4 ms·
Digital document signing almost feels like it should be baked into email systems by now. Having a separate service to do this feel antiquated.
by Molitor5901 2y ago
Digital document signing almost feels like it should be baked into email systems by now. Having a separate service to do this feel antiquated.
- xnx 2y agoGoogle Workspace has it built in https://workspace.google.com/resources/esignature/ https://workspace.google.com/resources/esignature/
- verdverm 2y agoyup, I dropped Docusign when this landed.
- Molitor5901 2y agoWOW. Thank you, that is really great.
- DaiPlusPlus 2y ago> Digital document signing almost feels like it should be baked into email systems by now It is: S/MIME is well-supported. Anything else is not a "real" signature, as far as I'm concerned.
- gruez 2y ago>Anything else is not a "real" signature, as far as I'm concerned. Courts don't really care about ECDSA signatures or x509 certificates. They readily accept faxed documents, which are literally low resolution scans and are trivial to forge. Moreover "real" digital signatures still need key management, which is basically an unsolved problem in countries without government issued e-ids. What's the practical difference between docusign attesting that jonh smith signed a document on some web interface, and john smith signing a document with a s/MIME certificate issued by docusign?
- jfengel 2y agoLegally I don't think DocuSign will attest to anything. I wouldn't trust that for anything significant. It's only good when everyone is going in good faith. If there is a serious dispute you need lawyers.
- ggm 2y agoCame to say this. Courts have been dealing with intent vs proofs for a long time and the intent is central. Some jurisdictions used (maybe still do) stipulate real hand on real pen in real ink, sometimes even colour of ink. But at large, your intent to declare something by signing even with an "X" is taken as such. Obviously as a computer scientist I want a render of my sig as an image/logo to underpin "the SHA512 checksum of the input byte stream under these canonicalisation rules <here> applied to this use of my X.509 private key" but in fact, I just have a clip of my signature as a PNG which Apple's preview tool pastes as an image into PDF documents and I send them on, and its fine. Docusign is trash-theatre. Its secure because they say so. It may marginally add some value in some jurisdictions, I don't know. Remember in Scotland, verbal contracts are binding with no need to witness. Bizarre! A family member nearly sold the flat under-value except the buyer was kind about it and accepted it was unintentional language not a verbal acceptance of offer.
- dragonwriter 2y ago> Docusign is trash-theatre. Its secure because they say so. Docusign's system is designed very specifically around the legal requirements of the US federal E-Sign Act, which guarantee, for transactions in interstate or foreign commerce, that even if there is a statute, regulation, etc., on its face requiring a written agreement, the electronic signature will be treated as satisfactory. It did not become popular because it was viewed as particularly secure, it became popular because it was point-by-point checklist following the E-Sign requirements, and there are lots of entities who wanted to legal guarantees that come with complying with E-Sign. > Remember in Scotland, verbal contracts are binding with no need to witness. Bizarre! For most matters (there are some matters that legally--either by common law or statute--require a written contract) verbal contracts are binding without a need to witness in most common law jurisdictions (including the US); written and signed contracts are important even then because they provide evidence of both the content and the fact of the agreement, even when they are not required for a binding agreement to exist. Proving the existence and terms of an unwritten, unwitnessed contract when you want to take action over a breach by your counterparty can be tricky.
- mc32 2y agoSaaS are now adding e-sigs as a feature (Box, Google, etc.) Some workflows still need DS but it’s fewer and fewer. Box, I think, can be CFR11 compliant.
- tommasoamici 2y agoIt is CFR11 compliant. Source: I work on Box Sign.
- contravariant 2y agoPretty sure that with any email that has anti-spoofing set up correctly you could argue that a simple email reply would be equally valid.
- dragonwriter 2y agoI mean, you can argue anything, but there are a multiple things required by (e.g.) the Federal E-Sign Act in terms of both capabilities and content, and DocuSign is structured directly around that, and “any email that has anti-spoofing set up” is not. You could build a workflow around such an email system that met the E-Sign requirements, but there is a reason people choose packaged solutions that already do that.