Live data from Hacker News

Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

github.com

21–30 of 48 posts

Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

#21

I don't like the idea of this using bitcoin. I wonder if it's possible to build this off of regular PKI - certificate transparency logs for instance encode the proof of commitment, while the signature can be an X509 certificate.

The standards exist. The problem is, the certificates are not cheap, because there is real KYC needed.

https://en.wikipedia.org/wiki/PAdES

Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

#22

Loved it until I saw its using Bitcoin. With proof of work doesn’t it tie this project to a bit of an environmental nitemare? Bitcoin isn’t the best place for this, no? I would have imagined Ethereum or some other ledger would have been better no? Anyone with more crypto ledger knowledge be able to say what I’m trying to say more precisely.

[flagged]

Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

#23
post #16

I love the concept, it would be great to see broader uptake of an open standard for this sort of space.

Thx. The spec matters more than the site here, its SPEC.md in the repo. Still v1.1 and cheap to change, so any/all notes welcome.

Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

#25
post #9

Nice idea but with all related things the ultimate question remains whether courts will actually recognize it. Currently courts will still consider paper-signed and scanned PDFs as legally binding, so any verification on top of that is superfluous to them. More realistically, you take an oauth when you take the stand at the court, and if a signed document was altered by the counterparty you'd say so truthfully, if it…

[dead]

Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

#27
In my opinion, all of these open source/free/open document signing tools are neat on paper (and technically fulfill the goal of being able to verify a document's chain-of-custody/signature provenance) - but won't take off in any meaningful way legally because there's no entity behind them taking the responsibility for accuracy and culpability.

DocuSign/Adobe/whomever is trust anchor, it's an entity you can sue or subpoena if something goes wrong. Someone who's actually on the hook for making sure whatever's signed is accurate and truthful (outside of the reputational risk of fraud completely obliterating any trust in your platform)...

No amount of cryptographic verification substitutes for having a legal person on the other end who can be held accountable for actually verifying the document was signed accurately/process was followed.

Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

#28
Why not use RFC 3161?

Due to how the code signing works, timestamping servers are provided by all major CAs with full public access, e.g. timestamp.digicert.com, timestamp.comodoca.com, timestamp.sectigo.com, etc.

PS. OP, your comments are auto-killed for some reason. You may want to message mods to get this sorted.

Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

#29

I don't like the idea of this using bitcoin. I wonder if it's possible to build this off of regular PKI - certificate transparency logs for instance encode the proof of commitment, while the signature can be an X509 certificate.

[flagged]

Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

#30

Earlier quoted context omitted.

Sure, lets say this lacks an RFC/ISO number, or any semblance of what is usually called a standard.

What I think you're trying to say, but don't seem to be getting across super clearly, is that this standard hasn't yet gone through an open third party review

[dead]
Post reply on HN