Highly annoying these services, they don't do even the most basic verification that the person signing really is the person that should be signing.
Highly annoying these services, they don't do even the most basic verification that the person signing really is the person that should be signing.
When you sign a mortgage or take out a loan and it’s all online, lenders will pay someone to come to your house, take a photo of you, verify it, and then video tape you signing.
It’s just not convenient.
This is the problem with things like account recovery. If you really want to minimize social engineering etc., you'll do something requiring a physical presence and various sorts of government issued ID and will probably cost money. And people won't like that. (And the companies won't like it because there's a lot of overhead.)
It's true that you can physically go to the institution in question and prove your bonafides to them so no intermediate is involved but you start to add a lot of friction to all but the most serious transactions.
Many years ago, possessing the values on a passport constituted verification. This data was stored and after a significant number of leaks, this data alone was useless as it became public knowledge. The next step was requiring a photo of the document. The photos were stored, and after a significant number of leaks, the same thing happened. The next step was ID selfies. Then the same thing happened. Now it’s selfie videos with the ID. This too will become useless when those videos are leaked.
It’s a never ending battle. A passport is a physical document and should only be used physically.
Online, we need public/private key authentication. It’s the only way.
Requiring physical presence is a pain but it's probably tolerable for sufficiently high value transactions. Only works within the US. There's a related process with more hurdles for international.
I'm having trouble imagining a scenario where such a high level of assurance for real identity verification is required but is not worthwhile to meet in person.
Can you name a few examples?
In general, I rarely do anything related to financial accounts in person.
Your credit card already has contactless chip and it's been ID verified. So does your smartphone. Why can't we just marry the two together?
In neither case is there any real additional identity verification.
If you care enough to get it really signed, pay the notary.
To the degree that signing a lot of documents is something of a formality, most of us don't want to have to go to a notary every time we need to put our signature on something.
What actually needs to happen is that things like Docusign need to be contextualized and treated as the appropriate amount of evidence of a contract that they are. Which is to say not much, just like a piece of paper with a signature on it these days.
A "signed" Docusign is evidence that someone opened an email link and clicked a box from a certain IP. It does not prove that a specific person did this. It does not prove that the person who did this actually read, understood, and agreed with the words in the document. In fact, a Docusign that didn't allow marking up the document is itself evidence that the person in question was coerced into accepting unilateral boilerplate terms, rather than being able to make modifications.
Like many legacy systems in the US, the jankiness from using an antiquated system is actually preventing a much more draconian system that would develop if the abstraction was made solid (for a straightforward example, see "identity theft").