There's something I never understood about e-signature services: how are they legally binding? Why do we need them at all? The end users don't have control over any of the keys, so it all hinges on the e-signature service telling the truth. It's significantly less secure than say, S/MIME with a proper CA-signed certificate. Is the bar for legal "signatures" really that low?
The law isn’t like programming. The reason you sign something is to show clear intent that you intended to agree to something. Nobody’s under the impression a paper signature cannot be forged either. It’s no different. It’s social not mathematical.
>Why do we need them at all?
Why not just email the contract, and the person replies back with "I agree to this"? Simpler and cheaper than paying $150/year.