The European Union is updating its electronic signature laws
theverge.com
theverge.com
1) software or plugins for signing should be available for free
2)All authorities have to accept same key (here in my country is huge problem with this. Governement offices and institutions accept different keys. Banks doesnt accept anything at all.)
3) Connected systems needs to be automated. its not acceptable to have manual verification and 12 hours sync between e-private-mailboxes (not fully related to esign).
4) if i can send form signed with e-signature it has to be delivered with appropriate automated feedback (meesage delivered,accepted,rejected)
5) they force users to use windows, internet explorer and expensive software, timestamps.
You mean _internationally_, right, or did I miss something?
It would only work intra-nationally (scoped to the member states of the EU (as an oversimplification)).
- "international" = "between nations"
- "intranational" = "within a nation"
Right?
AFAIK, Norway and Israel are the only two countries that require an electronic signature be done by a certified secure hardware element. And I think that's the right way.
According to eIDAS this can be replaced with much more weaker forms like server-side keys and signature after 2FA. And this is where folks from DocuSign (and others) will come in and place cryptographic signature on documents exchange for username+password+click (maybe with 2FA, I doubt that).
So you formerly needed smartcard (possession) with PIN (knowledge). Now you may only need username+password (knowledge) and maybe a second factor like mobile phone. I doubt that having control over a smartphone is on the same security level as control over a class 2/class 3 smartcard reader.
For German speaking people, you have some pretty well put together documentation on the new eIDAS directives here: https://www.bsi.bund.de/DE/Themen/DigitaleGesellschaft/eIDAS...
As far as I can see, any signature that is/appears to be qualified (regardless how it came to life) is considered equal to a signature under notary oversight (at least in germany) and shifts the burden of proof. This is heavy!
Then their talk about timestamping makes me think maybe there's a blockchain involved?
There's not blockchain; entities can simply sign a timestamp to a document, and then people and other entities can either trust it or not. From what I understand, a private company can be licensed as an "verified" timestamper, and then sell its services to other companies or individuals.
Note: It will probably help that the best providers of inexpensive, secure IC's are European and already all over those markets.
So long as other bank protections are in place, it shouldn't be a step backwards. If it's used to move all liability to the consumer though, then it's a problem.
Example for other readers on p4 under Luna PCI and Igenico reader that looks like it's a kid's pocket calculator haha:
https://www.keyon.ch/de/Produkte-Loesungen/SafeNet-HSM/HSM_T...
http://www.smartcardsource.com/contents/en-ca/Ingenico_myleo...
https://www.microsoft.com/en-us/research/wp-content/uploads/...
The recommended "solutions" all of which were being used at least somewhere in the mortgage industry were convoluted processes around people either drawing their signatures with their mouse, uploading a scan of their signature as a picture, or, the most ridiculous, just typing their name and then (optionally) choosing a cursive font so it looks like a fancy signature.
This, of course, is robbing the signature of all of it's original intent of reproducability by just a single person to, you know, prove that you signed yourself, and replaces it, usually, with the ability to receive mail to a certain email address and might as well just consist of a "secure" link to the document and an OK button.
All of these solutions were claimed to be legally binding according to the ESIGN act [0].
I am really glad we ended up not integrating.
[0] https://en.wikipedia.org/wiki/Electronic_Signatures_in_Globa...
Signatures became common as a legal formality in an age when many people were illiterate and signed their name with an "X" (which is still legal in the US). As with everything else in the US, there's a ton of racial history around the "X" signature that isn't relevant here, other than it's been known for hundreds of years that a plain signature isn't enough to verify the identity of the signer.
Instead, the signature came about as a formality to make clear to everyone involved that the person signing a document intended it to have legal effect. It's the difference between writing a note saying "I'll sell you my house for $100" and a signed contract --- there might be a question whether you intended the note to be binding, but there's no question that you intended a signed contract to be binding.
[fn] By contrast, things like signet rings that were able to produce easy-to-verify but hard-to-copy wax impressions have been used for identity verification. Same for name stamps in certain parts of the world.
(edit: stray formatting)
> If you agree to buy this house for $100, just click reply, type your name and then hit send.
All the fancy PDF displays and contract-signing-skeumorphisms just create a fuzzy-warm feeling, but don't actually do anything.
Which seemed a little odd to me as a way to authorize parts of a mortgage.
Additionally, while the "original intent" is reproducibility, it's not really difficult to duplicate a signature, and physical signatures are only really secure with neutral, third-party human witnesses.