Digitally sign PDF files from your commandline – open-pdf-sign
github.com
github.com
They actively coax you into receiving your bank account statements as PDF, but I haven't found ANY bank which signs the PDFs (while bragging about security all the time).
I wonder what happens if they lose your money due to bugs or even intentionally - will they then happily accuse you of forging the PDFs because they're unsigned?
With paper that'd be not so trivial, in my country the paper often has some special format and the paper itself is of a special type, and it ages and you cannot easily guess the printer which was used.
Hence I still demand all my statements on paper. Same for utility companies, health care, and other institutions which want to convert their regular physical bills to PDFs.
I also demand paper because the concept of forcing the customer to manually go to N websites every month to download PDFs is idiotic. Nobody pays me for that wasted time of my life.
A paper mailbox instead is a central place where I can retrieve all of my documents easily in O(1). I wonder how many decades it will take the IT industry to realize that?
How do you organise your paper documents?
Make your scanner put files in a place that Paperless can read them, then Paperless OCRs the file, makes it searchable, somehow finds the date of the documents, auto tags if you have it setup, and basically is a dream.
I don't organize them anymore, if I need an old document I search for some text in it or by date.
https://github.com/jonaswinkler/paperless-ng
There is a newer Paperless ngx that I have to upgrade to at some point.
As long as the device can scan to PDF into a network folder, I think most scanners/printers will work. Paperless works by monitoring a folder you choose - it doesn't care how files get to that folder.
It's very common for most all-in-one printer/scanners to be able to save to a Windows/SMB network share. In my case on the Linux box running Paperless, I also installed and setup Samba and exposed a share for the scanner.
An engineering firm I used to work for rented Kodak i2600 document scanners from the company providing their printers - and they were constantly scanning and these devices didn't mess up. If I did high volume scanning I'd try to get one of those.
- Realizing that whenever you need to extract some old document in the future for reference / proof, you'll likely have a date range when it happened to go looking for it. And needing something old happens rarely enough that the overhead of searching for it can be neglected, so you'll layout your binders to make putting things away fast, not searching things. And the older things become the less likely it is that you'll ever need them again. So sorting by date is important.
- Thus realizing that any finished documents can go to a SINGLE binder which is sorted by date, you don't need a separate one for healthcare, utilities, whatever. You don't even need registers in the binder, just flat date sorting.
- Therefore, you'll only be having 3 binders:
"ToDo", "Done" and "Constantly needed" (the latter is for contracts for example).
Sort the contents of "ToDo" and "Done" by date. Adding new paper will be quick because new stuff arrives close to the most recent date so you don't have to search a lot for the place to insert it at.
AND: Make sure to mark the date on every document with a highlighter of always the same color so you can easily spot the dates when inserting.
TL;DR: Most documents will go to a single or two sorted-by-date places, just like your email inbox. This makes adding things fast.
The amount of documentation you have (and have to go back to) is probably on an entirely different scale to what I am personally dealing with: this would never work for me, since just a date would make finding stuff almost impossible.
I put a lot of thought into this system so it's nice to know someone at least took notice of it!
Your problem of larger scale may or may not be alleviated by the details I left out for simplicity and because I assumed a typical reader may have a low scale:
- In practice my "ToDo" and "Constantly needed" folders do have registers such as "health care" etc. as those are the ones where I usually have to search for things. The date sorting there is inside the registers. For "ToDo" I also color-code the registers by priority and sort them by priority.
- The "Done" folders have a register for each year. For very high scale you might add registers for month. The folders are also labeled on the outside with their years. To make it easy to access things which you might have to go back to, you could add "look here!" registers which do not affect the date-sorting, i.e. like bookmarks.
> How do you organise your paper documents?
I just throw them in a box, without even opening them. On the off chance that I ever need one, I go to the box and fish out all the envelopes from that bank, and look for ones from the likely date range.That is, I optimize for quick storage at the expense of slow retrieval. But even the slow retrieval isn't bad.
[1]https://www.sec.gov/litigation/complaints/2020/comp24905.pdf
Not really sure what the state of the art there actually is. Pessimistically I figure we're still at the stage where websites would put an image of a lock with a green checkmark on their website to make it look secure - i.e. really only just for show.
Do they pay you for this?
The rotten, soulless entities that is banks do not deserve ANY free work.
They don't care about you, they won't value you work, they won't give anything back.
They'll use it to maximize their profits at best.
But most likely, they won't do anything: With absolute certainty, they KNOW that PDFs can be signed. They have to deal with cryptography anyway, and have security consulting.
They very likely intentionally decided to not sign PDFs anyway just because they can get away with it without getting sued, and save money by that.
The overhead of maintaining a properly secured PKI key and implementing signing of generated PDFs with it is nonzero.
Banks aren't always rotten and soulless, they are cold and lazy machines that do the bare minimum that their customers ask.
This project is great, let's spread awareness that PDFs _can_ keep an internal digital signature and maybe someday their customers will demand it.
Would you say the same for self checkout at the grocery store?
What about burger bars where you have to put your own toppings on?
Funny enough, the only digitally signed email I've ever (knowingly) received came from Aldi. I sent them a question about food waste and the response showed up in Apple Mail with a badge and signature validation notice that I'd never seen before.
What is your point anyway?
Do you really think I should be wasting half an hour to a full hour of my life every month to download a dozen of PDFs (remember, it's not only banks which want that) so big corporations can save like $5 on paper & postage?
Why would I want to work for below minimum wage for those people, for no tangible benefit to me?
(Paper is as easy to process as PDFs, and IMHO in fact easier to process:
You can fit multiple sheets on your desktop in parallel, you can shuffle it around, hold it next to each other for cross-referencing, you can write stuff onto it and be sure it will be readable in 10 years (might not be true for PDF annotation software!), the disk it's stored on won't die, your relatives can read it if you die, etc. If paper was a VR-product all these things would be advertised as great new VR features. In real life we get these 3D-features for free but their advantages are completely ignored when forcing the usage of computers for the sake of it.)
At their scale it's much. I honestly don't care about their costs, but at their scale that's tons of paper and gas that's totally wasted.
I don't know which country you're from, but all my bank statements, utility invoice etc go to my email, so there is no need to log anywhere. I'm not sure about others right now, but utilities are definitely signed. Maybe you could talk to your bank/... about it.
At their scale it is replaceable: They earn money to do their duties, if they cost a bit more they bill the customers a bit more so they get it back.
The time of my life is NOT replaceable. I do not get it back EVER.
And they very likely don't give a damn about their customers, it doesn't matter to them if some cronjob delivers PDFs or another cronjob prints letters - at the end of the day they just want to go home.
I do CARE about living, it gravely matters to me how much of my life I have available for myself.
> tons of paper and gas that's totally wasted.
It's not wasted: It fulfilled it's purpose of delivering information to me in a convenient fashion.
And once I'm done with it, it goes into the paper bin and gets recycled.
> I don't know which country you're from, but all my bank statements, utility invoice etc go to my email, so there is no need to log anywhere. I'm not sure about others right now, but utilities are definitely signed.
Every company here has a different method. Websites, emails which link to websites, emails which are the invoice, emails which have an attachement that is the invoice.
It is impossible to cleanly integrate this into one workflow.
A plain old regular paper mailbox however already is a clean, integrated workflow which ships unified pieces of paper which all have the same size and are able to be put into the same kind of folders thus.
Hence optimizing this to be more convenient for companies means taking away individual lifetime which matters to individuals for the sake of enriching entities which do not care about the money they saved, it's just a number in some database for them.
> Maybe you could talk to your bank/... about it.
Do you seriously believe they will do anything?
Whenever I interact with those kind of people, I rarely get an answer ever, and that's about things which are part of their daily duties.
If you go to them expecting them to actually do something out of their ordinary - good luck. It will get ignored with a 99% probability.
And even if one of them does something: Then the other dozen companies I have to deal with will not do anything.
So paper has to stay anyway. I'm happy with it. It's convenient, it's super standardized, and it just works.
(And encryption is NOT a signature. Anyone who knows the password can forge an encrypted file with the same password. So the PDFs would still be worthless.)
As far as signatures in PDFs goes, when have you ever needed them? What’s the real world scenario? I think most recipients would be incapable of validating the signature properly (including verifying ownership of the public key corresponding to the private key that signed it). Ie same flaws of any Cert based system.
How would I prove to a court that I do have money if I only have easily forge-able unsigned PDFs?
Now before you say this is unlikely, ask yourself this:
Would you lend thousands of dollars to a regular person without ANY signed document from them which says they owe you the money?
No, right?
Then why would I do that with a bank?
If they get that much money from me they ought to at least give me a kind-of unforgeable document which says the money is mine.
Encryption involves using signing key and universally uniquely identifying something.
That's exactly what it is. In fact encryption is even more secure than a normal written signature.
I can sign a piece of text put it here -- sign it with my private key -- put it on HN with my public key and everyone can be sure I wrote it.
With asymetric encryption you have a sort of signature because only the sender has the encryption key, so forging somemthing that opens with the same decryption key is hard. But I have yet to see somebody encrypt pdfs with an asymetric method.
No, certainly not.
The biggest issue is that you're conflating a human concept of a signature and the cryptographic one. This is obvious from your second paragraph.
> I can sign a piece of text put it here -- sign it with my private key -- put it on HN with my public key and everyone can be sure I wrote it.
Cryptographically maybe, legally no. We lack crucial information about who can use your keys, there's nothing that says you can't share a random keypair that has no legal backing. We also don't know if your keys are valid at all, maybe you're underaged? Do we know if your keys were valid during the time of signing, maybe you were underaged?
It's way more complex than Sign(text).
> With paper that'd be not so trivial, in my country the paper often has some special format and the paper itself is of a special type, and it ages and you cannot easily guess the printer which was used.
Read a similar discussion recently. Even with paper you can prove your account balance at day X but if your bank lose your money at day X + n and you want it back they could still claim you withdraw all since day X and had an empty account at day of lose.
The PDFs protect me for 0 days because they can claim I've faked them right from the beginning.
I'll take the paper :)
It's easy to get things perfectly when everything is new and the audience is small.
What I mean is the following:
Let's say that I'm downloading PDF from mybank.com. Browser establishes TLS connection to the mybank.com, sends request, receives response PDF and then does something with response. This TLS connection could be serialized as it is with accompanied ephemereal keys. Those bytes include remote peer X509 certificate signed by digicert and the whole exchange is further cryptographically signed with corresponding key.
So basically you already have cryptographically signed PDF from your bank. You just don't have tools to save or verify this signature. And juridical framework to further act on those artifacts. But tech is deployed for 30+ years already.
There have been proposals to extend TLS to have this capability, but to my knowledge none are really standardized or used anywhere.
To deliver any file over TLS, you need access to the private key part of the TLS certificate, and to decrypt it, you need the public part. Having a recording of unencrypted raw TLS session along with the public key part would allow decrypting the stream later, while making it impossible to forge any data not coming from the identity controling those private keys.
For proper verifiability in the future, you'd want more details from the certificate and CAs (like verifiable way to ensure certificate was not revoked at the time of download), but there is already an asymmetric encryption happening at the TLS level.
Now, you can still forge some parts by omission: if you've got streamable data (requiring no random seeks), you can cut off parts of documents while maintaining encryption: you still can't modify it otherwise.
What am I missing in your claim of forging a "recording" of an HTTPS session?
Everything after that only needs the symmetric key. That both sides know, and thus both sides can generate whatever they want to put into a recording, and you can't verify if it is correct or not. All a third party can verify given a detailed recording is "this client did access the bank web server and completed a handshake with it".
https://github.com/open-pdf-sign/open-pdf-sign-configurator/...
A core problem is that a pdf signature does not necessarily cover a complete file, but can be a partial signature. This adds a whole lot of complexity and unclarity around what is actually signed, allowing all kinds of attacks. I feel this is all so problematic that if you want to sign PDFs it's probably better to not use PDF signatures, but some form of outside signatures over the whole file.
Regarding (1), this is because there exists no complete specification of what an implementation needs to check with regard to the PDF format. Implementors have to figure it out on their own, and thus there have been some gaps.
But in general the ASiC-E container format is more versatile and also more robust against potential flaws.
Is there any wide use of ASiC?
For now, I'd expect ever increasing compliance with eIDAS in the future. PDFz are also not the only thing that people want to sign, that's where an agnostic container format has its benefits.
> Is there any wide use of ASiC?
I know that at least Estonia, Latvia, Lithuania and Finland have deployed it. Of those Estonia probably has the widest and longest use of it, as they migrated *to* ASiC-E, having used the predecessors BDOC and CDOC previously.
That's my one big hold-up from going full Linux: I absolutely must be able to sign documents using a cert held on a smartcard.
We use it for many years in a public sector organisation to make sure that our internal documents are properly signed.
https://vickiboykis.com/2019/05/10/it-runs-on-java-8/
hn discussion https://news.ycombinator.com/item?id=19877916
All that said, "that's how GPG does it" is usually a strong argument against a proposal.