as a by-product of the payment; from there ordinary law does the work. 🟡
The upshot on rolls. The architect drew the line in one sentence: "the protocol does, for reasonable money, what honest elections ought to do." Spelled out, it looks like this. Today a clean roll has not a single interested party: for whoever keeps the register a surplus record is convenient, and to everyone else it costs nothing. After the protocol there are four, each with a motive of his own:
| Who | What he does | Why he does it |
|---|---|---|
| The person on the roll | comes for the sum — and discovers a ballot cast in his name | the money |
| The losing side | presents the number of silent records station by station | a review of the result |
| The treasury | demands confirmation, matches against deaths and renunciations of citizenship | not to overpay |
| The fraudster | takes the sum for a dead record — and closes it to stuffing | the money; the benefit is unintended |
None of the four has to be hired, trained or persuaded, and none depends on who is in power. It is the same principle as throughout the protocol: not to add an inspector, but to make inspection somebody's personal interest. 🟡
Numerator and denominator. The architect noticed an oddity lying in plain sight: "votes are counted ballot by ballot, while the total is counted badly altogether." This is an exact description of today's procedure, and from an accountant's point of view it makes no sense. Ballots cast are recounted by hand, before observers, with a protocol in several copies and a right to a recount; disputes are over single units. Yet the number of those who could have voted is taken from a register in which more than a million records can be confirmed by nobody. In Moldova's 2024 referendum the outcome was decided by about ten thousand votes — a hundred times less than the uncertainty of the roll. It is as if the till were counted to the last coin with nobody knowing how much stock had been in the warehouse: precision on one side gives nothing until the other is reconciled. And it is precisely the denominator that is the resource for forgery: what gets stuffed is not "extra ballots" but ballots for records nobody will miss.
The protocol reconciles both sides by the same device of double entry (048f): every record on the roll must close with one of three outcomes — a vote, the sum, or confirmed silence — and the outcomes at a station must add up to the number of records. The result of an election is then checked not only as "how many ballots for whom" but as a balance: records = votes + sums + silent, with every part of the balance personally checked by someone. 🟡
Cheap re-voting. The architect added a consequence: "and at that percentage re-voting is much simpler." This changes not the detection of forgery but what happens after it — the weakest link of the present system. Today the only remedy for a spoiled polling station is to annul the result and hold the vote again for everyone; this is costly, slow and politically heavy, so courts resort to it in exceptional cases and demand proof that the violation changed the outcome (013d.6c). In the target configuration open votes are confirmed by tokens and are not subject to review; only the secret channel of an anomalous station can be in doubt — a few dozen or a few hundred people. Repeating the vote for them is a matter of one day and little money. And when a remedy is cheap, it gets used: the threshold at which a commission or court orders a repeat can be written down in advance as a rule — a divergence between secret and open votes at a station above a set level — with no dispute over whether it affected the outcome.
Hence deterrence too. Forging the secret channel makes sense only if the forgery stands; if it automatically leads to a repeat at that station, the gain from it disappears while the risk to the forger remains. The first version of this paragraph added a caveat: inviting only those who voted secretly to the repeat means disclosing which channel a person used. The architect objected: "it can be done; nobody knows whom they voted for. I am speaking only of paper ballots. It is the same level of security, only a second time, without loss." The objection is right, and the caveat is withdrawn. Paper voting is today too a public act with secret content: a person came to the polling station before his neighbours' eyes and signed a roll that lies with the commission. A repeat discloses nothing beyond that: those invited are the ones whose signatures already stand on the roll of the paper channel, and they vote in the same booth with the same secrecy. The level of protection is the same as at the first vote; only the spoiled result is lost.
This shows that it is precisely the two things together that work, as the architect said. Tokens without the register of those who took the sum leave open the main resource for stuffing — the half of the roll that does not vote. The register without tokens closes stuffing but leaves everything dropped into the box unverifiable. Together they leave the commission only the secret channel, and its size is a public number (§6b). 🟡
5c. A catalogue of techniques: what is closed, what remains, what is new¶
The architect asked whether any known channels remain unexamined — carousels and other techniques. Below is a consolidated list; the assistant's assessments rest on general knowledge of fraud practice, without a separate check of every row.
Closed by what is already written in §1–5b.
| Technique | How it works today | What becomes of it after the protocol |
|---|---|---|
| Rewriting the results protocol — including after publication: September 2026, Moscow precinct 248, 224 → 27 two days after entry into the GAS system (056f.1) | Figures are changed at the higher commission; no ballots needed; the posted copy does not get in the way | Open votes are summed by tokens independently of the commission (§2); only the secret channel can be rewritten — 5–10 % of votes, bounded by the number of signatures |
| Home voting | A mobile ballot box outside the station; people vote "for the grannies" | Pensioners take the sum more often than anyone; their records are closed and nobody can vote for them |
| Carousel | The same people vote at several stations on absentee and supplementary lists | It needs other people's or "nobody's" records and paper lists not linked to one another; in a single register with record status a second vote produces a conflict at once |
| Spoiling the opponent's ballots | A second mark is added during the count | Possible only in the secret channel; an open vote cannot be spoiled |
| Striking people off the roll, "you are not on the list" | An inconvenient voter is turned away | See below |
On the last row. The assistant first wrote: a person struck off will notice when the sum does not arrive — so the argument worked only for those who took the money. The architect widened it: "but he will come for the money anyway, even if he is not allowed to vote, and that can be done after the election too." Right: the late payment (§5b) makes a witness of the person who was turned away as well. He comes for the late sum, and the system must either pay — and then the register holds a record "was on the roll, did not vote, took the sum after the election, reported being turned away" — or refuse because there is no record, and then the person has a monetary reason to complain. The number of such cases by station is a gauge of exclusion that does not exist at all today. A caveat: the sum does not give the vote back, and mass exclusion still shifts the result; but it becomes countable, and a countable violation falls under the rule of a repeat at the station.
Remains, but on a smaller scale. Early and postal voting — ballots are stored for days and can be substituted; this is the same secret channel, under the same ceiling. Chain voting (a pre-filled ballot carried out of the station) and vote buying in general — the records are real, so the arithmetic of the roll does not help; something else works: the buyer loses his free base and the search narrows (019d.4b).
A separate category the catalogue lacked: falsification as intimidation. The Duma elections of September 2026 gave it a vivid form: 83 % for the Duma speaker in the Saratov district, precincts with 99 % turnout and 98 % for him, an opposing candidate on 983 votes against his 208,000; in St Petersburg and Moscow results were redrawn "from scratch" precisely where protest voting actually took place (056f.2). What these numbers have in common is that they do not affect the outcome: a constitutional majority was available without them. Their purpose is different — to show an opponent that his result is not merely small but indistinguishable, and so to drain the attempt to count of any meaning.
For the protocol this yields not a new defence but a clarification to §2. Parallel counting by tokens establishes a lower bound: if a candidate was sent a million tokens and the commission announces two hundred thousand for him, the fraud is arithmetically proven and its size is known. Against intimidation falsification this works better than against ordinary falsification, because intimidation requires a large discrepancy — and the larger the discrepancy, the more visible it is. A technique designed to demoralise, once a lower bound exists, demoralises whoever applied it. 🟡
Not solved by counting. Removal of candidates, clone candidates, administrative resource, media imbalance — all of this happens before polling day. The protocol acts on it through the weight of the vote and the composition of those voting (048g.3c), not through this section; nothing more should be promised here.
New — what the protocol itself creates. Three vulnerabilities that do not exist today.
The first is forced exit: the sum is taken in the name of someone else's voter, and on polling day he hears "you took the money". It is the mirror image of stuffing, but targeted: the opponent's supporters can be switched off station by station. The person will discover it, but late. Three rules are needed: a notification to the person at the moment the sum is taken on his record; a period for contesting it before polling day; a provisional ballot for anyone contesting on the day — the vote is counted after verification.
The second is coercion to take the sum. For a boss it is cheaper to demand that "unreliable" employees exit than to demand "vote the right way": exit is verifiable, a choice in the booth is not. Partial protection already exists: only shares by station are published, without lists (019d.4b), so a boss can check a particular employee only by making him show a bank statement. This is the same coercion as analysed in 048h, and the remedies are the same — making the demand punishable and an anonymous complaint; an anomalous exit share at a station next to a large employer shows in the data.
The third is the open channel as a black box. A token shows a person his own vote; that is not enough if the system can show everyone "your vote is counted" and count differently. The design of §2 bounds this from below: candidates' servers sum the tokens handed to them, and an official figure below that sum is proven forgery. But the lower bound depends on how many people handed over their tokens. Full protection is publication of all tokens with votes, without names, so that anyone can add up the total; this requirement should be written into the pilot's charter. 🟡
The architect's answers to the three vulnerabilities. On the first: "technically easy to solve through an application installed in advance." The assistant agrees: this is a problem banks solve every day — an operation is confirmed from a device bound to the person beforehand, and the sum cannot be taken for him from someone else's phone. For those without a smartphone — and these are precisely the elderly, who take the sum more often than anyone — there remains collection in person with a document, as with a pension. The three rules above stay as insurance rather than as the main protection.
On the second: "it does harm, but not much, and it is a matter for the police." The assistant agrees and adds the reason why not much. A boss who demands "vote the right way" adds votes to his candidate. A boss who demands exit can only subtract — and subtracts blindly: he does not know whom the employee would have voted for, because the choice is secret. By forcing a whole workshop to exit he removes his own supporters too. It is a markedly weaker instrument than today's marching of staff to the polls, and it costs people less: the coerced person at least gets the money.
On the third: "every party can personally ask every voter to help with an alternative count; I think 95 % will be for it, the losers especially." The main thing here is the second half of the sentence. The lower bound is needed above all by the losing side, and its supporters are the most motivated: they will hand over tokens more readily than anyone. The higher the share handed over, the less is left for forgery: at 95 % no more than a twentieth of a candidate's open votes can be taken from him, at 70 % — up to a third. On the figure the assistant is more cautious than the architect: in exit polls about half agree (§3), though there people answer a stranger for no reason at all, while here their own party asks, the token is anonymous and it comes down to a single tap; the benchmark is 70–90 %, and a pilot will show more precisely. So the requirement to publish all tokens stays in the pilot's charter as a second line: the parties' parallel count needs no trust in the state, publication needs no participation by the voter, and together they close what each leaves open on its own. 🟡
5d. The upshot: accuracy compared with today¶
The architect summed up the analysis: "in my view we have brought the present electoral system, almost without restrictions, to very good accuracy compared with today." The assistant agrees with both parts of the sentence. "Almost without restrictions" is right: the secret ballot, polling stations, commissions and observers stay as they are, nobody loses anything (§1); what is added is the choice of the sum, an open channel with a token, and the late payment. "Very good accuracy" is right, compared with today, on every row:
| Today | After | |
|---|---|---|
| Records on the roll that the person himself checks | 0 of 100 | 91–95 of 100, with the late payment — almost all |
| The resource for stuffing | 40–50 % of the roll | records nobody came for — each of them counted |
| The shift that goes unnoticed at a station | 10–15 points | 1–3 points |
| Rewriting the results protocol | limited only by nerve | only in the secret channel, 5–10 % of votes |
| The voter roll | a discrepancy of hundreds of thousands of records, no owner | the balance "records = votes + sums + silent", four interested parties |
| What follows detection | usually nothing | a repeat at the station by a rule written in advance |
What this rests on — three assumptions that only a pilot can test. First: the share of the secret channel really turns out small; in a country where people have something to fear it will be large, and accuracy will then be lower, though the share itself will show it (§6b). Second: identification in the application is no worse than a bank's; if it is weak, both the payment and the open channel are vulnerable. Third: the rule of a repeat at the station is actually applied rather than left on paper — that is no longer a matter of arithmetic but of who orders the repeat. And a limit to the conclusion: accuracy of counting is not the same as quality of choice. Honestly counted elections can give a bad result; the quality of choice is the business of other parts of the protocol — the weight of the vote and the composition of those voting (001b, 013d). 🟡
Two corrections by the architect to the upshot. On the first assumption: "if people have something to fear, that is already banditry, and elections will not help them." As a limit of applicability this is right: where people are beaten or jailed for a vote the protocol will not be adopted at all — it needs a referendum, and the same power runs it; this section is not written for such countries (048h.4b). The assistant keeps one refinement: fear is not always the bandit kind. An employer in a one-company town, the head of a family, a village where everyone knows everything — this exists in well-off countries too and is measured in per cent, not majorities (048h.4b). The secret channel is kept for precisely these people, and with fear of that kind its share stays within the target 5–10 %. So the first assumption should be read this way: a large share of the secret channel means not "the protocol is inaccurate" but "there is a problem here that elections cannot solve" — and the protocol shows that problem as a figure, station by station.
On the limit of the conclusion: "counting a good choice badly is pointless too." Right, and more precise than what was written. Quality of choice and accuracy of counting do not add up, they multiply: the result of an election is what people chose multiplied by how faithfully it reaches the final figure. A good choice counted with an error of 10–15 points gives a random result; an accurate count of a bad choice gives an accurately measured bad result. The protocol works on both factors at once, and on both by one and the same act: the payment changes the composition of those voting (001b, 013d), and the same payment closes records to stuffing (§5b). 🟡
5e. Does the application make elections cheaper¶
The architect's question: does having an application make the procedure much cheaper. The answer from the data: cheaper, but not much — and price is not the point.
What elections cost today. For the parliamentary election of 28 September 2025 Moldova's CEC received 174.1 million lei; about 1.6 million people voted — roughly 109 lei, or 5–6 euros per vote cast. More than 109 million of that sum was remuneration for members of precinct and district commissions at home and abroad, so about two thirds of the spending is people at polling stations. Postal voting for part of the diaspora was estimated separately at 17 million lei. The structure is the same in Estonia: by the calculations of Krimmer and co-authors (local elections 2017, parliamentary 2019) internet voting is the cheapest channel per vote, and about two thirds of all costs are labour.
What follows. The application in itself saves almost nothing while the station is open: the commission sits the whole day whether a thousand people come or fifty. Savings appear when the paper channel shrinks. In the target configuration (§5b) a station of a thousand records sees some fifty people; stations can then be merged several times over, and the main expenditure item — paying commissions — falls roughly with the number of stations. The assistant's estimate: organising costs fall by a factor of one and a half to two, not ten — the paper channel, the CEC and the protection of the system remain, and the application's security costs money (in Estonia it was precisely this that raised the price of an internet vote between 2017 and 2019). The most expensive vote today is the one cast abroad — stations in embassies, post, queues — and here the application gives the largest saving per vote.
And the scale. Five or six euros per vote once in four years is a quantity invisible in a budget; the sum paid out under the protocol is larger by orders of magnitude. So the argument "the application saves on elections" is a weak one for the protocol and should not be put forward. The strong argument is different: the application is not a saving but infrastructure, without which three things in this section do not work — identification at payment (§5c), the token of the open channel (§2), and the notification to a person of any operation on his record. 🟡
5f. Testing the catalogue against the September 2026 elections¶
The catalogue in §5c was assembled from general knowledge of practice. The Duma elections of 20 September 2026 produced a list of techniques applied within a single campaign, per three analyses: Maxim Katz, Abbas Gallyamov, and Meduza's discussion with Alexandra Prokopenko and Andrei Pertsev (all 21 September 2026). Below they are arranged by the layer on which they act, because the layer determines whether the protocol reaches them at all. The material comes from those analyses; primary data were not verified. 🟡
Layer 1. Before the ballot — and the protocol does not work here¶
| Technique in September 2026 | What the protocol does |
|---|---|
| Yabloko struck from the lists almost everywhere | nothing |
| Long prison sentences for politicians (Shlosberg, Kruglov), removal of the right to stand, pressure on grassroots activists | nothing |
| Three-day voting; voting in occupied territories | nothing |
This is stated outright in §5c ("not solved by counting") and is confirmed here in practice: the campaign was decided on this very layer. The Novgorod case (056f.2) shows what is at stake: where the list stayed on the ballot it immediately took over six per cent.
But the protocol does change one thing on this layer, and it deserves stating precisely. It does not prevent a candidate being struck off — it changes what striking off costs. Today it works twice over: the voter loses his alternative, stays at home, and his absence is counted as consent. Under the protocol he comes anyway, because he came for his own money, and his money goes somewhere. A candidate can be removed; a voter cannot. Turnout ceases to be a consequence of motivation — and half the effect of clearing the ballot rests on that.
Layer 2. Producing turnout — the protocol's main answer¶
Per Pertsev this is the principal instrument, not stuffing: corporate mobilisation, tightened this cycle.
| Technique | What the protocol does |
|---|---|
| Threat of dismissal for not turning up; brigade leaders added to HR staff; compulsory reporting | Turnout ceases to be a commodity. A boss sells upward the turnout he produced; once everyone is paid for appearing, people come without him and "I delivered 95 %" is worth nothing |
| Bonuses to those who bring people in | the same budget line becomes pointless: there is no reason to pay for what will happen anyway |
| Mobilisation by state employees of their charges — clubs, pensioners, schoolchildren's parents | pensioners take the sum more often than anyone (§5c), and need not be led by the hand |
| Demands to photograph the ballot | not solved by the protocol; treated separately in 056d.7b — a photograph fixes the ballot at the moment of the shot, not at the moment it enters the box |
| Voting by remote ballot in a manager's presence | partly: the token stays with the person, and a token transmitted to a party does not depend on who was standing nearby |
The layer's limit, stated honestly: the protocol devalues coercion over attendance and does not abolish coercion over choice. The latter is examined in §5c as the second new vulnerability, where it is also shown why coercing the choice is a weaker instrument than today's herding: a boss who demands appearance subtracts blindly.
Layer 3. Producing the number — here the protocol gives a lower bound¶
| Technique | What the protocol does |
|---|---|
| Rewriting protocols in territorial commissions — per Pertsev one of the main instruments | open votes are summed by token past the commission; an official figure below the sum of transmitted tokens is proven fraud (§2) |
| Redrawing "from scratch" where protest actually occurred (St Petersburg, Moscow) | the same; and the larger the discrepancy, the more visible it is |
| Remote voting under the administration's control | the token shows a person his own vote — which today's remote voting lacks by construction |
| Falsification as intimidation — excessive figures that do not affect the outcome (83 % for the speaker; 983 votes against 208,000) | works better against this than against ordinary fraud: intimidation requires a large discrepancy, and a large discrepancy is easier to prove (§5c) |
Layer 4. "Dirt" — about five per cent, on Pertsev's estimate¶
| Technique | What the protocol does |
|---|---|
| Barring and expelling observers (Yekaterinburg, Yabloko's observers) | reduces their significance: a parallel count does not require presence at the precinct |
| Home voting without observers | pensioners take the sum more often than others; their records are closed and nobody can vote in their stead (§5c) |
| Physically blocking an observer (the Sakhalin case) | the same: there is nobody to block, the count runs from phones |
| Stuffing and carousels | closed by the register with record status per §5c; and per Pertsev they "do not give very much" anyway |
Layer 5. The product — the image of a majority¶
Prokopenko describes this as the signalling function of a constructed majority: "people saw each other at the polling stations, people know that they came, nobody knows how the neighbour voted."
The protocol produces a competing number, and that is its only answer on this layer: the share who declined the sum and the share of transmitted tokens are quantities no commission computes. But this switches on only after adoption, and before adoption the layer belongs to the authorities entirely (056f.1).
Conclusion: three layers out of five¶
The protocol acts on layers 2, 3 and 4 — producing turnout, producing the number, and dirt — and on two of them it changes the construction rather than improving supervision. On layer 5 it supplies a competing number after adoption. On layer 1, where the September 2026 campaign was actually decided, it does almost nothing — and the one thing it does is important but narrow: a candidate can be removed, a voter cannot.
Hence a conclusion worth keeping in any conversation about the protocol: it protects the count, not the choice. Where the choice has been destroyed before polling day, an honest count saves nothing — it only shows what was not there. 🟡
5g. How the authorities behave now and how they would behave after adoption¶
§5f examined techniques. This section is about behaviour as a whole, before and after, because what changes is not the techniques but what an administrator is paid for at all. The world "after" is not measured by the standards of "before": a large part of the present machine ceases to exist not because it was banned but because its product is no longer wanted by anyone.
What stops being a commodity¶
| Today | After adoption | |
|---|---|---|
| The administrator's target | turnout X %, party Y % — both quantities produced by the machine itself | turnout is near-universal and signifies nothing: people came for their own money. "I delivered 95 %" is not a thing anyone buys |
| What a local boss sells upward | produced turnout and a produced percentage | there is nothing to present; the only figure that attaches to him is economic (048g.3c) |
| Corporate mobilisation | the principal instrument, with brigade leaders, reporting and bonuses | a budget line with no purpose: paying for what will happen by itself |
| Rewriting the protocol in a territorial commission | works because there is nothing to compare against | runs into the token lower bound: a figure below the transmitted sum is proven fraud (§2) |
| The observer | a target: keep him out, expel him, block his road | ceases to be the bottleneck — the count runs from phones, there is nobody to block |
| Falsification as intimidation | free, and demoralising | becomes the most expensive kind of fraud: it requires a large discrepancy, and a large discrepancy is the easiest to prove (§5c) |
What remains and what appears¶
Listed honestly, or the comparison turns into advertising.
Coercion over choice remains. A boss cannot demand attendance but can demand a vote. The instrument is weaker than today's and is examined in §5c: whoever demands appearance subtracts blindly, not knowing how the employee would have voted.
Everything before the ballot remains (§5f, layer 1): striking candidates, sentences, removal of the right to stand. The protocol protects the count, not the choice.
A political cycle in payments appears. An incumbent who cannot draw a percentage can still move money: inflate the payment before a vote and trim it after. This is a known phenomenon, and the answer lies in the construction rather than in supervision: the distribution formula is fixed in the referendum text and not set annually (004.4.7b). But manoeuvring with the timing of collection and with spending remains, and this should be counted a standing vulnerability rather than a settled question. 🟡
And above all: the struggle moves from the precinct into the text of the law. If the number cannot be faked, the only way to change the outcome is to change the rule. Hence a prediction worth stating plainly: after adoption the pressure will fall not on commissions but on the formula — the coefficient, "temporary" defence deductions, the exclusion of categories from the list of recipients (004.4.3c).
That relocation is itself the gain, and here is why. Today the dispute concerns a number nobody can verify, so whoever writes it wins. Afterwards the dispute concerns a rule everyone reads, and it acquires three properties the present one lacks: it is visible (a formula cannot be changed in silence), it is slow (a law, not a night in a commission), and it is measured in money — everyone sees by how much his share fell. Fraud becomes not impossible but public and attributable.
What changes for a person¶
Today participation is a political act carrying risk and no payment, and absence is counted as consent. Afterwards participation is paid and signifies nothing, and only the choice of recipient stays political, covered by the secret channel. This is precisely the change Meduza's discussion describes as missing: the man who was afraid of being noticed with a paper ballot (056f.1) comes for his money and gives nothing away.
Weak point. All of this describes a construction rather than an observation: the protocol is adopted nowhere, and not one line of the right-hand column has been tested. The nearest verifiable analogue is regimes with direct resource payments, but none of them ties the payment to voting, so their experience cannot be transferred whole. 🟡
6. Two remainders for discussion¶
Loss of deniability for those who have already stayed. The floor price protects before the choice of status. Someone who has already refused D and stayed to vote no longer has that protection: for him the demand "since you stayed — show the token" is free for the instigator. Today he could show a photo and re-vote; an official token cannot be fooled that way. The Estonian device (an open vote can be overridden by a secret one, the last counts) restores deniability but takes away the token's power of proof: one cannot have a vote that is both provable for the count and deniable to the boss. It is the same trio "verifiability, secrecy, accessibility" (048h.1); the architect's construction chooses verifiability for volunteers.
The signal from choosing the secret channel. Once the open channel is official, choosing the secret one may read as "something to hide" — the literature calls this the unravelling of voluntary disclosure. The argument against, and it is a strong one: exit polls have existed for half a century, almost half of those who voted answer them voluntarily, and this has not unravelled the secrecy of the ballot (§3); where ballot photos are lawful, no effect is visible either. The argument for: in a dependent environment (a company town, the public sector under autocracy) pressure to "vote openly" is more likely. This is tested in a pilot by the share of open votes across types of territory.
And a general limitation: proof is not enforcement. In Belarus the forgery was proven and changed nothing. A parallel count works where there is a court willing to act on arithmetic.
6b. Who needs the secret channel and what its share shows¶
The assistant's formula was "the only thing needed is that the secret channel cease to be the only one". The architect refined it: "what is needed is that the secret channel be used by those who are really afraid — and then it is a question for the police why; by those who cannot poke at a phone; and above all by those who do not want their vote to be verifiable. That is a small share of all citizens. A father forcing his daughter to vote is some kind of horror film. A worker dismissed for how he voted? There would be such a scandal and inquiry that that boss would never work anywhere again. What matters is that the majority will be able, by themselves, cheaply, afterwards, if need be, to recount their own votes — no matter whom they voted for."
The main thing here is the last sentence, and it changes who counts. Today a recount is a request to the same system that counted the first time. With the open channel the recount is done by those who voted: each candidate's supporters add up their tokens and get a lower bound that cannot be disputed (§2). This needs neither an observer for twenty-one hours (013d.6c), nor a court, nor trust in the commission; it needs only that many people vote openly. The more they are, the narrower the corridor in which anything can be drawn: the ceiling on forgery equals the share of the secret channel (§5).
With the estimate "a small share" the assistant agrees for some countries and disagrees for others, and the figures are recorded in 048h.4b: in rich democracies pressure is single percentages, in the post-Soviet space and the Balkans a fifth to a quarter of workers and polling stations; observers saw family voting at every tenth to every fourth station in several countries, so there the "horror film" is everyday life. But there is no need to argue about it, because the construction answers the question by itself.
The share of the secret channel is a third sensor, beside the sum and the return of people with their votes (040b.2b). Nobody prescribes how many people "should" vote secretly; each chooses for himself, and the sum of those choices is a public number. Where there is nothing to fear, a small share votes secretly — those the architect named — and almost nothing can be forged. Where people are afraid, the secret share is large: verifiability is lower, but the frightened person has a crowd in which his choice of channel says nothing about him (§6, the second remainder). The trade-off between cover and verifiability need not be set by law — it adjusts itself and at the same time shows where in the country it is frightening. A high secret share in a district is precisely that "question for the police why" the architect speaks of, only put not to one person but to a territory, and put as a figure.
One condition, refined after the analysis of repeat voting (§5b). For the paper channel the very fact of taking part is visible today as well — the person came to the station and signed — and there is no reason to demand more here than exists now: what stays secret is the content. The condition concerns publication: only the shares of channels by polling station are published, without lists — the same rule as for status A and B (019d.4b); and no conclusions about a person from his having chosen paper are admissible. 🟡
6c. A working hypothesis: a letter on the ballot¶
Status — the architect's working hypothesis, not part of the protocol. The situation: an underdog candidate wants to advance the protocol where it cannot be put to a referendum. The proposal: build the whole campaign on the protocol, and on polling day ask supporters to add a letter to the ballot besides the ordinary mark: A — "I am for the protocol and would take the sum", B — "I am for the protocol and would stay to vote"; whoever does not support the protocol makes the ordinary mark with no letter. "Those who collect the ballots will see at once how many people support the protocol. It cannot be counted, but the action itself is very handsome and striking in media terms."
What is strong in it, in the assistant's assessment. First: it is a referendum without a referendum — support for the idea becomes visible on official ballots that are unfolded before the commission and the observers of all parties. Second: "it cannot be counted" is true only of the official count; the candidate's observers can tally letters as ballots are read out, which gives a lower bound in the spirit of §2. Third, and most valuable: the ratio of A to B is the first field data on what share of supporters would take the sum — that is, on the main unknown of the whole forecast (015b.6) — obtained not in a poll but on a real ballot. The format has a precedent: actions that cannot be counted but are visible to all — for instance "Noon against Putin" in March 2024, when people came to polling stations at the same hour — work precisely as a media event.
The main risk is losing one's own supporters' votes. In many countries extraneous writing makes a ballot invalid or gives the commission grounds to declare it so; the ban on marks exists precisely so that a ballot cannot be identified and shown to a vote buyer. One common letter does not identify a person, but what decides is not logic but the text of the law and the practice of commissions. So a lawyer's opinion for the particular country is needed before the action. Where writing kills the ballot, the letter is taken off the ballot: a photograph with the letter outside the station, a badge, a parallel count through the candidate's application on the model of "Golos" (§2) — a weaker effect, but the votes are intact. The second risk: the commission sees the letters, and in a dependent setting supporters at a small station can be estimated by number; for the countries of 048h.4b the action is unsuitable. The third: zero information on those who support the idea but do not vote for the underdog — the letter measures support only within his electorate. 🟡
The architect's refinement removes most of the main risk: "right in the box where the tick goes; usually in all countries one can write a letter too." For countries where people vote with a pen this is largely true, and it is better than writing beside the box. The rules of such countries usually require not a cross as such but a clear intention: in Scotland and England a ballot marked otherwise than by a cross is not rejected if the voter's intention is clear; in California a check mark, a cross, a circle or "any other clear indication of the voter's choice" is valid; in Russia any sign in a single box is valid. A letter in the chosen candidate's box is itself the mark of choice, not extraneous writing, and almost no ground for rejection remains. The action loses nothing by it: a ballot with a letter in place of a tick is just as visible when ballots are read out.
The assistant qualifies "in all countries" — there are three cases where the device does not work technically, and Moldova is one of them. First: countries where people vote not with a pen but with a stamp — in Moldova the voter applies a "Votat" stamp in a circle, there is simply nothing to write a letter with and nowhere to put it, and any writing would be extraneous. Second: machine reading and electronic machines — scanners in the USA and the Philippines recognise a filled oval and may not read a letter at all; in India and Brazil the voter holds no paper ballot. Third: ranked systems (Ireland, Australia, Scottish local elections), where numbers are written in the boxes and a letter breaks the mark itself. So the lawyer's opinion stays, but the question to him becomes simpler: not "may one add writing" but "with what and how is the mark made, and what does the law call a valid sign". 🟡
The architect removed the third limitation: "if I know about the idea but do not vote for the underdog, I can put the letter myself." Right, and it is precisely the letter in the box that allows it: the sign goes in the box of one's own candidate, whoever he is. The assistant was wrong to tie the letter to the underdog's electorate. The consequence matters more than the correction itself: the action detaches from the candidate. Letters in the boxes of different parties show what no result of the underdog ever could — that the idea is supported across party lines; and for a protocol that changes the rules for all parties at once, that is exactly the proof needed. A practical condition remains: not only the underdog's supporters must learn about the letter, so the campaign must push not "vote for me and put the letter" but "put the letter whoever you vote for". For the candidate himself this looks a losing move yet is a strong one: he asks not for a vote but for a sign, and thereby shows that the idea matters more to him than the seat. 🟡
How it is said. The architect refined the tone: the candidate need not build all his campaigning on this, but in a debate he can address his opponents and their voters directly — "out of respect, as in sport: I am against you, but the idea is above parties, and you may do it too." The assistant regards this as the best possible form, for three reasons. A debate is the only platform where an underdog is heard by someone else's electorate, so the invitation reaches exactly those it is meant for. The opponent is caught in a fork: to stay silent means the invitation stands unopposed; to forbid his voters to put the letter means coming out, in full view, against an idea that does them no harm; to support it means making the idea common property. And the gesture itself works for the candidate: a person who openly offers a rival's supporters a sign without asking for their vote looks stronger than one who asks for votes. The limit is the same as for the whole action: it works as long as debates exist and the underdog is admitted to them. 🟡
Wider than the protocol. The architect noticed that the device suits more than this one idea: "this can be done even in Russia, showing in this way whether I am for or against; the opposition, by the way, could have used it — everyone counting ballots would know from the letter that the voter is in fact against the authorities but expresses it in a valid ballot instead of spoiling it. Though the result is equally meaningless." The general principle is right: a letter in the box is a way of sending a second message without sacrificing the first. A spoiled ballot says "against" at the price of the vote; the letter says the same and the vote remains. Here the assistant also corrects his own text above: the action is not dangerous to a person even in a dependent setting — a common letter identifies nobody, the ballot is anonymous; "unsuitable" referred not to personal risk but to there being nobody there to run a parallel count. The Russian case is examined in the country chapter (056d.7b). 🟡
The window of opportunity. The architect: "the beauty of it is that the system is unlikely to introduce stamps or electronic voting everywhere quickly, and for some time this device will work even in countries like Russia." Right: the device feeds on the oldest and most widespread part of the procedure — paper and pen — and replacing it across a country means passing a law, buying equipment and retraining commissions; that is years and money. Besides, any hasty replacement made so that people cannot put a letter becomes news in itself and an advertisement for the letter. The assistant adds a cheap countermeasure worth knowing about in advance: not changing the technology but declaring, by a clarification of the electoral commission, that ballots with a letter are invalid. That is quick, but such a measure has a price of its own: it contradicts the "any sign" rule where that is written into law; it hits the voters of all candidates, the authorities' candidate included, because anyone can put the letter; and it requires a public explanation of why a letter is more dangerous than a tick. So the action is best announced in such a way that no time remains to change the rules before polling day, with the fallback — a sign off the ballot — kept ready. 🟡
The countermeasure does not work. The architect rejected the previous paragraph: "you talked nonsense; the letters can be turned into any symbol — an oval with a dot, an upside-down tick; and it is secret all the same, while the authorities cannot prescribe the exact size of a tick or a symbol." He is right, and the assistant overrated the countermeasure. A ban on a particular letter is sidestepped by changing the sign within a day: the space of signs is infinite, and announcing a new one over the network is an hour's work. To close the device the authorities would have not to ban a sign but to describe the only permitted one — say, "only a cross of two straight lines" — and reject everything else. But people today put ticks, crosses, pluses, or shade the box; such a rule would invalidate a noticeable share of ordinary ballots, above all those of elderly voters, that is, of the authorities' own electorate, and would turn every count into a dispute over the shape of a line. And even that does not close the device: a cross can be drawn with a long tail, at a slant, in a corner of the box. The race here runs in the voter's favour: his move costs nothing, the authorities' reply costs a law and spoiled ballots. Only a stamp and a machine really close the device — that is, the very costly replacement spoken of above.
One condition remains, no longer legal but practical: the sign must be common and recognisable. The strength of the device lies in the commission seeing many identical signs (056d.7b); a hundred different squiggles say nothing. So the sign can be changed, but by everyone at once and to a single one. 🟡
Where the device belongs. The architect named the essence: "how to advance anything openly where nothing can be advanced any longer: Belarus, Russia, Kazakhstan. It is a hack of autocracies that hold elections and cannot give them up." Political science calls such regimes electoral authoritarianism (Schedler; in Levitsky and Way — competitive): elections in them do not decide who rules, yet they remain the only source of legitimacy, and the regime cannot abolish them without admitting what it is. Hence the vulnerability. Since elections are held, millions of people once every few years lawfully receive paper and a pen in a booth where nobody sees them, and then that paper is unfolded before the eyes of the apparatus. The regime controls the question on the ballot, the list of candidates and the final figure; the one thing it does not control is what else a person draws in the box. The device uses exactly this remainder: a referendum on a question that cannot be put, inside an election that cannot be won. It can be closed only by giving up paper or giving up elections themselves, and both steps cost the regime more than the sign does. Country analyses: 056d.7b (Russia), 057b (Belarus). 🟡
Nor does a stamp close it. The architect removed the first of the three technical exceptions named above: "even a stamp can be applied upside down, or a little to the right, or a little to the left; the authorities cannot deprive people of this method one hundred per cent." Right, and the assistant was wrong to list Moldova among the countries where the device is impossible: a stamp with the word "Votat" turned through a hundred and eighty degrees remains a valid mark in the right circle and yet is readable at a glance — the word stands upside down. The general rule that follows: any act a person performs by hand has spare degrees of freedom — tilt, position, pressure, order — and a law requiring "a mark in the circle" cannot enumerate them all without invalidating half the honest ballots. Degrees of freedom are absent only where there is no hand at all: a touchscreen and remote voting accept one of the preset answers and nothing beyond it. So of the three exceptions one and a half remain: a machine without paper closes the device completely; a scanner does not prevent the sign from being made but hides it from the commission's eyes; ranking by numbers leaves the same degrees of freedom as a stamp. 🟡
Why going digital is costly to the regime itself. The architect named two reasons why the only working countermeasure — a machine without paper — is not free for an autocracy: "it strips away the imagined sanctity and honesty of elections, and authoritarian regimes do not want that; and they also fear that all this digital part, unlike paper, will easily leak for money or through carelessness to the wrong people — as cameras in Iran helped to kill the head of the country."
The first reason is ritual. An electoral autocracy holds elections for the picture: the queue, the booth, the box, paper counted by people before witnesses. The picture is what produces legitimacy; a server issuing a figure does not, because nobody can check it, the authorities' own supporters included. Russia shows the price of the transition: remote voting is being expanded there, and it is exactly what produced the loudest scandal of recent years — in Moscow in 2021 the results in several districts flipped after electronic votes were added. A regime can go digital, but it pays with the very appearance of honesty for which it keeps elections at all.
The second reason is leakage. Paper ballots are physically anonymous and are destroyed after a year; a digital system stores who voted, when and from which device, and that database lives as long as the server does. It leaks the way all other state databases leak — for money, through negligence, at a change of power — and then the regime acquires a name-by-name list of its own officials and security men who voted against. The Iranian example concerns the same property of digital infrastructure: according to reports published in March 2026, Tehran's traffic cameras had been hacked for years, and the picture of movements gathered through them helped plan the strike of 28 February 2026 in which Iran's supreme leader was killed. A system built to control the population became a channel for watching the authorities themselves. An autocracy that has seen this has something to think about before moving voting into the digital realm as well. 🟡
The third reason, and the main one: the exam. The architect pointed to Ekaterina Schulmann: "elections in Russia and other autocracies are a theatre in which the state machine sits an exam in loyalty; making them electronic means removing the exam itself." The assistant did not find a direct quotation, but the thought in her rendering is well known and matches the academic literature: in Magaloni ("Voting for Autocracy", 2006) and in Gandhi and Lust-Okar (the 2009 review) elections in such regimes exist not for choosing but as a regular check — the centre learns which governor, mayor, director and rector can bring people out and deliver the figure, and the apparatus from bottom to top shows it is ready to do so. A result can be drawn on a server by one person; a region can be mobilised only by thousands, and it is their readiness that is tested. Electronic voting abolishes the exam: it yields a figure but says nothing about which of the executors still function. A regime that has gone wholly digital goes blind with respect to its own apparatus.
This shows why the device of the sign hits so precisely. While the exam is sat on paper, it is administered by the very teachers and employees it tests — and the sign is laid on the table before exactly them. They sit the exam in loyalty and that same night learn how many people around them would not have passed it. The device can be closed only by abolishing the exam, and abolishing the exam means ceasing to know whom one can rely on. 🟡
A fork for the regime. The architect carried the thought to a conclusion: "for the ordinary people the authorities need, a scanner is magic that can be drawn and faked; it is a desacralisation of the vote, its conversion into zeros on a monitor, and zeros anyone can type on his own phone in any quantity. This eats away at legitimacy, and even that is already a victory." The assistant agrees and notes whom exactly this hits. The regime's opponents disbelieve the result under any technology; paper persuaded not them but the regime's own base — the elderly, the rural, the loyal, for whom "I saw them count it myself" is the proof. A machine takes that proof away from this base: nobody can check it without special knowledge, which is the very argument on which Germany's Constitutional Court banned voting machines in 2009 in a country where nobody feared forgery (048h.1). The assistant first added a guess here that scanners are installed reluctantly because they hinder stuffing. The architect corrected it by Occam's razor: "a scanner is configured by a programmer — it counts the way it is set up, and that is the desacralisation; and they are not installed because the schoolteachers on commissions handle them badly, while stuffing a ballot is far easier for them." The simple explanation is better: a scanner means money, maintenance and training for people used to counting by hand; and it is not a safeguard but the same black box, only with paper inside.
The result is a fork in which both branches lose for the regime. To keep paper is to keep the sign: a referendum on any question, laid out on the table before its own apparatus. To go over to the machine is to remove the sign at the price of the ritual, the exam and its own supporters' faith in the figure. The device thus wins even when it is closed: the very attempt to close it costs the regime more than the sign does. 🟡
The examination as a target map¶
The examination argument acquired an operational extension in September 2026 that this section lacked. From the analysis of the Duma results: "electoral mobilisation differs technically in no way from mobilisation to the front — it is exactly the same administrative exercise; the chain of command must on order turn people into loyal voters or into soldiers." And then the conclusion the examination is kept for: conscription may follow the electoral map — the quieter the elections passed and the less plausible the drawn result, the more reliably the local authorities are held to govern their territory (056f.2).
If so, the examination stops being a metaphor: its grades are used as a target list. For this section's argument that is a reinforcement — it becomes clear why the regime clings to the paper procedure and why digitising it is expensive for it: what it would lose is not legitimacy but an instrument. And it is at the same time a warning worth keeping alongside: an excellent grade in such an examination is no reward for the inhabitants of the region that earned it. 🟡
7. Weak point of the section¶
The construction is described at the level of an idea: there is no token-issuance protocol, no answer to who holds the signing key and how it is verified that exactly one token per voter was issued, no legal frame — in many jurisdictions disclosing one's vote is prohibited, and an open channel requires a change in the law. The assessment of "unravelling" rests on the absence of an observed effect in free societies; for a dependent environment there are no data. 🟡
Related: 048f (double entry) · 048h (secrecy, verifiability, the price of coercion; the trilemma) · 057b (Belarus) · 056d.2 (the count and the opposition) · 033c.4 (publicity of status) · 059d.5 (the floor price of a vote; Proof-of-Stake) · 057c.6 (open source, multisignature) · 042 (poison pills)