Live data from Hacker News

The dubiousness of digitized signature services

blog.certisfy.com

11–20 of 70 posts

Re: The dubiousness of digitized signature services

#11
post #2

The average user is not savvy enough to sign consistently, but can keep a private key secure? That's a big assumption.

If the private key is in a smart card, why not? Some countries like Estonia include smart cards in their national IDs.

I'm increasingly convinced that this is the way forward. Having a key verifiably tied to you as an individual goes a long way to enabling a broad range of governmental services. Digital voting, for one thing, but also no more need to rely on shady credit check companies for address verification, as I've seen on some (Canadian) government forms.

Re: The dubiousness of digitized signature services

#12
I've been looking into this whole area recently for a project.

The problem isn't (only) the technical issues. As TFA points out, this is easy, and even the most naive and simplistic implementation beats physical signatures hands-down.

There's two main problems:

1. Legality. Getting a court to recognise a digital signature probably isn't that hard. It's a bit like scanned images - if you can prove that this is the best evidence, then it'll probably be accepted. However, getting lawyers to accept digital signatures is difficult. One of those awkward situations where there's no consequences for them if they insist on a physical signature but lots of potential downside should they accept a digital signature.

2. File formats, or "the standards problem". To include a digitial signature in a document, we need a file format that includes digital signatures. Every document file format has a different version of this, and every digital signature service provides a different "wrapper" format with a different signature.

This needs to be solved top-down. The SCOTUS, or the EU Court, or some organisation of similar standing, needs to say "this wrapper format is the only type of signature legally accepted, and if a document is wrapped in this format, it is legally signed". Both problems vanish and we can have nice things again.

Re: The dubiousness of digitized signature services

#13
post #2

The average user is not savvy enough to sign consistently, but can keep a private key secure? That's a big assumption.

If the private key is in a smart card, why not? Some countries like Estonia include smart cards in their national IDs.

In Portugal we have this. Each citizen identification card (called Cartão do Cidadão) has a unique certificate and the official Software allows you to sign any documents with it. Unfortunatly, I have never used this and never saw anyone using it. I never heard of any company accepting contracts signed with it. The technology is ready, but pen and paper are still the norm.

Re: The dubiousness of digitized signature services

#14
post #11

Earlier quoted context omitted.

If the private key is in a smart card, why not? Some countries like Estonia include smart cards in their national IDs.

I'm increasingly convinced that this is the way forward. Having a key verifiably tied to you as an individual goes a long way to enabling a broad range of governmental services. Digital voting, for one thing, but also no more need to rely on shady credit check companies for address verification, as I've seen on some (Canadian) government forms.

Or social security numbers in the US, which are absolutely not fit for this purpose.

For those in the US who don't want a national ID: it wouldn't have to be one if the states issued their own. Yes, this would mean they'd all need the technical capability to operate a CA securely. Fund them enough to do that.

Re: The dubiousness of digitized signature services

#15
post #6

Signatures generally have mostly become a total joke. I suppose there's some element, for many of us, that there's something vaguely scrawled that looks like other vague scrawls that indicate I may have glanced at a piece of paper. But, especially, at the current time having clean and dirty pen cups so we can sign a paper receipt or have to sign a digital pad with what's effectively just an X? At least my financial i…

The point of a physical signature is not that anyone else can prove you signed something. It's that if you go to court, and the court asks if you have signed the document, you're committing perjury if you say "no" (assuming you did sign it). It's the act that's important, rather than the resulting scribble.

Re: The dubiousness of digitized signature services

#16
Very recently, just before Pandemic hit India, we had to run around because one of the key Japanese counterpart was in USA and unable to send money (small amount) to complete a stock purchase.

My response was, "Please login to your bank's website and do the transfer."

That was the time I learnt that some (or maybe more) Japanese Banks still need the individual's personal Stamp/Seal to send money from their Banks.

I learnt an interesting thing.

Re: The dubiousness of digitized signature services

#17

I've been looking into this whole area recently for a project. The problem isn't (only) the technical issues. As TFA points out, this is easy, and even the most naive and simplistic implementation beats physical signatures hands-down. There's two main problems: 1. Legality. Getting a court to recognise a digital signature probably isn't that hard. It's a bit like scanned images - if you can prove that this is the bes…

1 and 2 have been solved in EU

Re: The dubiousness of digitized signature services

#19
I think this article misunderstands the purpose of signatures.

The purpose of a signature is to inform the signer that they are entering a binding contract. It is simply the modern equivalent to a handshake.

Sadly, precedent around Eula’s mean that signatures are no longer necessary to execute contracts.

If anything, society would be better served by making it more difficult to enter into binding agreements than to make it less difficult.

Imagine if, by law, for a EULA to be binding, the end user had to scroll through the entire document, and initial each separate section. Eula’s would be much shorter, and much less common.

In a digital equivalent of “no trespassing” or “cameras in use” signs a few standard clauses could be made enforceable by displaying them prominently on each page. For instance, there could be a clauses such as “you are purchasing a transferrable non-exclusive license to this software”, or “your subscription to this service is at-will with a fixed rate of $N/time-unit.”

Re: The dubiousness of digitized signature services

#20
I think this article misunderstands the purpose of signatures.

The purpose of a signature is to inform the signer that they are entering a binding contract. It is simply the modern equivalent to a handshake.

Sadly, precedent around Eula’s mean that signatures are no longer necessary to execute contracts.

If anything, society would be better served by making it more difficult to enter into binding agreements than to make it less difficult.

Imagine if, by law, for a EULA to be binding, the end user had to scroll through the entire document, and initial each separate section. Eula’s would be much shorter, and much less common.

In a digital equivalent of “no trespassing” or “cameras in use signs” a few standard clauses could be made enforceable by displaying them prominently on each page. For instance, there could be a clauses such as “you are purchasing a transferrable non-exclusive license to this software”, or “your subscription to this service is at-will with a fixed rate of $N/time-unit.”

Post reply on HN