However, if Microsoft signatures have now became more forgeable at scale, perhaps we could see some rash of fake contract fraud in the future where disputing fact of signature becomes more common.
Perhaps the bank only retained page 20, and is saying that they used the same master form for every mortgage and the master form says "this" on page 12.
Or one party discovers that other has misplaced their copy of the contract and then shows up with a copy that has advantageous wording on page 12.
I guess a cryptographer would add a hash of all preceding pages on the last page.
That's basically how hashes and signatures work anyways. They basically take in the result of the previous block and integrate it into the new block so that if you change any part of the previous parts, the whole thing breaks.
Edit: I should specify this is how the algorithms themself work. Implementations can fuck this up (and they do a lot).
In contract disputes, there's usually no dispute of if a contract was signed. Sometimes there's a dispute over which contract was signed, but then each party may have a signature on a contract or not. Much more often there's no disagreement on the contract or that it was signed, but on the terms.
It's nice that electronic signing can solve the issue of validity of signatures, but it's not that big of a deal, because it wasn't that much of an issue; and that's why e-signing has devolved into 'click a button to enter a signature' without any sort of cryptography.
They accepted my copy verbatim and scanned it right into their DMS, despite the fact that my revision was older than the internal revision it was tagged under. They scanned the -whole- document though, so the language on the signed copy is crystal clear.
The banker’s remark: “that’s unusual, no one ever asks for a copy of them signed.”
Edit: my initial draft was a grammatical mess up top
Common examples are someone is sent a contract of employment unfortunately often after starting and they don't sign it. If they have been coming into work broadly in line with that contract so long as it's fair, employee and employer are bound by it.
Here is an interesting edge case in the UK [0]. Long story short if you give someone the ability to sign on your behalf and appear to consider parties bound by that it's binding.
In a personal sense, I send out appointment letters but my secretary does it for me. I consider myself as bound to that as if I arranged it myself. I gave the secretary latitude to book appointments for me, and I usually turn up to those appointments. If that letter is signed, or if it's by my hand. Doesn't legally matter as much as you'd imagine.
[0] https://www.lexisnexis.co.uk/blog/banking-and-finance/gordon...
Of course, an unwritten contract is no more valuable than the paper it's (not) written on; and either party can dispute the terms. But you can still make a valid contract with a verbal agreement and a shake of hands. But don't do this unless you trust your co-contractor!
It mostly depends on how quickly courts will do the proceedings to establish that it is or isn't so.
In general, agreeing to something by text in an email is as legally enforceable as a signature.
...but apparently not always. Not something I'd want to bet my business or reputation on.
"AUSTRIA’s Federal Administrative Court [..] declared a framework contract from Austrian Federal Railways (ÖBB) to Stadler for the delivery of up to 186 double-deck trains to be null and void due to an alleged formal error in the qualified electronic signature of the offer." (September 2021)
https://www.railjournal.com/news/austrian-court-annuls-stadl...
Of course, when in doubt, proving the exact content of such an unwritten contract may be hard.
Correct in the US, although it's worth mentioning the Statute of Frauds and the Uniform Commercial Code:
While I am sure that clause can be nulled and voided if it came to that, the fact that the responsibility is on the signee is terrible.
As an example, in DK an email constitutes a valid contract for most purposes.
[0] https://www.docusign.com/products/electronic-signature/legal...
However, when you read the page about Finland it suddenly starts talking about Austria.
In Italy there is an officially legislated signed email service that has legal value
The decision to require users to use an emailed link to view and sign a message could stem from DLP requirements. Emails are plain-text and therefore any sensitive data leaked could be irreversibly exposed. By keeping the messages inside a system that requires authentication, there is less likelihood that a someone besides the intended recipient will interact with the message. Such systems also support auditability and DLP scanning.
eIDAS was intentionally formulated to allow such signature services, making the whole thing quite pointless from a security perspective.
This method would most likely be eIDAS confidence level low. They (like many other providers) most likely offer multiple LoA variant but only advertise the lowest one online so you think you are "ok" with an easy to use variant but when push comes to shove you need to upgrade to substantial or high, do the full validation scheme and get a QSCD to do you signatures with.
The first "shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic signatures."
Qualified signatures used to require that the private key was physically on some tamperproof chipcard (or similar), but eIDAS changed that. Now, you can rely on some vendor's implementation of cloud signing services that is certified to ensure(?) that "signature creation [data] [is] with a high level of confidence, use[d] under [your] sole control". Much like how many people don't manage the secret keys of their crypto wallets.
For remote QCSD the relevant spec is ETSI EN 419 241‐2 PP. It has very few requirements (8.1.8) about authentication, only that it should be resistant to guessing your PIN/password, and it should only let in the legitimate user.
Note that you can get certified as a qualified trust provider by EY or KPMG.