4 ms·
IP addresses and browser User Agent strings are stored for each signature/submission - those are the only measures for 'non-repudiation' currently available. b
by somery 3y ago
IP addresses and browser User Agent strings are stored for each signature/submission - those are the only measures for 'non-repudiation' currently available.
but i think it doens't differ from other mainstream SaaS solutions - if you read through their terms of services - they put 'non-repudiation' liability on users of their services
- dtx1 3y agoThose are both unfortunatly trivially faked
- infogulch 3y agoAnd yet it's the standard practice for normal people.
- dtx1 3y agoFrom my research this has 0 legal validity, at least in germany in regards to the EU eIDAS. They are just smoke and mirrors for companies to make them "feel" secure but without cryptographic ensurances (Advanced Electronic Signature) or TLS like Signed Cryptography (Qualified Electronic Signature) this is just as legally binding or not binding as an E-Mail
- V__ 3y ago> just as legally binding or not binding as an E-Mail Which is legally binding. In Germany most contracts are free-form contracts (Formfreiheit) and only need declarations of intent in the form of offer and acceptance. This can be a handshake or even a head shake.
- infogulch 3y agoOr perhaps even an emoji reaction in a text chat, as described elsewhere itt.
- etothepii 3y agoUnless you are a qualified lawyer it would be polite to begin a comment like this with IANAL. IANAL but in the common law world a contract requires 3 things: * Offer and acceptance * Consideration (something of value) * An intention to form legal relations. Acceptance is, of course, what a signature signifies. Acceptance is "a matter of fact" and thus in reality pretty much anything will do.
- TheNewsIsHere 3y agoYeah, it’s not like in the spirit of the law you can perform your part of the contract and then get away with saying “I never agreed”. In the US, we have a federal law that covers electronic contract signing. I believe it’s part of the UCC? (I’m not an attorney, and that area isn’t one I practice with in tech either.)
- _ea1k 3y agoSignatures are pretty easy to fake too, because basically noone verifies them. In practice, the security involved only has to reach the "good enough" threshold and not a 100% hack proof level.
- rgarcia 3y agoAnother method you might consider implementing would be identity verification via SMS code. I've experienced this with docusign: https://support.docusign.com/s/document-item?language=en_US&rsc_301=&bundleId=gav1643676262430&topicId=kzp1578456318101.html&_LANG=enus https://support.docusign.com/s/document-item?language=en_US&... It requires you to know the phone number of the signer, but for important stuff you typically do.
- somery 3y agoYep, support for SMS verification will be added eventually with ability to bring own Twilio credentials when self-hosting it.