5 ms·
Why, why, WHY does no one even question the idea of graphic signatures to begin with? This thing where we scan a piece of paper or paste in a little image has
by negativity 14y ago
Why, why, WHY does no one even question the idea of graphic signatures to begin with?
This thing where we scan a piece of paper or paste in a little image has always smacked of forgery to me anyway? All I need is one image of your signature, and I can sign for you anywhere I want. It's like when they hand out rubber stamps for secretaries to use.
It's like somewhere along the line, wherever you see hand-written signatures still employed as a means of confirmation/verification, no one explained to the witless bureaucrats that accept them, that there may as well be an image of a spider cartoon.
For reference:
> http://en.wikipedia.org/wiki/David_Thorne_%28writer%29 http://en.wikipedia.org/wiki/David_Thorne_%28writer%29
> http://www.amazon.com/Internet-Playground-Irreverent-Correspondences-Online/dp/1585428817 http://www.amazon.com/Internet-Playground-Irreverent-Corresp...
> http://keboch.files.wordpress.com/2008/11/imagesspider-20as-20payment.gif http://keboch.files.wordpress.com/2008/11/imagesspider-20as-...
Wasn't the whole idea of hand-written signatures supposed to be a pattern where it's difficult to readily forge the distinctive handwriting style of a fluid fancy cursive-script signature? When you paste in an image, it's a cookie-cutter perfect match every time. Where's the authenticity?
Hand-written signatures have no place in digital documents as a secure means of authenticity. Why are they used at all?
In general, they should be replaced by digital/cryptographic mechanisms, but in most cases the underlying concepts are to hard for people to explain or understand.
When people use scanned signatures, it's like we're still stuck in the 1800's where if you were illiterate, placing your "X" on the dotted line was good enough for a binding contract.
Am I the only one who sees things this way? Am I alone here?
- Ecio78 14y agoNo, you are not alone. I've worked for banks and financial firms (in Italy) and I've always seen image signatures only used for sort-of-personally-signed communications (i.e. a letter from the CEO stating that we're changing conditions) but not for "real" contract signing. On other side, AFAIK, in our law simple plain text email (neither PEC nor s/mime signed email) and faxes are considered legal methods of communication and I cant really understand why (it is so easy to create fake email or faxes)
- notahacker 14y agoI used to receive renewal confirmation and acceptance of price increases for five figure licence agreements between big, traditional companies by plaintext email saying "I accept". It was treated as legally binding (though we did want bona fide signatures for the initial agreement) Some universally accepted unique private key is probably the way forward here...
- rokhayakebe 14y agoI thought this was awesome until I read your comment, now I am thinking it again. You are correct in saying this eases forgery. We should definitely rethink the whole thing. In a sense a signature is nothing other than authentication. I would be comfortable authenticating through my mobile phone and have that be the signature.
- deleted 14y ago[deleted]
- deleted 14y ago[deleted]
- relix 14y agoSignatures aren't a way to authenticate yourself securely. They're just a more definite version of a checkbox that says "I agree". They're not supposed to be secure, they are and always have been easy to forge. When was the last time someone checked the signature on your credit card? The only protection signatures offer is by law - it is forbidden to sign as someone else. These scanned/digital signatures are nothing new. People have been signing documents and faxing them (in effect copying them) since faxes exist. That's basically the same: nobody can tell if you just pasted a copy of a signature on the document before you faxed it, or if you really did sign it. In Estonia, the digital ID card enables people to digitally sign documents. There's a law that says these digital signatures are as valid as a handwritten signature, and must be accepted as such. It has become very popular [0]. To me it is a very smart idea to train your citizens to use digital signatures which are both more reliable and easier to verify. [0]: http://news.err.ee/sci-tech/16da12d4-ddca-43a5-b12f-024866e9da8c http://news.err.ee/sci-tech/16da12d4-ddca-43a5-b12f-024866e9...
- nicolas314 14y agoI am totally baffled that copy/pasting an image can be considered legally binding in 2013. Digital signatures with x.509 certificates have existed for ages now and these are rightfully legally binding anywhere in Europe. Please have a look at European laws about digital signature!
- zmmmmm 14y ago100% agree. This is almost like granting power of attorney to anyone who hacks your Gmail account, making the threshold for controlling your whole existence your Gmail password (or even your Gmail session if you stay logged in and don't 100% physically secure your computer every time you walk away from it). The video shows no extra authentication step when the signing occurs, which is particularly egregious. a) If it's legally binding like a real signature then I can't do it because it's far too risky b) If it's not legally binding like a real signature then it's useless The litmus test is what happens when a dispute arises in court over one of these signatures. If the defense "Somebody accessed my computer while it was logged in and fraudulently signed" is accepted then this thing is blown out of the water. No longer can the hand writing expert come in and testify whether it is in fact your writing. No longer will the fact that the signature is 100% identical to another document that you signed in the past be evidence that the signature was copied. All of the security features of "real" signatures are gone.