Umm, what? Someone cannot create a PDF and sign with someone else's key. This would've defeat the purpose of public-key cryptography.
>it's not a great storage mechanism for this system to scale to thousands or millions of signatures
Not sure how recommending a system that scales not on signatures but on messages shared is better.
>Another alternative is these messages are broadcast through a public and decentralized ledger.
Okay. So suppose a message was distributed from an address. How you know to whom this address belongs? How will be different that you being shared their public key?