4 ms·
These signature services make no sense. My UK estate agent is trying to get me to use an American signature service to renew my lease. - What I get is an emai
by buckminster 6y ago
These signature services make no sense. My UK estate agent is trying to get me to use an American signature service to renew my lease.
- What I get is an email from a third party (the signature service) with whom I have no business relationship. Why would I trust anything they say?
- How do I know the agent has signed the lease?
- What can I do if the American service claims I signed a contract when I didn't? If I sign even a single contract with them I'm effectively giving them power of attorney to accept any contract on my behalf.
- Anyone who gains access to my email can enter contracts on my behalf.
It's mad.
The point of signing a contract in each other's presence is that both parties understand they are agreeing to something, and both have no doubt that the other is also entering the agreement. Online signature services do not achieve this.
And finally, PKI is worse. I won't rehearse the arguments. Read Ross Anderson.
- hedora 6y agoWe refinanced during the pandemic with $MEGABANK, and they almost exclusively used third parties and email for the entire transaction. The last step was a total stranger (employed by another subcontractor we’d never heard of) stopping by our house and notarizing each signature in the closing paperwork. There was a day or two where we’d directed the previous lender to transfer title, and had already wired $100K’s to an unknown escrow service half a state away. I didn’t sleep all that well until the previous lender said they’d received a wire for the amount due on the loan. It’s not surprising that, among the paperwork we signed, there were multiple FBI notices about avoiding wire fraud. Note that PKI didn’t help much with this transaction. All “secure” communications were delegated to entities that I had no reason to trust (e.g., subdomain.docusign.com). I did check some license numbers here and there, and called the phone numbers the license holders registered with the government. So, the SSL cert on the .gov site helped (though even that is hit or miss, since it relies on domain registers confirming all the sites they allow are actually government entities.) I also called the office number I found at $MEGABANK’s website to make sure they’d heard of me. Beyond that, I had no reason to think $TOTALLY_LEGIT_ESCROW.com was not a phishing front.
- Edmond 6y agoThe use of PKI referred to in the article isn't about domain names. PKI can be used for trust projection and verification beyond domain names, that is what the article refers to.
- hedora 6y agoMy point is that banks are already abusing existing trust projection and verification mechanisms in consumer-hostile ways. How would giving them even more expressive mechanisms for delegation of trust to third parties improve this situation? Edit: I say that it is “consumer hostile” because they’ve used PKI and contract law to construct a complicated system of subcontractors that allows them to process mortgages without ever providing a single cryptographic proof that anyone involved in the transaction is a representative of the bank. (And the result is that many people have recently lost their homes to fraud.)
- deleted 6y ago[deleted]
- woah 6y agoIt’s hard for programmers to understand signatures and law in general, because it is somewhat similar to programming but with very different rules. The signature is just evidence of an agreement between you and the other party. It is not the only thing that matters. For example, if someone forged your signature on some paper transfer documents, would they then be able to move into your house? No. In your scenario, it sounds like you’re worried about the third party signature service colluding with the other party and putting some terms in the contract that you didn’t agree to, while displaying the original contract to you when you sign? If this is a genuine worry, just screenshot the document as you sign it. If the other party then tries to enforce these fraudulent terms, you can use the screenshots as evidence of the fraud. There may then be a criminal investigation, and everyone involved in the fraud may go to jail.
- buckminster 6y agoI understand perfectly well that if it goes wrong I will, most likely, be able to unpick the damage. But I also understand that this can take years and lots of money. Especially if the signature service is in a different country. So-called identity theft is a real problem. My particular concern is that I believe I'm entering into a tenancy but then discover, due to some bug in the software, that the landlord never actually entered the agreement. At this point the landlord can legally evict me if, say, he gets a better offer. What can I do about this? Edit to explain a detail of English law: this is a lease renewal. It isn't necessary for my continued occupation, but without it I have no security of tenure.
- woah 6y agoNobody is going to risk jail time to just get a slightly better rent on an apartment or something. There are much better ways to make money if you’re willing to go to jail for fraud. The problem you are concerned about is not a problem.
- matthewheath 6y agoThe court will take into account more than just the lack of the landlord's signature on an electronic document. They will look at the intention between you two, as well as any correspondence between you and the landlord's agents. A contract does not have to be written to exist, although it certainly helps. An oral agreement that you'll continue in the lease and will treat the document as a formality would suffice. There will be evidence you will be able to adduce in your favour beyond this signature service. Furthermore, there are strict rules around eviction; the landlord can't immediately evict even when you're not on an AST.