Sign a PDF document client-side with no data leaving the computer
observablehq.com
observablehq.com
Tony Arcieri explains the issues more broadly here https://tonyarcieri.com/whats-wrong-with-webcrypto
Also, Nadim Kobeissi formalized it wrt Protonmail a while ago: https://eprint.iacr.org/2018/1121.pdf
Even for non-malicious sites this can be a problem.
I think a notable case of the second category is jwt.io which last I checked definitely seemed to fire a few network requests after I pasted a token.
(Happy to be corrected if this is obviously false or has been corrected later.)
That said I couldn't see my token in one of them but it is scary enough to make me avoid using that site.
BTW, I think their statement/claim
> "Warning: JWTs are credentials, which can grant access to resources. Be careful where you paste them! We do not record tokens, all validation and debugging is done on the client side."
is correct, it's just to scary for me to put client credentials there at all when it isn't trivially east to prove that they aren't uploaded.
They do make request to https://b.6sc.co/ all the time, regardless of you pasting stuff or just having it as an idle tab. Seems to be some kind of analytics that just tracks your time on the page and if you are active or not. With that said, I just fired up a proxy now when you mentioned it, have not actually properly investigated it.
If you are transporting over HTTPS and have a Content Security Policy (https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) it seems like that job is largely taken care of.
Native clients suffer from code distribution problems too, but to much lesser extent, especially with reproducible builds and actually readable code as opposed to minified JS.
You do not have to connect to the internet to access a local HTML file. If you disconnect the internet, then anything in the file that tries to access the internet will not work, so you can also know that it isn't sending stuff to the internet.
That this is running completely locally without any software to install is pretty useful and cool. Your criticism isn't great (IMO borders on concern-trolling) because the alternative is something where the docs go to some centralized SaaS that store everything including your signature for an unknown period of time.
No. The alternative is using a desktop application, which offers a superior UX in every way.
I don't get what's so bad about installing applications. It's painless. Browsing the web on the other hand is painful.
Ah very well, then it's not as important.
"Besides, if you don't trust in-browser JS then you shouldn't trust any site on the web, e.g. online banking."
Online banking is different from the PoV of expectation of privacy. With online banking I'm managing the account the bank has plaintext access to by definition. Had this been about digitally signing a document, the vendor would be an untrustworthy third party (the signer and the verifier being 1st and 2nd parties).
"That this is running completely locally without any software to install is pretty useful and cool."
No it's running in-browser, not natively. It's not enough it runs locally, it needs to run locally the same way, every day, without requiring 365.25 code-audits per year, per user.
"Your criticism isn't great (IMO borders on concern-trolling) because the alternative is something where the docs go to some centralized SaaS that store everything including your signature for an unknown period of time."
No the alternative is a native client that does this offline, where you can inspect the source, download and compile it (hopefully reproducibly), and where you know you can trust the program acts the same way during runtime, every time. That's not true for JS applications. Since this isn't about digital signatures, I admit I was wrong in that respect. However, wrt security related programs, in-browser crypto isn't safe as the sources showed.
this looks more like drawing a image onto a pdf.
Instead of simply saving the signed PDF in preview and sending it out, export the PDF as another PDF (there’s an option to do that in the File dropdown).
I’ve found that doing that fixes all comparability issues (based on signing 5-10 docs a week).
Edit: Before someone tells me I should be using Acrobat, I know, but for some reason it runs painful slow on the new Apple M1’s.
I would call that Apple bashing nonsense.
Mac, Windows, Linux, BSD ... if you're going to go signing legal documents (a) with a self-signed certificate (b) without an independently traceable timestamp .... then frankly don't expect it to hold up for long in a law court.
And the signatures we're taking about are an image of a signature, not a cryptographic one.
Also, I don't know about you, but AFAIK pretty much all software these days (whether closed-source or open) comes with a great big disclaimer attached effectively saying "you're on your own" if the software functions in an unexpected manner.
That said, most of the times I need a signature is some bureaucratic useless form and the signature is just a pro-forma - and you can be sure if I don't have a signature (and maybe if I didn't pass my form through a filter to make it look like it was scanned) some government employee in some office will reject my form and I'll have to do another one and fork out even more money.
In small transactions (say, less than $100), no-one really cared - I would scribble my signature on a docket, no-one would double-check it with my card, everyone went on their way. Signatures were required but not respected or checked. In large transactions (I bought a MacBook, for example), the staff could not care less about my card or the signature scrawled on the back, but they would only take my money after I could produce some photo ID (a passport in my case) showing that the name on the card correlated to my face. In this case signatures were technically required but totally ignored because they’re easily forgeable. (A fact I’ve always been bemused by is that the signature is on the card - if you drop your card or something the signature is right there).
End of long story - how valid are “just signatures” legally? As someone with zero legal experience (clearly qualified to comment) I feel like other evidence showing that someone received and signed the document would be much more valid than just “the signature” by itself.
I've found sometimes that Preview mangles some PDFs created in Adobe. In addition, there are many cases FoxIT (PhantomePDF) also mangles or can't even open PDFs that are *complex in nature that were created in Adobe Pro.
To be fair, I just signed some bank documents, and it was all inside their system and it just consisted of me checking a checkbox. It was their system, so it was considered a signature, since I logged into their system first.
Once you get into power usage, such as redaction in the legal world, Adobe is the only product that doesn't have bugs. I've tried. It's a sad state of affairs, but yeah that's the world.
*And by complex, I mean 1GB pdfs with 1000s in pages that have Adobe's embedded audio/video as well as scanned handwritten notes and photos., not 1 or 2 simple pages.
They call it "Continuity Camera", and it is probably my single favorite little feature in the Apple ecosystem. Nothing revolutionary, but just something simple done really well - and when you need it, you really need it.
I held my pointer finger between my thumb and middle finger, and made myself really think of it as a pencil. I looked down at the trackpad as I wrote (rather than at the screen), and tried to visualize the trail it would leave on the surface.
Such certificate is useful for PDF signing besides other uses.
(Linux) Load the PDF in xournal, click on > Tools > Image. Select a jpeg holding my signature. Change the dimensions and drag the signature around as needed. Note that you then have to export to PDF rather than saving it.
(Android) Using the OneDrive app. There's a signature option in the annotate menu.
Xournal can be installed from the official Debian repository, but not Xournal++ (not yet - it's apparently being worked on).
So Xournal is very convenient for filling in basic forms on Debian and is easier to install.
Xournal++ could be installed on Debian by downloading a .deb, or using snap or flatpak. But not as convenient as installing Xournal via apt-get.
When Xournal++ makes its way into the official Debian repository, I might switch to it.
For now, I'm very happy with Xournal (the original)!
Sure, you could presumably try to get to the bottom of this, but it's easier to just use a local option.
It's a very simple but full-featured PDF editor. Makes working with PDF pleasant. I didn't think it would even be possible. Inserting an image is Ctrl+I.
In short, Xournal (original, not ++) can add pictures and text too! And it's available via official Debian repository. So it's easier to install in Debian.
Xournal++ is a rewrite of Xournal, and has more features, but I don't want to deal with downloading a .deb or using snap or flatpak. They're working on getting Xournal++ into official Debian repository though, but it's not there yet.
Xournal (original, not ++) is quite good for filling in basic forms on Debian!
Some malicious programs use techniques like delayed network requests to send data when you're not expecting it, and you basically have to audit the entire application to make sure it isn't making these covert requests.
Does he go through every single line of code on every single application he uses to ensure privacy? Does this mean he is an expert in the Linux kernel? And chromium, and sendmail...
Like I get it's great that these are open source, but it's really not realistic for someone to audit every single line of code in every software to be guaranteed that nothing nefarious happens. If a bad actor wanted to hide an RPC request, they wouldn't label it as _sendUserDataToServer(), so it would require quite a good understanding of the call stack on the functions you are looking at.
Just look at the Linux kernel, it's auditable but recently it came to light that a university had submitted nefarious code to it. Presumably that code passed code reviews, static analysis, and some sort of testing? Yet it still made it in. It's just not feasible to have 100% confidence that third party software is ensuring your privacy.
This is missing the point. Having the source code decreases the chance of having malicious software by allowing random people to read the code. Anyone can raise alarm if they see anything suspicious and it's easy to check such claims.
If components are OSS then I have an easier time auditing. And perhaps I audit one section, and trusted people audit other sections and we can all run a trivial verification program.
Again, it’s not perfect, it’s just better. And it at least has the conditions for perfect review, while other methods do not.
...and it came to light because it is auditable. Short of rejecting digitalisation and returning to monke, is there anything better in terms of trust and security than using open source software?
> Does he go through every single line of code on every single application he uses to ensure privacy? Does this mean he is an expert in the Linux kernel? And chromium, and sendmail...
You're misunderstanding it. You don't need to go over every line to benefit from the source being available. It's very rare for bad actors to publish outright malicious source code and just hope no one spots it. People who want to release malware just about always insist that you cannot inspect the source code.
Of course, it's possible to release good source code and also introduce malware into the official binaries, lying about it corresponding to the published source, but that's another matter.
> It's just not feasible to have 100% confidence that third party software is ensuring your privacy.
It's rare to aim for absolute perfection and absolute guaranteed trustworthiness. Insisting on Free and Open Source software is a pretty effective means of avoiding many forms of malware.
Which is solved by reproducible builds.