Live data from Hacker News

The dubiousness of digitized signature services

blog.certisfy.com

31–40 of 70 posts

Re: The dubiousness of digitized signature services

#31
post #11

Earlier quoted context omitted.

If the private key is in a smart card, why not? Some countries like Estonia include smart cards in their national IDs.

I'm increasingly convinced that this is the way forward. Having a key verifiably tied to you as an individual goes a long way to enabling a broad range of governmental services. Digital voting, for one thing, but also no more need to rely on shady credit check companies for address verification, as I've seen on some (Canadian) government forms.

With software I'd be wary of making it the last line of defense, especially for very significant acts such as voting. A bug in the system would be totally fatal, not only for society but especially for the victim. Even more so if bugs aren't commonplace but only sporadic.

Using cryptography in addition to "classic" means of attestation sounds a lot better to me. You could also make it an "optional feature" of people's citizenships (like 2FA on an account) to ease adoption.

Re: The dubiousness of digitized signature services

#32

For serious identity variation in paper legal land we don't use signature matching, we use notaries: show id to a trusted 3rd party who can be later dragged into court, sometimes even with an additional witness to vouch for identity. (In closely related news, just try buying a house during a pandemic, I dare you. There are amusing pictures floating around online of my wife and I shoving documents back and forth throu…

just try buying a house during a pandemic, I dare you

Did that. (Offer made and accepted in August; moved in on October 1st.) All of the legal paperwork was done online on the basis of "here's a scan of two pieces of ID and click click click I agree" -- the only "shoving through a window" moment was with a bank draft, and even that could have been done digitally if I had been comfortable with transferring such a large amount of money based on instructions received via email.

Rules vary from state to state; in BC they were changed early in the pandemic to remove the need for in-person transactions.

Re: The dubiousness of digitized signature services

#33
post #6

Signatures generally have mostly become a total joke. I suppose there's some element, for many of us, that there's something vaguely scrawled that looks like other vague scrawls that indicate I may have glanced at a piece of paper. But, especially, at the current time having clean and dirty pen cups so we can sign a paper receipt or have to sign a digital pad with what's effectively just an X? At least my financial i…

The point of a physical signature is not that anyone else can prove you signed something. It's that if you go to court, and the court asks if you have signed the document, you're committing perjury if you say "no" (assuming you did sign it). It's the act that's important, rather than the resulting scribble.

I'm sorry, I don't understand. Well, I agree that it would be perjury. But then there would be no proof of perjury, and the perjurer would get away. That can't offer much assurance to the person accepting a signature.

Besides, the argument applies to other signs of consent, like verbal consent. Suppose you give a verbal consent to an agreement and then renege. The other party drags you to court. The judge says, "Did you verbally consent to this contract?" Saying "no" likewise would be perjury.

Re: The dubiousness of digitized signature services

#34
post #3

I've always seen the value of signatures as a ceremony first, not as a (serious) method of authentication. As an example, when have you last seen a merchant compare your signature to that on your credit card? Conduct implying intent, together with a hand-written signature, can go a very long way in practice. The value of these services to me accordingly seems to be in their accuracy of replicating the ceremony, not i…

> As an example, when have you last seen a merchant compare your signature to that on your credit card?

What would the merchant compare the signature on the card to? You don't sign a contract when buying groceries, you put in your card and type your PIN.

On the other hand, whenever I go to my bank and have to sign something, they do compare my signature with the one they have on file (formerly in a paper card, nowadays a virtual representation of that same card).

Re: The dubiousness of digitized signature services

#35

Very recently, just before Pandemic hit India, we had to run around because one of the key Japanese counterpart was in USA and unable to send money (small amount) to complete a stock purchase. My response was, "Please login to your bank's website and do the transfer." That was the time I learnt that some (or maybe more) Japanese Banks still need the individual's personal Stamp/Seal to send money from their Banks. I l…

Last week I have seen a newsshow about a company digitizing those (quite pretty) seals. They also mentioned how Japanese are very fond of fax machines.

Re: The dubiousness of digitized signature services

#36
post #11

Earlier quoted context omitted.

I'm increasingly convinced that this is the way forward. Having a key verifiably tied to you as an individual goes a long way to enabling a broad range of governmental services. Digital voting, for one thing, but also no more need to rely on shady credit check companies for address verification, as I've seen on some (Canadian) government forms.

Or social security numbers in the US, which are absolutely not fit for this purpose. For those in the US who don't want a national ID: it wouldn't have to be one if the states issued their own. Yes, this would mean they'd all need the technical capability to operate a CA securely. Fund them enough to do that.

People opposing a national ID in the US have de facto caused social security numbers, completely inappropriate as a national ID, to be used as one by everyone.

The US desperately, desperately needs a proper solution where "thing you give tons of people" isn't also "exactly enough to steal your ID".

Re: The dubiousness of digitized signature services

#37
This entire subject is so ridiculous. The US military has solved this problem almost as much as 15 years ago. No visible scribbles of any kind, just cryptographic signatures backed by certificate. The certificate is embedded on a photo ID hardware token that requires a PIN that locks after 3 failed attempts. The military uses digital signatures for everything.

Re: The dubiousness of digitized signature services

#38

For serious identity variation in paper legal land we don't use signature matching, we use notaries: show id to a trusted 3rd party who can be later dragged into court, sometimes even with an additional witness to vouch for identity. (In closely related news, just try buying a house during a pandemic, I dare you. There are amusing pictures floating around online of my wife and I shoving documents back and forth throu…

We just refinance and the notary came into our house and we did all the paperwork at our table. Masks all around and sanitizer of course. I think the notary fee was higher than normal because of it.

Re: The dubiousness of digitized signature services

#39

For serious identity variation in paper legal land we don't use signature matching, we use notaries: show id to a trusted 3rd party who can be later dragged into court, sometimes even with an additional witness to vouch for identity. (In closely related news, just try buying a house during a pandemic, I dare you. There are amusing pictures floating around online of my wife and I shoving documents back and forth throu…

Did it. Sat outside m, 6 ft apart w masks. Not too hard. Worked fine. But you're right, notarization is the way we do this for real transactions, at least in the p2p world.

Re: The dubiousness of digitized signature services

#40

These signature services make no sense. My UK estate agent is trying to get me to use an American signature service to renew my lease. - What I get is an email from a third party (the signature service) with whom I have no business relationship. Why would I trust anything they say? - How do I know the agent has signed the lease? - What can I do if the American service claims I signed a contract when I didn't? If I si…

We refinanced during the pandemic with $MEGABANK, and they almost exclusively used third parties and email for the entire transaction. The last step was a total stranger (employed by another subcontractor we’d never heard of) stopping by our house and notarizing each signature in the closing paperwork.

There was a day or two where we’d directed the previous lender to transfer title, and had already wired $100K’s to an unknown escrow service half a state away.

I didn’t sleep all that well until the previous lender said they’d received a wire for the amount due on the loan.

It’s not surprising that, among the paperwork we signed, there were multiple FBI notices about avoiding wire fraud.

Note that PKI didn’t help much with this transaction. All “secure” communications were delegated to entities that I had no reason to trust (e.g., subdomain.docusign.com).

I did check some license numbers here and there, and called the phone numbers the license holders registered with the government. So, the SSL cert on the .gov site helped (though even that is hit or miss, since it relies on domain registers confirming all the sites they allow are actually government entities.)

I also called the office number I found at $MEGABANK’s website to make sure they’d heard of me.

Beyond that, I had no reason to think $TOTALLY_LEGIT_ESCROW.com was not a phishing front.

Post reply on HN