Earlier quoted context omitted.
Indeed. It doesn’t meet the requirements of EU qualified signatures or seals, for example.
What are the actual requirements? In USA we only have a few requirements from the E-SIGN act: Key Legal Requirements Intent to Sign: Parties must show a clear, provable action to sign the document. Electronic Consent: Parties must agree to use electronic records, with consumer transactions requiring specific advance disclosures. Signature Association: The system must capture an audit trail or text linking the signatu…
Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted
41–48 of 48 posts
Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted
#42Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted
#43Earlier quoted context omitted.
Indeed. It doesn’t meet the requirements of EU qualified signatures or seals, for example.
What are the actual requirements? In USA we only have a few requirements from the E-SIGN act: Key Legal Requirements Intent to Sign: Parties must show a clear, provable action to sign the document. Electronic Consent: Parties must agree to use electronic records, with consumer transactions requiring specific advance disclosures. Signature Association: The system must capture an audit trail or text linking the signatu…
Certificates must be issued by qualified trust service providers (see section 3 for their requirements) who verify the identity of the certificate holder and ensure that the holder has sole control over the certified key. Among other things, this generally means that the key must be held in a certified HSM or smart card/USB key.
The provider infrastructure is subject to supervision of the EU member states, who accredit bodies that perform the conformity assessments.
The main purpose of all this is to ensure that the four requirements listed in article 26 are met:
"An advanced electronic signature shall meet the following requirements:
(a) it is uniquely linked to the signatory;
(b) it is capable of identifying the signatory;
(c) it is created using electronic signature creation data [private key] that the signatory can, with a high level of confidence, use under his sole control; and
(d) it is linked to the data signed therewith in such a way that any subsequent change in the data is detectable."
Let's Seal could attempt to argue that they do ensure these requirements, but their "control of a domain" scheme is unlikely to clear that bar, and they probably also don't secure their signing infrastructure in a way that would be deemed sufficient.
Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted
#44Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted
#45Nice idea but with all related things the ultimate question remains whether courts will actually recognize it. Currently courts will still consider paper-signed and scanned PDFs as legally binding, so any verification on top of that is superfluous to them. More realistically, you take an oauth when you take the stand at the court, and if a signed document was altered by the counterparty you'd say so truthfully, if it…
Re: Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted
#46You can't be the "Let's Encrypt of" anything if it's self-hosted. The entire point of Let's Encrypt is that there is a centralized reputable entity of note signing everyone's keys. Without that, it's entirely worthless. It's no better than a self-signed SSL cert or putting your own PGP key on a document manually. There's no point in a layer of abstraction atop that.
If you recognize it or not, is another topic.