Earlier quoted context omitted.
Sure, but do you have any indication cryptography is involved in this process? In my (limited) experience as a consumer, they just take some existing PDF and add marks on top of it.
Here in Norway, I've had to use my banks 2-factor BankID[1] to sign my loan, house purchase contract etc. According to their documentation[2] it absolutely relies on cryptography, including SEID-SDO[3] [1]: https://www.bankid.no/bedrift/bankid-signering/ [2]: https://confluence.bankidnorge.no/confluence/pdoidclc/techni... [3]: https://www.nets.eu/developer/E-Signing/overview/Pages/Signe...
Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
91–100 of 158 posts
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#92> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…
At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value. [0] https://en.wikipedia.org/wiki/EIDAS
While I am sure that clause can be nulled and voided if it came to that, the fact that the responsibility is on the signee is terrible.
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#93Earlier quoted context omitted.
In the UK at least it you email agreeing to terms and then appear to be complying you're unlikely to get out of it. Common examples are someone is sent a contract of employment unfortunately often after starting and they don't sign it. If they have been coming into work broadly in line with that contract so long as it's fair, employee and employer are bound by it. Here is an interesting edge case in the UK [0]. Long…
I don't know about other places; but in the UK, a contract doesn't even have to be written down, let alone signed. Of course, an unwritten contract is no more valuable than the paper it's (not) written on; and either party can dispute the terms. But you can still make a valid contract with a verbal agreement and a shake of hands. But don't do this unless you trust your co-contractor!
It mostly depends on how quickly courts will do the proceedings to establish that it is or isn't so.
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#94Earlier quoted context omitted.
At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value. [0] https://en.wikipedia.org/wiki/EIDAS
I’ve found the per-country overview of general legality of digital signatures on DocuSign [0] quite informative. As an example, in DK an email constitutes a valid contract for most purposes. [0] https://www.docusign.com/products/electronic-signature/legal...
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#95Earlier quoted context omitted.
"The current system works well enough" is a poor justification to avoid technological progress. I imagine people said the same thing about automobiles during the era of horses & buggies... yet here we are. A much better argument is the indelible nature of physical signatures. But even that factor has pluses & minuses in an increasingly-digital world. If anything, we need digital signatures - e.g. to watermark origina…
On the contrary, "Progress" is a poor justification for complexity. To justify change, especially change that adds complexity and cost, there needs to be a problem that needs solving or an opportunity to make things better, where better means "cheaper" or "easier" or "simpler" or "fails less." Progress that doesn't make things better for somebody isn't progress, it's Juicero. If there isn't any notarization fraud out…
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#96Earlier quoted context omitted.
>Emails don’t provide that legal value. In Italy there is an officially legislated signed email service that has legal value
The service probably has nothing to do with email and is only tangentially related to eIDAS. At least that is the case in Czech Republic. One surprising fact about such systems is that they tend to produce blockchain-like audit log and predate bitcoin by several years.
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#97Earlier quoted context omitted.
On the contrary, "Progress" is a poor justification for complexity. To justify change, especially change that adds complexity and cost, there needs to be a problem that needs solving or an opportunity to make things better, where better means "cheaper" or "easier" or "simpler" or "fails less." Progress that doesn't make things better for somebody isn't progress, it's Juicero. If there isn't any notarization fraud out…
Managing electronic signatures (e.g. DocuSign & file storage) is a 10x improvement for me compared to printing, signing, mailing or faxing, and file cabinets. The complexity & reduced costs are definitely worth it. YMMV.
Basically, compared to hand-written signatures, they are strictly less secure and a demonstration of how technology makes forgery easier.
Would you like it if your bank accepted transfer orders through DocuSign?
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#98Earlier quoted context omitted.
I think the main point the parent comment is making is that, today and historically, the great majority of contract disputes today don't involve disputing (analog or digital) signatures. People usually dispute about all the other terms rather that about the act of having signed it. [Even though analog signatures aren't particularly secure either] However, if Microsoft signatures have now became more forgeable at scal…
The question of signing generally arises with dueling forms, where there's no dispute that "a" 20-page contract was signed on June 4, 2017, and that this is page 20, with all of the signatures, but... What did that contract say in Paragraph G on Page 12? Perhaps the bank only retained page 20, and is saying that they used the same master form for every mortgage and the master form says "this" on page 12. Or one party…
They accepted my copy verbatim and scanned it right into their DMS, despite the fact that my revision was older than the internal revision it was tagged under. They scanned the -whole- document though, so the language on the signed copy is crystal clear.
The banker’s remark: “that’s unusual, no one ever asks for a copy of them signed.”
Edit: my initial draft was a grammatical mess up top
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#99> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…
The occurrence of fraud is so low, it’s better to just have non crypto signatures for legal docs and then contest when necessary.
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#100Earlier quoted context omitted.
Same thing with the notarization system. Is the notary system foolproof? Absolutely not! Imagine how much better notarizations could be with a bit of technology around it. A digital notary could take a photo of your document, register a hash/summary/thumbnail in realtime, and make it so that backdating or changing the document after the fact is a technical impossibility. What do we use instead? A guy who's probably e…
"The current system works well enough" is a poor justification to avoid technological progress. I imagine people said the same thing about automobiles during the era of horses & buggies... yet here we are. A much better argument is the indelible nature of physical signatures. But even that factor has pluses & minuses in an increasingly-digital world. If anything, we need digital signatures - e.g. to watermark origina…
It’s not that techno-notaries wouldn’t have benefits, it’s that they wouldn’t have much benefit over the current system.
Also, digital notaries aren’t required to do things like signing images or even documents or commits or whatever.
I would just hate if all my documents requiring a notary suddenly required enotaries.