Live data from Hacker News

Ask HN: Why is company letterhead a valid form of auth in 2022?

news.ycombinator.com

11–20 of 37 posts

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#12

You've gotta split it into 'technical auth' and 'legal auth'. Legal auth is simply making sure they can sue you, and/or get you sent to prison if you circumvent their system.

> Legal auth is simply making sure they can sue you, and/or get you sent to prison if you circumvent their system.

Also, there isn't a standard way to identify a company and to validate its actions. A slightly better one (at least where Latin notaries exist) is that the company secretariat make a declaration of whatever and include a certified copy of the company registration that certifies that the said person is the secretary of the company, but you end up with the ID problem except that it's for companies. Maybe a standard "passport" identifying companies? Did I re-invent parts of apostille? (https://en.wikipedia.org/wiki/Apostille_Convention)

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#16

Quoted post unavailable.

Can you share what a forward thinking European company would do, since Europe is so futuristic, and provide a specific example of a futuristic European social media tech company implementing this futuristic policy?

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#17
post #8

I have as well. Even a really long time ago, so it sounds like a long lasting habit. It reminds me of how lawyers are happy to accept signatures by fax. You could be a rather lousy forger, yet because of the huge and extremely black pixels, still make a passable forged signature over fax. You can even tape a real signature on the page, or make numerous corrections, because the resolution simply cannot show any of tho…

> It reminds me of how lawyers are happy to accept signatures by fax

The purpose of a lot of these sorts of requirements is not authentication. It's ensuring that if you do do it, you trigger the statutory requirement for some particular criminal offense. For example, a jurisdiction might have a crime of forgery which is substantially easier to prosecute than fraud (perhaps fraud would need the prosecution to prove intent to make financial gain, wheras forgery might be satisfied as soon as you can prove signature was forged -- hypothetical example, it will vary by jurisdiction and IANAL).

These sort of statues might have been written before computers or even faxes, and there might be caselaw to the effect that forging someone's signature and sending it by fax does satisfy its requirements of the offence, but none yet for just writing your name at the bottom of an email; things like that.

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#18

You've gotta split it into 'technical auth' and 'legal auth'. Legal auth is simply making sure they can sue you, and/or get you sent to prison if you circumvent their system.

This is the only sensible answer in this thread.

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#19

Quoted post unavailable.

Can you share what a forward thinking European company would do, since Europe is so futuristic, and provide a specific example of a futuristic European social media tech company implementing this futuristic policy?

Depending on the country, sign with a government-issued digital signature, or get a notarized signature and mail it, if strong authentication is desired. The company registries of most countries are available online, which would identify the CEO(s).
Post reply on HN