3 ms·
I was interested at first because I built a signature product a few years ago. I find it a bit confusing and had to reread to catch the point. There are 3 leve
by crails124 6y ago
I was interested at first because I built a signature product a few years ago. I find it a bit confusing and had to reread to catch the point.
There are 3 levels defined by the EU. I use these levels everywhere because it's not really a legal thing but increasing levels of technical requirement. The US has many conflicting laws on what signatures are valid.
The lowest level is what you first started out with. The marketing term for this is "E-signature". It's a subtle marketing speak to mean putting an image into a document. Theses are generally accepted for most things. California though has not allowed this in the past. A provider offers signatures at this level (with some nuance).
The second level is a "digital signature" backed up by other details. People think this means like an actual signature. In document contexts it's very confusing. But what they really mean is signing (encrypting with your private key so the public can decrypt it). This can be a verified email, phone, the more the better. What's important is at this level the signer is not actually the person, it's the service. The service has a trusted cert created from the Adobe trust chain and does additional measures to verify the person. The visible signature at this point is just a mock to make people comfortable using it. The signature is really cryptographic. This level is pretty much always court admissible.
The last level is signing the doc with your own trusted cert. You can get these tokens from many providers to do yourself. It's required for typically government things like stamping a document by an actual engineer (ie a PE). To get these certs you need to go to a notary to get verified. This is as legit as it gets. It's almost bulletproof.
Product wise, I am pretty familiar with PKI but am still confused as to what it really does or why I should use it. If this is to get wide adoption, the person using it needs to know nothing about certs and PKI. Additionally, I'm confused if this is using PKI or a web of trust. I'd think it would have to be web of trust to be practical but it seems like the examples allude more to PKI? Best of luck, I look forward to see where it goes.
- hedora 6y ago> What's important is at this level the signer is not actually the person, it's the service. Interesting. Does this mean that if a scammer uses docsign to phish me into a mortgage transaction, and I lose my house, then docusign is on the hook financially? Put another way: Are they legally required to sign on behalf of both (purported) parties of the contract in the case of a dispute? What if 99% of signatures are through them, and the last step is a fraudulent notary?
- Edmond 6y agoSend me an email (in my profile), I am interested in your perspective. PKI/Web of trust are just terminology around the usage of asymmetric key cryptography to solve certain problems. The service relies on third parties to perform verification and issue certificates, just as the domain name certificate authorities do. The difference is that the information on the certificate can be anything, not just domain names. Users use the Certisfy app to make use of those certificates, by making various claims against their certificates (think: location, age, name, even height:)..etc) Think of the app as a kind of trust projection and information verification toolkit/client made for ordinary consumers.