Live data from Hacker News

Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

usenix.org

91–100 of 158 posts

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#91
post #17

Earlier quoted context omitted.

Sure, but do you have any indication cryptography is involved in this process? In my (limited) experience as a consumer, they just take some existing PDF and add marks on top of it.

Here in Norway, I've had to use my banks 2-factor BankID[1] to sign my loan, house purchase contract etc. According to their documentation[2] it absolutely relies on cryptography, including SEID-SDO[3] [1]: https://www.bankid.no/bedrift/bankid-signering/ [2]: https://confluence.bankidnorge.no/confluence/pdoidclc/techni... [3]: https://www.nets.eu/developer/E-Signing/overview/Pages/Signe...

That's interesting, thanks, but I am specifically interested in the US (like the thread I was responding to).

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#92
post #12
post #11

> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…

At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value. [0] https://en.wikipedia.org/wiki/EIDAS

Which makes attacks like these even worse: Serbian law, for instance, has a clause how you are not allowed to dispute an electronic signature signed using an officially issued eID certificate.

While I am sure that clause can be nulled and voided if it came to that, the fact that the responsibility is on the signee is terrible.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#93

Earlier quoted context omitted.

In the UK at least it you email agreeing to terms and then appear to be complying you're unlikely to get out of it. Common examples are someone is sent a contract of employment unfortunately often after starting and they don't sign it. If they have been coming into work broadly in line with that contract so long as it's fair, employee and employer are bound by it. Here is an interesting edge case in the UK [0]. Long…

I don't know about other places; but in the UK, a contract doesn't even have to be written down, let alone signed. Of course, an unwritten contract is no more valuable than the paper it's (not) written on; and either party can dispute the terms. But you can still make a valid contract with a verbal agreement and a shake of hands. But don't do this unless you trust your co-contractor!

In most places, if there are witnesses to a contractual obligation being established or contract being performed, even a verbal agreement can be sufficient.

It mostly depends on how quickly courts will do the proceedings to establish that it is or isn't so.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#94
post #12

Earlier quoted context omitted.

At least in Europe, electronic signatures of a certain form are legally equivalent to handwritten signatures [0], and are increasingly used as such. Emails don’t provide that legal value. [0] https://en.wikipedia.org/wiki/EIDAS

I’ve found the per-country overview of general legality of digital signatures on DocuSign [0] quite informative. As an example, in DK an email constitutes a valid contract for most purposes. [0] https://www.docusign.com/products/electronic-signature/legal...

Even if I spoof it? ;)

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#95
post #84

Earlier quoted context omitted.

"The current system works well enough" is a poor justification to avoid technological progress. I imagine people said the same thing about automobiles during the era of horses & buggies... yet here we are. A much better argument is the indelible nature of physical signatures. But even that factor has pluses & minuses in an increasingly-digital world. If anything, we need digital signatures - e.g. to watermark origina…

On the contrary, "Progress" is a poor justification for complexity. To justify change, especially change that adds complexity and cost, there needs to be a problem that needs solving or an opportunity to make things better, where better means "cheaper" or "easier" or "simpler" or "fails less." Progress that doesn't make things better for somebody isn't progress, it's Juicero. If there isn't any notarization fraud out…

Managing electronic signatures (e.g. DocuSign & file storage) is a 10x improvement for me compared to printing, signing, mailing or faxing, and file cabinets. The complexity & reduced costs are definitely worth it. YMMV.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#96
post #87

Earlier quoted context omitted.

>Emails don’t provide that legal value. In Italy there is an officially legislated signed email service that has legal value

The service probably has nothing to do with email and is only tangentially related to eIDAS. At least that is the case in Czech Republic. One surprising fact about such systems is that they tend to produce blockchain-like audit log and predate bitcoin by several years.

Append-only stores of record predate "blockchain" by decades: a distributed trust/consensus algorithm is the real innovation in Bitcoin.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#97
post #95

Earlier quoted context omitted.

On the contrary, "Progress" is a poor justification for complexity. To justify change, especially change that adds complexity and cost, there needs to be a problem that needs solving or an opportunity to make things better, where better means "cheaper" or "easier" or "simpler" or "fails less." Progress that doesn't make things better for somebody isn't progress, it's Juicero. If there isn't any notarization fraud out…

Managing electronic signatures (e.g. DocuSign & file storage) is a 10x improvement for me compared to printing, signing, mailing or faxing, and file cabinets. The complexity & reduced costs are definitely worth it. YMMV.

DocuSign is a very weak signing system: signatures it produces are forgeable by anyone getting even a temporary access to an email (eg sitting on an unlocked computer or grabbing an unlocked phone), and the graphical part is something anyone can't replicate twice, unless you use one of their fonts making it even more easily forgeable. I don't even remember seeing an option to say that a particular email should always use a specific form (eg drawing of a signature).

Basically, compared to hand-written signatures, they are strictly less secure and a demonstration of how technology makes forgery easier.

Would you like it if your bank accepted transfer orders through DocuSign?

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#98
post #21

Earlier quoted context omitted.

I think the main point the parent comment is making is that, today and historically, the great majority of contract disputes today don't involve disputing (analog or digital) signatures. People usually dispute about all the other terms rather that about the act of having signed it. [Even though analog signatures aren't particularly secure either] However, if Microsoft signatures have now became more forgeable at scal…

The question of signing generally arises with dueling forms, where there's no dispute that "a" 20-page contract was signed on June 4, 2017, and that this is page 20, with all of the signatures, but... What did that contract say in Paragraph G on Page 12? Perhaps the bank only retained page 20, and is saying that they used the same master form for every mortgage and the master form says "this" on page 12. Or one party…

Asking for a copy of the signed documents for my corporate bank account was how I discovered that my bank’s internal processes were using one revision, and the forms they ask you to download and fill out ahead of time were a different revision, despite being the same (uniquely numerically identified) form.

They accepted my copy verbatim and scanned it right into their DMS, despite the fact that my revision was older than the internal revision it was tagged under. They scanned the -whole- document though, so the language on the signed copy is crystal clear.

The banker’s remark: “that’s unusual, no one ever asks for a copy of them signed.”

Edit: my initial draft was a grammatical mess up top

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#99
post #11

> For documents of prime importance, such as contracts and invoices Few in the legal world actually use cryptographic signatures for signing things. It's vastly more common to use scanned hand signatures or just /s/ and an e-mail record of sign off. Why? Because it has worked that way for hundreds of years. It's pretty uncommon for there to be a dispute about the fact of signature, and even if there is, cryptographic…

I really like how preview has an image signature feature now and it seems to pass whenever people need a doc signed.

The occurrence of fraud is so low, it’s better to just have non crypto signatures for legal docs and then contest when necessary.

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#100
post #84

Earlier quoted context omitted.

Same thing with the notarization system. Is the notary system foolproof? Absolutely not! Imagine how much better notarizations could be with a bit of technology around it. A digital notary could take a photo of your document, register a hash/summary/thumbnail in realtime, and make it so that backdating or changing the document after the fact is a technical impossibility. What do we use instead? A guy who's probably e…

"The current system works well enough" is a poor justification to avoid technological progress. I imagine people said the same thing about automobiles during the era of horses & buggies... yet here we are. A much better argument is the indelible nature of physical signatures. But even that factor has pluses & minuses in an increasingly-digital world. If anything, we need digital signatures - e.g. to watermark origina…

Technology should be weighing the benefit against the cost.

It’s not that techno-notaries wouldn’t have benefits, it’s that they wouldn’t have much benefit over the current system.

Also, digital notaries aren’t required to do things like signing images or even documents or commits or whatever.

I would just hate if all my documents requiring a notary suddenly required enotaries.

Post reply on HN