5 ms·
From the link: "For bureaucratic reasons, a colleague of mine had to print, sign, scan and send by email a high number of pages. To save trees, ink, time, and
by jonchang 7y ago
From the link:
"For bureaucratic reasons, a colleague of mine had to print, sign, scan and send by email a high number of pages. To save trees, ink, time, and to stick it to the bureaucrats, I wrote this script."
So yes, it does seem like there are situations where a "digital" signature is insufficient.
- leesalminen 7y agoMy bank sometimes requires a “wet” signature and have rejected digitally signed PDFs from MacOS Preview before. This tool will come in handy.
- cgrand-net 7y agoMy bank used to reject scans but accept faxes... bureaucratic reasons.
- dd36 7y agoFaxes are considered secure.
- somehnguy 7y agoI'm declaring myself as considered a Triceratops . Doesn't make it true.
- swixmix 7y agoIt depends on the threat model. If I need to prove to a court in the US, then I'm signing paper and faxing it. To do it differently would be more expensive to prove.
- somehnguy 7y agoRight, the legal system considers it secure. I'm talking about the technical sense. Where there is no encryption at all, anyone with a phone line splitter can listen in, and the machines are usually not in a secured area so anyone could just pick up the fax and walk away. Not secure at all.
- monkpit 7y agoI don’t think you need to argue that fax is not technically secure on HN. Pretty sure we are all on the same page there. What matters is legal precedent and existing policy in various countries.
- loeg 7y ago> I don’t think you need to argue that fax is not technically secure on HN. Pretty sure we are all on the same page there. dd36 and swixmix seem to be taking the other side of that argument.
- dd36 6y agoIf I were taking that side, I wouldn’t have qualified my statement. Gov’t and courts consider it secure. HIPAA compliant, etc.
- bcoates 7y agoThey're secure in the sense of being low-risk for active content shenanigans and a small surface area for vulnerabilities. Attacking a network through a .tiff of a fax is a lot harder than attacking it through an email, pdf, word doc, http session, etc.
- jkaplowitz 6y agoIt depends on what your threat model is. The attacks you're talking about are real, absolutely. For the threat model of a physically local attacker with either the right timing (for grabbing an incoming fax) or the right knowledge (for the phone system equivalent of tcpdump), you're quite right that fax is insecure. Likewise for state sponsored adversaries or certain organized crime groups. But if you just want to make it hard for people scanning the internet to see what juicy corporate espionage they can find and resell, without specifically targeting you, fax is probably less vulnerable to that threat model than, for example, an undermaintained email server. Likewise if you piss off script kiddies somewhere on the internet with botnets and exploit kits, your website is probably a bigger risk than your fax machine.
- cortesoft 7y agoIf you pass a law stating you are a Triceratops, it would become 'true' in the legal sense... and since we are dealing with legality, it being declared 'secure' does matter
- yourapostasy 7y agoBehold...the power of lobbyists. Fax industry sure got their money's worth that year that passed.
- recursive 7y agoI don't know directly, but I've heard that there are special laws regarding fraud via fax. Even though fax has no technical protection, it may have legal ones, that might give the counterparty some recourse if things went bad.
- Xylakant 7y agoIn Germany, a fax is legally considered an original copy, a scan/print is not, despite a fax often being a scan that’s then transmitted via fax protocols. Law hasn’t caught up with technology yet in that area. You also get a confirmation from the recipient when using fax.
- detaro 7y agoAll the while we actually have a pretty good law about digital signatures since basically forever, but ~nobody supports those. (and they missed the chance of using the new ID cards to establish them more widely, which was really stupid)
- derefr 7y ago> despite a fax often being a scan that’s then transmitted via fax protocols ...what's the alternative to that "often"? What is a fax machine, if not a scanner attached to a modem?
- anonymfus 7y agoConventional fax machine transmits document while it scans it as it has (almost) no memory. Like analog TV camera, just much slower.
- derefr 7y agoSure, but that's still "a scanner attached to a modem." Nothing about a scanner implies that it must buffer the input, just like nothing about a printer implies that it buffers the output. There are/were "line printers" doing "latch a character from the input line, print the character, unlatch" serial output (which were so common that Unix pipes are designed around the foibles of outputting to such devices.) Most POS thermal receipt printers are still line printers! I don't know as much about scanners, but I can't imagine that the original (digital, attached to a computer) scanners weren't also "serial scanners"—i.e., rather than a 1D scan head with a long CCD strip that could latch an entire line at a time into a shift register, they would have had 2D scan-heads that would scan one pixel at a time, in a "read brightness, signal ready, wait for return line to unlatch" serial loop. No memory required, just terribly slow.
- wayoutthere 7y agoSounds like their document management system was tied to a fax line and they didn't want to bother upgrading. IT departments at banks have like, zero budget.
- qubex 7y agoI read on NH yesterday (or perhaps the day before) that in the USA HIPAA (Health Insurance Portability & Accountability Act 1996) carves our a special exemption to consider faxes ‘secure’.
- loeg 7y agoIt does.