Democratic elections have always depended on procedures through which voters prove their eligibility, mark their choices, and deposit ballots. The ballot box is closely monitored, the count is supervised, and the ritual is familiar enough that most people understand what’s supposed to happen, even if they don’t appreciate every aspect of the protocol.
They don’t need to know every single rule; they just need to have confidence in it. The polling station isn’t only a place where votes are collected but also a place where trust becomes visible. It’s a place where people stand in line, officials check names, and ballots move from booth to box to count. Even though the process isn’t perfect, what matters is that it is legible to ordinary people.
In Estonia, one of the world’s most digitally integrated states, voting is done somewhat differently. It’s done over the internet. The 2023 parliamentary election, during which more than half of all ballots were cast online, is now recognized as the world’s first parliamentary election in which online votes outnumbered paper ballots.
That didn’t happen because the state appended a voting website to an otherwise analog democracy. No, the system grew out of a broader digital state with an existing national digital identity program, and technical provisions for cryptographic infrastructure, software applications, audit procedures, and election oversight. And, given how Estonians have already used digital identity for taxes, banking, digital signatures, healthcare, and public administration, the introduction of internet voting (known as “i-voting” in English language documents produced by the Estonian government) wasn’t really a surprise.
In fact, while online voting is still considered unusual in democratic terms, at least for us living outside Estonia, for Estonians, it’s part of daily life. However, the ordinariness of this new system has introduced problems of its own into the electoral process. Trust issues, to be more specific, and the kind of trust issues that the traditional ballot simply hasn’t suffered from.
The vulnerabilities of the traditional ballot are easy for ordinary people to imagine. I-voting, on the other hand, prevents citizens from directly observing the voting process, prompting questions about what happens when election legitimacy depends on systems most citizens can’t personally inspect.
The Old Civic Protocol
Despite being simple in theory, paper voting was – and still is – anything but. It only feels simple because much of its complexity is visible to the public and supported by institutions people recognize as legitimate. It’s the illusion of simplicity that depends on rules and roles, documents, seals, signatures, observers, and non-negotiable timelines. A sealed ballot box matters because it’s visible, and because there are institutions, laws, and people responsible for keeping it sealed.
A polling station is, thus, a highly protocolized environment, with mandatory eligibility checks, privacy protections, and measures to prevent people from casting multiple votes. Ballots must be stored securely, the count must follow accepted rules, and the entire system must establish who voted without tying that person to their political choice.
Paper systems perform this latter function through physical separation. The voter list confirms the voter’s eligibility, the booth protects privacy, the ballot preserves the vote, and the counting table turns individual ballots into results. These steps are relatively easy to picture and follow by ordinary people, even if they don’t really understand the full institutional machinery behind said steps.
I-voting hasn’t simply moved these traditional systems onto a screen. In fact, i-voting reproduces many of the same democratic functions through a different set of dependencies. Paper voting relies heavily on physical custody, election officials, observers, and legal authorities, while i-voting relies on software, cryptography, digital ID systems, technical audits, and specialist expertise.
In other words, the democratic act of voting remains procedural, but the distribution of authority changes. Much of the process becomes less visible to the ordinary voter, and any meaningful inspections increasingly depend on people with the technical literacy to understand the systems underneath. The voter is still expected to trust the process, but the question becomes more complicated: who, exactly, is being trusted, and why?
When the Ballot Becomes a File
With the i-voting system, Estonian voters don’t need to go to polling booths. In fact, they don’t even need to leave the comfort of their homes to vote.
During the voting period, voters can download the voting app onto their personal computers, authenticate their digital identity, select their preferred candidate, and confirm their vote with an individual PIN. Votes are then encrypted, digitally signed, transmitted, separated from the voter’s identity, and counted.
The process looks rather simple from the voters’ side, but that simplicity is only superficial, because there are several safeguards operating under the hood. One of them is a separate verification smartphone app, which allows voters to check shortly after voting that the vote received by the system matches the one they intended to cast.
Arne Koitmäe, an Estonian election official closely familiar with the country’s internet voting procedures, explains why this layer matters: “When the vote is sent to the voting service, the vote is in the wild, on the internet. That environment cannot be controlled by the election administrator, so it is important to provide a way to make sure the vote is not tampered with while it is being sent.”
The verification app addresses one kind of risk: whether the vote was altered in transit. Revoting addresses another: whether the voter was pressured while casting it. Voters can vote online as many times as they want, but only their last i-vote is counted. In addition, a later paper vote can override an earlier online vote and thus alleviate certain challenges associated with remote voting, such as coercion at home by family and friends.
Polling booths, ballot boxes, and physical custody still exist for paper voters, while online voting performs comparable functions through software, cryptographic design, digital identity, and oversight.
In the digital system, a vote that was otherwise cast via a traditional paper ballot becomes a file, and that file has to be traceable enough for the system to verify, but not traceable in a way that exposes a voter’s private choice. It has to be secure enough to count, but anonymous enough to remain democratic.
Koitmäe also describes the counting-stage separation in practical terms: “Before decryption, the cryptograms are taken out of the digital signature container. From that point, they are anonymous. They are just cryptograms.”
Trust as a Designed Output
We might tend to approach the trustworthiness of internet voting through the lens of cybersecurity, but security is only part of a larger picture. The main issue, at least from the perspective of trust, is legitimacy.
A secure system that doesn’t earn the trust of its citizens can’t possibly do democratic work, and a trusted system that’s not secure is even worse. Estonia’s voting system needs to produce trust indirectly, and it does so through layers of procedure. However, most citizens can’t inspect the software in any meaningful way; they can’t follow the cryptographic path of their respective votes, and they can’t personally verify the stages that separate identity from ballot content.
Instead, citizens must rely on the country’s national digital identity program and previously implemented digital infrastructures, election laws, cryptographic design, audits, observers, verification tools, source code reviewers, courts, and election officials.
Admittedly, this isn’t anything new, because paper elections also required trust in officials, storage rules, ballot designs, recount procedures, chain of custody, and legal enforcement. Most voters never inspected any of those things either. What actually changes with i-voting is the kind of expertise needed to independently assess implemented safeguards. Understanding the physical chain of custody is one thing, but evaluating cryptographic protocols, source code, or server security requires a much narrower form of technical literacy.
The issue here is that most voters don’t actually have such expertise, so voters are compensated for that gap largely through an appeal to trust in institutions.
The reliance on institutions isn’t merely theoretical. A study published in Government Information Quarterly found that institutional trust was a stronger predictor of both confidence in i-voting and its actual use than technological trust. In practical terms, voters appear to care less about whether they trust digital technology in the abstract than whether they trust the institutions responsible for designing, operating, and overseeing a particular voting system.
The same study found that higher digital literacy increased the likelihood of using i-voting, while age and education themselves showed no significant effect. That makes the divide between i-voters and those who vote traditionally less clearly generational than it might first appear, assuming a tendency for younger generations to be more digitally literate.
From the voter’s perspective, then, the question is not simply whether to trust the software, but whether to trust the institutions and experts responsible for designing, operating, and overseeing it. That kind of trust is not unusual, even if the technology makes it more visible. In written comments provided for this article, Byron Hyde, Honorary Research Associate at Bangor University, notes, “Trust in almost anything works through proxies because we rarely have access to the things itself to arrive at our own assessment.”
Ballots in traditional voting went into a box, and boxes are tangible, and their contents are, in theory, legible to anyone. The ballot in i-voting, on the other hand, becomes an encrypted digital object that moves through different systems that aren’t as easily accessible to the public. In this case, the public has to place its trust in procedures and safeguards that govern both the people and the machines handling their votes.
Transparency Without Direct Visibility
Internet voting changes the significance of transparency because full visibility isn’t possible, understandable, nor, in some cases, even desirable (from a privacy perspective). If anyone could access and see anything and everything, voter secrecy would be compromised, and the system would become potentially easier to attack and exploit. The solution is to divide the transparency and the responsibilities.
Voters receive one kind of access, while auditors receive another. The same applies to election officials, software reviewers, courts, cryptographers, observers, and political actors. Each of these groups sees different parts of the process under different rules, which creates narrower forms of transparency, in which voters aren’t permitted to inspect every layer directly. Instead, they’re asked to trust that the right segments of the system can be inspected by the right people under the right conditions.
Koitmäe describes this kind of observation as more technical, but not hidden: “Observing is more complicated than paper voting. We have a training program for observers so they can know what happens from the beginning until the votes are opened and we have the results.”
Though this might sound undemocratic, as the process can’t be reviewed by just about anyone, the reality is that it’s far from it. Modern societies already rely on expert-mediated systems, such as air traffic control or central banking operations, that ordinary citizens can’t independently inspect. Instead, they rely on certification, professional standards, independent oversight, legal accountability, and the possibility of public scrutiny when something goes wrong.
That last part is really important, because different institutions can review disputes, investigate failures, challenge procedures, and explain different decisions publicly. None of those mechanisms allows ordinary people to inspect cryptography personally, so ordinary people have to rely on different experts and specialist authorities. And since elections represent the procedure through which democratic authority renews itself, the burden of explanation and accountability also rises.
Edge Cases in the Republic
The Estonian protocol is easy to trust when everything works as designed. The voters authenticate successfully, the application runs without issues, the ballot is cast, and the verification tools confirm that the votes were received. The results are published, institutions accept the outcome, and everyone involved moves on. But what happens if the system is challenged?
What if cybersecurity researchers question the assumptions built into the system, or election officials and independent experts disagree about the seriousness of a particular vulnerability? What happens if a political party claims the system is rigged or exploited, and can’t be trusted?
For Koitmäe, that political layer matters because legitimacy cannot be repaired by technical safeguards alone: “Frankly, I don’t see that there are any technological measures that will change this narrative. It certainly affects legitimacy in the end.”
This is where the asymmetry between traditional and i-voting becomes important. Most irregularities in a physical election can be described in terms an ordinary voter understands, like missing ballots, broken seals, improper handling, or discrepancies in the count. However, vulnerabilities in i-voting systems are much harder to evaluate without expert knowledge, because they move disputes into technical language that not everyone can speak.
Sure, the public can judge how institutions respond to possible tampering or exploits, and whether courts, auditors, officials, and political actors treat the system as accountable, but most people can’t personally resolve a cryptographic dispute. This creates a shift in public judgment, which no longer examines the legitimacy of the ballot count, but the institutions that claim that the ballot count is factual and not tampered with.
Hyde warns that this kind of trust can remain stable until a visible failure or political crisis forces people to reassess it: “When everything appears fine from the public perspective, trust tends to remain stable regardless of trustworthiness. But that’s a vulnerable situation that’s easily disturbed by a crisis.”
Convenience and Authority
Estonia’s internet voting system works because of its sheer convenience. A vote that takes minutes to cast, remotely, and that fits into an already digitized civic life has obvious appeal compared to traditional voting. It also helps people abroad, people with mobility constraints, and people whose work or family schedules make physical voting difficult. It makes participation much more accessible, which adheres to democratic values.
That accessibility, however, shouldn’t be confused with universal digital competence. It might seem reasonable to assume that younger voters would be more comfortable with i-voting than older ones, but the aforementioned research suggests that age alone is a poor explanation and not a significant predictor of online voting, especially when other factors, such as technical knowledge, are taken into consideration.
However, convenience also changes expectations, because the ease of digital voting makes traditional polling stations feel inefficient. The importance of a polling station in the electoral process diminishes, and in-person voting becomes just one among a number of ways to vote. With the widespread acceptance of i-voting, paper voting becomes a fallback, or a safeguard, rather than the obvious center of the electoral process. Authority gradually moves towards the system most citizens actually use.
That shift isn’t driven by convenience alone. Research based on post-election surveys from Estonia’s 2021 local and 2023 parliamentary elections examined how technical knowledge, trust, confidence, and perceptions of the system’s performance influenced the decision to vote online. The findings suggest that not all voters approach i-voting in the same way: their willingness to use it depends partly on how much they understand, how confident they feel in that understanding, and whether they believe the system has worked reliably.
When the use of one system becomes prevalent and shows results, the procedural trust associated with the system and its processes becomes self-reinforcing. People trust the system because they use it, and they use it because it works. It works because it’s maintained, and it’s maintained because its efficiency has become a part of the democratic settlement. Over time, the question shifts from whether internet voting should exist to what kind of legitimacy its continued existence requires.
This is a rather important shift, because democratic infrastructure becomes harder to remove once it becomes ordinary, and that’s exactly what’s happening in Estonia. If a majority of voters vote online, turning off the internet voting would likely have adverse effects on the relationship between voters and the state.
The Distributed Ballot Box
Though it’s tempting to say that Estonia replaced the ballot box with software, the truth is that the ballot box hasn’t been replaced, nor has it disappeared. It’s only been reformatted. Paper voting still exists, and even the traditional ballot box was never an independent source of legitimacy because, as previously explained, it depends on election officials, printing and distribution systems, secure storage, observers, rules, etc.
Part of the ballot box now resides in the voter’s personal electronics, and other parts of it live in different systems, like encryption, election law, audit procedures, revoting rules, verification tools, public documentation, etc. In other words, internet voting added new layers of dependencies.
In that sense, the ballot box didn’t simply become digital; the authority surrounding it became more distributed. Sure, traditional institutions remain important, but they increasingly share the task of legitimizing the result with software developers, cryptographers, CS researchers, and other tech specialists. Their expertise now becomes part of the chain through which voters are asked to trust the result.
More importantly, this doesn’t weaken the authority of the state, but it does affect its role. The state still establishes election law and administers the voting, but it can’t make cryptographic claims credible merely by declaring them to be true. Those claims have to survive technical scrutiny, independent reviews, and public challenge, making electoral legitimacy dependent partly on legal institutions, and partly on expertise of different specialists.
These distinctions make legitimacy a maintenance problem. Sure, paper voting needed maintenance as well, in the form of poll workers, storage rules, recount procedures, chain-of-custody protections, and public confidence. Internet voting requires the same democratic seriousness, but in a different form. It requires secure identity, software assurance, operational discipline, independent review, legal clarity, and the willingness to respond seriously to technical criticism.
Final Thoughts
The introduction of Estonia’s internet voting system is not a story about democracy being replaced by code. It is a story about how democratic legitimacy changes when the procedures behind elections become more technical, less visible, and more dependent on institutional interpretation. Elections have always relied on protocols. The question is how citizens are persuaded to accept these newer protocols as democratic, and what institutions must exist around them for that acceptance to be justified.
Estonia’s answer is both practical and unusually coherent, as the state invested in building the digital identity infrastructure first and normalized its use. Make voting one civic act within that trusted system, surround it with cryptographic safeguards, legal rules, revoting options, verification tools, audits, and public explanation, and let repeated use reinforce the public trust.






I'm from Estonia.
Estonia did Voice cost cheaper than Exit cost (see Exit, Voice, and Loyalty by Albert O. Hirschman).