Live data from Hacker News

Docuseal: Open-source DocuSign alternative

github.com

171–180 of 200 posts

Re: Docuseal: Open-source DocuSign alternative

#171
post #4

Very nice and easy to use product. Loved that you provided an live version to try it without any signup wall or anything. Also won't DocuSign accuse you of "misleading" their customers by using a name that is "too similar" to their ?

> won't DocuSign accuse you of "misleading" their customers by using a name that is "too similar" Docuseal would be the winner with all the free press, and changing a name costs almost nothing.

They should make a seal be the mascot

Re: Docuseal: Open-source DocuSign alternative

#172

Earlier quoted context omitted.

> What justification do the e-signature SaaS companies have for their exorbitant prices? They will defend their digital signature in court. I was shocked to find these "click here to sign" contracts manage to do it all without an ounce of cryptography, but the fact is lawyers don't need cold hard math, they need a warm body to be a subject matter expert to explain to a jury that unless you're claiming someone else ha…

I had to get a notary to sign my I-9 form for a new remote job. The process of identity verification involved a seemingly 19 year old dude looking at my ID and then signing a piece of paper. A website sending you an email and tracking your IP and keeping a log... seems to be about the same level of trust to be honest.

Notaries are personally responsible for any misconduct with up to a felony criminal case for violations. Including not sufficiently verifying the identity of the person in front of them. Sure, most states will just slap them with a $500 penalty, but they'll also revoke the notary status pretty quickly.

I would like to re-emphasize personally. It's not a business risk, it's a personal liability.

Re: Docuseal: Open-source DocuSign alternative

#173

Earlier quoted context omitted.

Like a chain of blocks? Where each block is signed by adding a prefix that produces an increasingly difficult hash?

Wait... You're talking about Git, right? Brilliant idea! You could sign a pull request, and once it's signed, you can then merge the businesses. But how do you show a diff of the signature? And what if it's not for a corporate merger?

But what keeps someone from forking your git repository and insisting that their HEAD is the source of truth? How can we get a globally agreed upon source of truth?

Re: Docuseal: Open-source DocuSign alternative

#174
post #138

Earlier quoted context omitted.

Of course it is applicable. The Docusign users failed to use it in a way that would be legally valid. If you have a more recent case that seems relevant or invalidates that result, post it. Otherwise I'm not sure what being 7 years old has to do with anything.

You're attempting to make a mountain of a single instance, years ago, of an electronic signature being rejected by a non-judicial officer in a quasi-judicial proceeding and trying to make it out like a general policy when it is so rare an exception that no court before or since has ruled against the consensual use of electronic signatures by the parties. If you have any evidence that electronic signatures can't be us…

> If you have any evidence

I never claimed I did, and I have no interest in talking to someone intent on making up crap that I never said, so I'm going to ignore you now. Life is too short to put up with bad-faith bullshitters.

Re: Docuseal: Open-source DocuSign alternative

#175
post #11

Hi everyone, my name is Alex and I'm the creator of DocuSeal. I was not happy with the existing mainstream document signing solutions so I decided to create an open-source alternative. I've been working on this project since the middle of May and here is what the tool can do so far: - PDF form fields builder - 10 field types available (Signature/Date/File/Checkbox etc) - Multiple submitters per document - Automated e…

Thank you for creating this and making it open source. What mechanism(s) is used to ensure non-repudiation? I appreciate that the demo is not behind a sign up wall, but is account creation and email verification required for invitees to sign any documents? Are IP addresses stored as part of the digital signature? Any other mechanism?

Only if we can use our Yubikey to sign the document...

Re: Docuseal: Open-source DocuSign alternative

#176

Earlier quoted context omitted.

Thank you for creating this and making it open source. What mechanism(s) is used to ensure non-repudiation? I appreciate that the demo is not behind a sign up wall, but is account creation and email verification required for invitees to sign any documents? Are IP addresses stored as part of the digital signature? Any other mechanism?

Only if we can use our Yubikey to sign the document...

[deleted]

Re: Docuseal: Open-source DocuSign alternative

#178
post #49

Earlier quoted context omitted.

Thank you for creating this and making it open source. What mechanism(s) is used to ensure non-repudiation? I appreciate that the demo is not behind a sign up wall, but is account creation and email verification required for invitees to sign any documents? Are IP addresses stored as part of the digital signature? Any other mechanism?

One of the tough things about a party-controlled, self-hosted e-signature is that it becomes easier to repudiate because a party to the contract has custody of the platform. The non-custodial party can claim they never signed, and when the custodial party produces evidence of IP address and timestamp, the non-custodial party may have a credible argument that they are faked and the person asserting those authenticated…

Yeah, I really like this initiative, but this is not a technology problem. This is a trust problem. The EUJ actually has a not-terrible framework in place around electronic signatures, and _some_ countries are pushing hard for adoption and implementation.

Re: Docuseal: Open-source DocuSign alternative

#180
post #64

Earlier quoted context omitted.

This may be german law specific, the overarching EU Legislation can be found by googlign "qualified electronic signature". In general they require complete, verified cryptographic signatures via smartcards or similar but because no one uses it, videoident has become the defacto alternative in germany

Most physical bearers (smart card or similar) of a Qualified Certificate are issued in person or based on a known identity. Here there is no need for remote identification before the issuance of the certificate. What you are talking about is a “remote signature service”. Such a service will often onboard a user remotely using a physical ID, video and liveliness checks and give them the credentials to produce advanced…

> But what level of signature is needed for what transactions is not regulated in the eIDAS.

Yeah, its the issue that germany decided that only the QES is as legally binding as a physical signature and then they made a whole bunch of contracts, especially work related stuff require physical signatures

Post reply on HN