Live data from Hacker News

Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

usenix.org

11–20 of 158 posts

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#11
> For documents of prime importance, such as contracts and invoices

Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off.

Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic signature solutions don't necessarily solve it.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#12
post #11

> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…

At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value.

[0] https://en.wikipedia.org/wiki/EIDAS

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#13
post #12
post #11

> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…

At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value. [0] https://en.wikipedia.org/wiki/EIDAS

I agree, in Europe digital signatures are very common now. Although at least for me it's almost exclusively PDFs.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#14
post #11

> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…

I have been asked to e-sign pretty much every building/home leasing document involving myself in the past few years in the US. I am sure that this is also the case for thousands, if not millions, of other Americans.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#15
post #9
post #8

I've heard the same for Windows code signing certs - that's it possible to modify the payload and have the signature still apply.

Sounds like a useful feature to me.

I mean, aside from bypassing the whole point of having them.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#17
post #11

> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…

I have been asked to e-sign pretty much every building/home leasing document involving myself in the past few years in the US. I am sure that this is also the case for thousands, if not millions, of other Americans.

Sure, but do you have any indication cryptography is involved in this process? In my (limited) experience as a consumer, they just take some existing PDF and add marks on top of it.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#18
post #12
post #11

> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…

At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value. [0] https://en.wikipedia.org/wiki/EIDAS

> Emails don’t provide that legal value.

In general, agreeing to something by text in an email is as legally enforceable as a signature.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#19
post #12
post #11

> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…

At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value. [0] https://en.wikipedia.org/wiki/EIDAS

True, our company constantly use certificate based signatures, and government agencies emit most documents with the same method, almost always on pdfs. Tho most people tend to use AutoFirma, a java program written by the government for signing and checking signatures validity. I would love to see it thoroughly audited too.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#20
post #12

Earlier quoted context omitted.

At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value. [0] https://en.wikipedia.org/wiki/EIDAS

> Emails don’t provide that legal value. In general, agreeing to something by text in an email is as legally enforceable as a signature.

> In general [..]

...but apparently not always. Not something I'd want to bet my business or reputation on.

"AUSTRIA’s Federal Administrative Court [..] declared a framework contract from Austrian Federal Railways (ÖBB) to Stadler for the delivery of up to 186 double-deck trains to be null and void due to an alleged formal error in the qualified electronic signature of the offer." (September 2021)

https://www.railjournal.com/news/austrian-court-annuls-stadl...

Post reply on HN