The dubiousness of digitized signature services
blog.certisfy.com
blog.certisfy.com
The purpose of a signature is to inform the signer that they are entering a binding contract. It is simply the modern equivalent to a handshake.
Sadly, precedent around Eula’s mean that signatures are no longer necessary to execute contracts.
If anything, society would be better served by making it more difficult to enter into binding agreements than to make it less difficult.
Imagine if, by law, for a EULA to be binding, the end user had to scroll through the entire document, and initial each separate section. Eula’s would be much shorter, and much less common.
In a digital equivalent of “no trespassing” or “cameras in use signs” a few standard clauses could be made enforceable by displaying them prominently on each page. For instance, there could be a clauses such as “you are purchasing a transferrable non-exclusive license to this software”, or “your subscription to this service is at-will with a fixed rate of $N/time-unit.”
If you have a contract that obliges something from me, and it’s not my signature, you may be attempting fraud on me. See bankers and robo-signing. That is why I need to see, on your copy, my signature and any other personalizing marks that my original document contains.
I don't think this is the problem that these services solve.
Their purpose is to replicate the ritual of signing a document, to draw on the meaning of that tradition, so that that reasonable parties to an agreement understand there is a clear threshold that signifies the transition from negotiation to agreement, and all parties have a common version of the details of that agreement.
That all parties have a common version is exactly the point of the signature aspect. The idea of signing with ink is to have a personalized mark. Of course, with these services, the generic “signature” lacks the personalization.
The fact that many an agreement is pushed on the signer to be signed without reading it indicates that the mark is the important thing.
If pen-like inputs were more common, it would be easier to use one’s own mark. Of course, signatures are easier to fake in the all-digital realm too if you have a specimen you can copy-paste from.
Always keep a paper copy in case of disputes.
This sentence is correct but subtly conflates two elements, essentially contained in the respective words "signatory’s" and "acceptance":
* It proves the signatory's identity i.e. it was this person that agreed to the contract rather than some other person.
* It proves actual agreement i.e. this wasn't just a draft contract that we were still in the process of negotiating, but the final contract we had settled on.
If it came to court and the first one, identity, was in dispute then a signature is fairly unlikely to resolve that, at least on its own. But if the second point was in dispute "yeah I know I said that but it was conditional on blah blah other thing" then a signature on a contract makes that much harder to argue. The second one is very similar to what the parent comment said: the fact the signatory went through the ritual shows that they understood they were actually agreeing to precisely those conditions.
Our loop is around whether or not we can establish who the “we” was. The original commenter was making a statement about the purpose of a signature and I was stating a disagreement with that purpose. At very best, we need to recognize multiple purposes. But since contracts all come down to what is supported by a court of law, it needs to be the right signature. If you’re saying the presence of a signature is all that is necessary, it’s perfectly fine for you to create a contract in which I pay you money and assign some mark that says I agreed to it. But you better be a decent forger then. Some of the ritual elements are in place to protect against bad faith.
- What I get is an email from a third party (the signature service) with whom I have no business relationship. Why would I trust anything they say?
- How do I know the agent has signed the lease?
- What can I do if the American service claims I signed a contract when I didn't? If I sign even a single contract with them I'm effectively giving them power of attorney to accept any contract on my behalf.
- Anyone who gains access to my email can enter contracts on my behalf.
It's mad.
The point of signing a contract in each other's presence is that both parties understand they are agreeing to something, and both have no doubt that the other is also entering the agreement. Online signature services do not achieve this.
And finally, PKI is worse. I won't rehearse the arguments. Read Ross Anderson.
There was a day or two where we’d directed the previous lender to transfer title, and had already wired $100K’s to an unknown escrow service half a state away.
I didn’t sleep all that well until the previous lender said they’d received a wire for the amount due on the loan.
It’s not surprising that, among the paperwork we signed, there were multiple FBI notices about avoiding wire fraud.
Note that PKI didn’t help much with this transaction. All “secure” communications were delegated to entities that I had no reason to trust (e.g., subdomain.docusign.com).
I did check some license numbers here and there, and called the phone numbers the license holders registered with the government. So, the SSL cert on the .gov site helped (though even that is hit or miss, since it relies on domain registers confirming all the sites they allow are actually government entities.)
I also called the office number I found at $MEGABANK’s website to make sure they’d heard of me.
Beyond that, I had no reason to think $TOTALLY_LEGIT_ESCROW.com was not a phishing front.
How would giving them even more expressive mechanisms for delegation of trust to third parties improve this situation?
Edit: I say that it is “consumer hostile” because they’ve used PKI and contract law to construct a complicated system of subcontractors that allows them to process mortgages without ever providing a single cryptographic proof that anyone involved in the transaction is a representative of the bank. (And the result is that many people have recently lost their homes to fraud.)
The signature is just evidence of an agreement between you and the other party. It is not the only thing that matters. For example, if someone forged your signature on some paper transfer documents, would they then be able to move into your house? No.
In your scenario, it sounds like you’re worried about the third party signature service colluding with the other party and putting some terms in the contract that you didn’t agree to, while displaying the original contract to you when you sign?
If this is a genuine worry, just screenshot the document as you sign it. If the other party then tries to enforce these fraudulent terms, you can use the screenshots as evidence of the fraud. There may then be a criminal investigation, and everyone involved in the fraud may go to jail.
My particular concern is that I believe I'm entering into a tenancy but then discover, due to some bug in the software, that the landlord never actually entered the agreement. At this point the landlord can legally evict me if, say, he gets a better offer. What can I do about this?
Edit to explain a detail of English law: this is a lease renewal. It isn't necessary for my continued occupation, but without it I have no security of tenure.
A contract does not have to be written to exist, although it certainly helps. An oral agreement that you'll continue in the lease and will treat the document as a formality would suffice.
There will be evidence you will be able to adduce in your favour beyond this signature service.
Furthermore, there are strict rules around eviction; the landlord can't immediately evict even when you're not on an AST.
(In closely related news, just try buying a house during a pandemic, I dare you. There are amusing pictures floating around online of my wife and I shoving documents back and forth through barely-cracked car windows for notarization ...)
I closed on a house a month ago. Notarization was done online by smartphone. Worst part was working with a local bank that had little to no online services.
Did that. (Offer made and accepted in August; moved in on October 1st.) All of the legal paperwork was done online on the basis of "here's a scan of two pieces of ID and click click click I agree" -- the only "shoving through a window" moment was with a bank draft, and even that could have been done digitally if I had been comfortable with transferring such a large amount of money based on instructions received via email.
Rules vary from state to state; in BC they were changed early in the pandemic to remove the need for in-person transactions.
The problem isn't (only) the technical issues. As TFA points out, this is easy, and even the most naive and simplistic implementation beats physical signatures hands-down.
There's two main problems:
1. Legality. Getting a court to recognise a digital signature probably isn't that hard. It's a bit like scanned images - if you can prove that this is the best evidence, then it'll probably be accepted. However, getting lawyers to accept digital signatures is difficult. One of those awkward situations where there's no consequences for them if they insist on a physical signature but lots of potential downside should they accept a digital signature.
2. File formats, or "the standards problem". To include a digitial signature in a document, we need a file format that includes digital signatures. Every document file format has a different version of this, and every digital signature service provides a different "wrapper" format with a different signature.
This needs to be solved top-down. The SCOTUS, or the EU Court, or some organisation of similar standing, needs to say "this wrapper format is the only type of signature legally accepted, and if a document is wrapped in this format, it is legally signed". Both problems vanish and we can have nice things again.
That said, I find it interesting that a couple people on their partners list are Notaries Public--adding digital signature to the list of functions a Notary can perform would make the migration to digital signatures easier. It would probably require making the Notary's signature part of a public chain maintained and issued by the local government as part of their licensure, though, so I don't see where Certisfy comes into that picture at all.
>I find it interesting that a couple people on their partners list are Notaries Public--adding digital signature to the list of functions a Notary can perform would make the migration to digital signatures easier.
That's the main idea here, to delegate trust generation to appropriate entities...this would scale to meet the need of the internet. Today, unless you have hundreds of billions in the bank like facebook, information verification is not practical.
My response was, "Please login to your bank's website and do the transfer."
That was the time I learnt that some (or maybe more) Japanese Banks still need the individual's personal Stamp/Seal to send money from their Banks.
I learnt an interesting thing.
I run a B2B micro-ISV, and the number of times I've been mailed checks, despite slapping "NO CHECKS ACCEPTED" on everything, is ridiculous.
For those in the US who don't want a national ID: it wouldn't have to be one if the states issued their own. Yes, this would mean they'd all need the technical capability to operate a CA securely. Fund them enough to do that.
The US desperately, desperately needs a proper solution where "thing you give tons of people" isn't also "exactly enough to steal your ID".
As a curious factoid, in-between the world wars, it was popular for workers to have their ID number tatooed on their arm.
Using cryptography in addition to "classic" means of attestation sounds a lot better to me. You could also make it an "optional feature" of people's citizenships (like 2FA on an account) to ease adoption.
I'm sure some service would figure out a way.
The user just needs to learns how to perform some simple operations with the app, they never have to know about private/public keys.
There are 3 levels defined by the EU. I use these levels everywhere because it's not really a legal thing but increasing levels of technical requirement. The US has many conflicting laws on what signatures are valid.
The lowest level is what you first started out with. The marketing term for this is "E-signature". It's a subtle marketing speak to mean putting an image into a document. Theses are generally accepted for most things. California though has not allowed this in the past. A provider offers signatures at this level (with some nuance).
The second level is a "digital signature" backed up by other details. People think this means like an actual signature. In document contexts it's very confusing. But what they really mean is signing (encrypting with your private key so the public can decrypt it). This can be a verified email, phone, the more the better. What's important is at this level the signer is not actually the person, it's the service. The service has a trusted cert created from the Adobe trust chain and does additional measures to verify the person. The visible signature at this point is just a mock to make people comfortable using it. The signature is really cryptographic. This level is pretty much always court admissible.
The last level is signing the doc with your own trusted cert. You can get these tokens from many providers to do yourself. It's required for typically government things like stamping a document by an actual engineer (ie a PE). To get these certs you need to go to a notary to get verified. This is as legit as it gets. It's almost bulletproof.
Product wise, I am pretty familiar with PKI but am still confused as to what it really does or why I should use it. If this is to get wide adoption, the person using it needs to know nothing about certs and PKI. Additionally, I'm confused if this is using PKI or a web of trust. I'd think it would have to be web of trust to be practical but it seems like the examples allude more to PKI? Best of luck, I look forward to see where it goes.
Interesting. Does this mean that if a scammer uses docsign to phish me into a mortgage transaction, and I lose my house, then docusign is on the hook financially?
Put another way: Are they legally required to sign on behalf of both (purported) parties of the contract in the case of a dispute? What if 99% of signatures are through them, and the last step is a fraudulent notary?
The service relies on third parties to perform verification and issue certificates, just as the domain name certificate authorities do. The difference is that the information on the certificate can be anything, not just domain names.
Users use the Certisfy app to make use of those certificates, by making various claims against their certificates (think: location, age, name, even height:)..etc)
Think of the app as a kind of trust projection and information verification toolkit/client made for ordinary consumers.
The purpose of a signature is to inform the signer that they are entering a binding contract. It is simply the modern equivalent to a handshake.
Sadly, precedent around Eula’s mean that signatures are no longer necessary to execute contracts.
If anything, society would be better served by making it more difficult to enter into binding agreements than to make it less difficult.
Imagine if, by law, for a EULA to be binding, the end user had to scroll through the entire document, and initial each separate section. Eula’s would be much shorter, and much less common.
In a digital equivalent of “no trespassing” or “cameras in use” signs a few standard clauses could be made enforceable by displaying them prominently on each page. For instance, there could be a clauses such as “you are purchasing a transferrable non-exclusive license to this software”, or “your subscription to this service is at-will with a fixed rate of $N/time-unit.”
A signature also makes it so that someone must commit a felony to misrepresent what you agreed to by forging your signature, no matter how easy it might be to forge. It also creates evidence of their crime.
The article’s complaint seems to be that it might be easy to forge a signature, electronically or physically. Forged signatures are almost never an issue in contract disputes, and when they are, it’s almost always petty small time crime like check fraud.
Solving something that is not actually a problem, using an extremely complicated tool like cryptographic signatures, which require a huge amount of tooling around the storage of private keys and the identification public keys, is backwards.
Conduct implying intent, together with a hand-written signature, can go a very long way in practice.
The value of these services to me accordingly seems to be in their accuracy of replicating the ceremony, not in trying to compete with cryptographic signatures.
What would the merchant compare the signature on the card to? You don't sign a contract when buying groceries, you put in your card and type your PIN.
On the other hand, whenever I go to my bank and have to sign something, they do compare my signature with the one they have on file (formerly in a paper card, nowadays a virtual representation of that same card).
In theory, the merchant is supposed to look at the signature on the back of the card and compare it with the signature you write on the receipt. You can even write ID REQUIRED and then they’re supposed to check for ID.
In practice, I didn’t bother signing any of my cards for about 15 years. After two cashiers expressed annoyance at my blatant disregard for the rules (a few years apart) I started signing the cards.
They are not by the card schemes' rules, and I think they haven't been in quite a while.
> You can even write ID REQUIRED and then they’re supposed to check for ID.
Yes, but they are also supposed to make you sign on the spot after checking your ID. No signature on the card, no purchase – at least officially.
Vice versa, "ID REQUIRED" has no consequences (by scheme rules at least).
Also send me an email (in profile), I can issue you a short lived trustworthy certificate to try out the service :)
Ultimately the goal is to create a service that can serve as a generic and scalable solution for internet information trust. Everything from dating/social-media profiles to academic credentials can be authenticated with a service like this, all while preserving user privacy.
At least my financial institution was willing to work with a phone call, mobile phone number, and email for something rather than having to go in and do the notary thing.
Besides, the argument applies to other signs of consent, like verbal consent. Suppose you give a verbal consent to an agreement and then renege. The other party drags you to court. The judge says, "Did you verbally consent to this contract?" Saying "no" likewise would be perjury.
It only comes up if there's a dispute over whether the document was signed. Because the signature itself is so easily forged, the entire legal process relies on people not perjuring themselves if asked if they signed a document or not.