"For bureaucratic reasons, a colleague of mine had to print, sign, scan and send by email a high number of pages. To save trees, ink, time, and to stick it to the bureaucrats, I wrote this script."
So yes, it does seem like there are situations where a "digital" signature is insufficient.
I'm talking about the technical sense. Where there is no encryption at all, anyone with a phone line splitter can listen in, and the machines are usually not in a secured area so anyone could just pick up the fax and walk away. Not secure at all.
dd36 and swixmix seem to be taking the other side of that argument.
For the threat model of a physically local attacker with either the right timing (for grabbing an incoming fax) or the right knowledge (for the phone system equivalent of tcpdump), you're quite right that fax is insecure. Likewise for state sponsored adversaries or certain organized crime groups.
But if you just want to make it hard for people scanning the internet to see what juicy corporate espionage they can find and resell, without specifically targeting you, fax is probably less vulnerable to that threat model than, for example, an undermaintained email server. Likewise if you piss off script kiddies somewhere on the internet with botnets and exploit kits, your website is probably a bigger risk than your fax machine.
You also get a confirmation from the recipient when using fax.
...what's the alternative to that "often"? What is a fax machine, if not a scanner attached to a modem?
There are/were "line printers" doing "latch a character from the input line, print the character, unlatch" serial output (which were so common that Unix pipes are designed around the foibles of outputting to such devices.) Most POS thermal receipt printers are still line printers!
I don't know as much about scanners, but I can't imagine that the original (digital, attached to a computer) scanners weren't also "serial scanners"—i.e., rather than a 1D scan head with a long CCD strip that could latch an entire line at a time into a shift register, they would have had 2D scan-heads that would scan one pixel at a time, in a "read brightness, signal ready, wait for return line to unlatch" serial loop. No memory required, just terribly slow.
> fax machines were purely analog devices, not a scanner attached to a modem
Why would an analog scanner not still be a scanner? I'd call whatever component that's in even the oldest fax machines "a scanner." Even if it is "enitrely analog" (continuous brightness intensity read, like a tape head or record-player stylus) you'd still call the process of converting light from a sensor passing over a document, into electricity, scanning, and you'd still call the component that does that "a scanner." Just like speakers and microphones are still "speakers" and "microphones" whether they're just transducers attached to wires, or have a whole ADC+USB/Bluetooth signal path leading out of them. Am I wrong?
As I had opened account with them years back, I couldn’t recollect what I had signed then. The clerk at the desk helpfully turned her display for me to take a quick glance at the signature in the file which I copied in the form. Thanked her well.
Dropbox's "Scan Document" feature is great for getting around that. It turns a photo into what looks exactly like a scan. I just sign the document in Preview, and then use the Scan Document feature to just "scan" the document as its displayed on my screen. The result seems indistinguishable from a printed wet ink copy also scanned with Dropbox.
I can set up Apple Pay and use it across devices to make payments worth tens of thousands, but I can’t use the same technology to authenticate a document.
It really boils the blood.
I have a previously-scanned signature that I'd like to re-use. I'd love to simply import the file. Instead I have to print it out and then hold it in front of the camera, trying to get it aligned. It's madness. Is it supposed to be more secure for some reason?
For example, even just assigning everybody unique identifiers (social security number, drivers' license number) has allowed businesses to demand these identifiers to track customers in privately-held surveillance databases. This system has already grown out of control with little sign of stopping.
A "secure" e-signature token would lead to even more businesses demanding your "identity". Imagine having to pay twice as much for groceries for wanting to keep your purchases personal!
I'd much rather suffer the small work of (print, sign, scan, cache, burn) until I see some reigning in of private surveillance databases.
The federal government refuses to issue actual public IDs, which would solve the problem nicely, for political reasons. They can't retract Social Security.
Also, I like rasterized contracts / text, instead of a small pdf + an image, as it's easier to tamper with
I used Preview for the longest time before they questioned 1 of the documents.