eSignature Beta for Google Docs and Google Drive
workspaceupdates.googleblog.com
workspaceupdates.googleblog.com
I haven't used the feature, but from reading the blog post it is sad to see how poorly Google executes on products, even at the beta stage.
Some context:
I've built such a product before and eSigs are more simple than they seem as long as you do a few things. 1) You need to verify somebody's identity. Sending them an email with the request is a valid way of doing this. 2) You need to make the final signed document easily accessible (e.g. emailing all parties a copy of the signed document. 3) You need to not obscure what the person is signing (they need to be able to easily see the entire document if they wish) 4) You need to make it possible for all parties to verify the validity of a signature, which is done with an audit trail appended to the back of the document. 5) Some types of contracts are not valid to be signed with eSign. 6) The parties need to agree to do business electronically, but this is mostly up to them.
You do not need to create fake wet signatures, cryptographically sign a document, or do encryption beyond what is necessary for normal compliance. Those are all UX or marketing features: they don't hurt, just that according to experts I have spoken to, they aren't a factor when going to court.
And then we have what Google is offering:
From the screenshots, I think it is only a fake wet signature. I'm not sure how valid that is.
Apparently you cannot ask for an eSignature from non-Gmail users right now. But how are you supposed to know they are Gmail users? Can Google not send people a simple email with a link? This alone makes the feature almost worthless, and for something that seems so trivial.
They also said they will only be adding an audit trail later this year. This is really sketchy because I believe it means you, nor anybody else can actually verify if it has been signed. Again, this is quite trivial: you store the audit trail in a database, and you append the log as pages onto the back of the PDF document.
I just find these comments to be so strange. You can look at all of the articles in that blog to see all of the feature improvements that have launched in Docs over the past 2 years. It's a lot of stuff.
Maybe they're not features that matter to you, some are available only to paid customers as opposed to free tier, or maybe you just haven't bothered to even notice. But they're there.
It's nothing about Google specifically -- I see people make these comments about so much software, where they assume a project is or has been dead, just because they can't even be bothered to look at the changelog. It baffles me.
It's like, unless it's a radical total UX overhaul, people don't notice the work developers are putting in on actual features. And if it is a radical total UX overhaul, people complain about the change because they assume it's superficial rather than actual features.
I have a Google Spreadsheet that I used to track investments I have in various markets. Three months ago Google stopped showing any stock quotes for ETFs in Europe. No explanation, just 'f u, we showed them for years now all your spreadsheet breaks'. I had to help myself with getting some quotes from Yahoo News via script but it's half-baked.[1]
Google doesn't care about it's products and anyone who thinks different hasn't opened their eyes.
Btw their lack of quality and care is not new for Google Docs/Spreadsheets [2] Issues keep popping up but are usually fixed after a while. This time they just stopped bothering.
I wish Google had Product leaders who actually cared about the quality of their products rather than just launching new features that make a splash and then slowly wither on a vine. Fewer features I could actually rely on would go a long way.
[1] https://www.reddit.com/r/googlesheets/comments/13i2gf6/googl...
It's easy to experiment and build when your product is small and few people use it. When you're bringing in real money and most of the Fortune 500 is using your software, it's a lot harder to add anything meaningful for fear of rocking the boat. And note, this isn't necessarily a bad thing. If the business is doing well, there might not really be a need for many new features.
In a product as old as Google docs, they honestly have all the important features that most people actually care about already. You can save. You can track changes. You can set up custom styles. Or embed images. You can edit docs collaboratively. Or programmatically via their api. Documents look the same on basically everyone’s computer. And they can be in shared folders for teams.
At some point every product runs out of high value, visible features to add that anyone cares about. This isn’t a failure mode. It’s the opposite. This is the final state that most successful software should aspire to reach.
I have a lot more respect for teams that understand this, and let their products find their UX steady state. Fastmail. Git. Vim. WhatsApp. And yes, Google docs.
I think this is pretty interesting, because I don't necessarily agree. If we were starting from a blank slate in a world where a spreadsheet hadn't existed before I suspect the perfect spreadsheet software would look pretty different to Google sheets or excel, but because this software has been around for a long time they're part of the standard interfaces for computers, like a mouse or keyboard. If you deviate too far from the current design people get confused and default back to what they know i.e. excel with all it's quirks.
I agree with you. But I also think at this point excel and google sheets are past the point where people would tolerate a radical redesign. If google or microsoft want to invent a better spreadsheet, I think it makes more sense to try those ideas out in a brand new product. Excel and Google Sheets are "done".
Just look at how slow Notion is and how snappy Docs is. Yet, a lot of Notion features are now in Google Docs.
Here, go nuts:
https://workspaceupdates.googleblog.com/search/label/Google%...
They're useless. I've been paying for Google Docs for over a decade. Nothing of note has been added until they finally... FINALLY let me get rid of the concept of "pages" recently.
If you have to look at a changelog to understand what changed, then the stuff that's being shipped isn't making a difference.
In order for a signature to be recognised, it has to meet one of three trust levels
1. Electronic signature: this is basically something that puts a distinguishing mark on a file.
2. Advanced electronic signature: these use cryptography according to the specifications set out in the regulation, but anyone can make them. There are some requirements about how a person’s identity is linked to their signature.
3. Qualified electronic signature: these are advanced electronic signatures which have been produced with a recognised trust service provider. Each country has a list of trust service providers, and each other country mutually recognises their trust lists.
It is a bit more detailed than that, but in general, simple transactions can pretty much use any electronic signature (but this varies from jurisdiction to jurisdiction. The uk generally doesn’t need anything fancier than docusign). In order for something to be completely watertight, it needs to be a qualifying electronic signature.
In order for these features to be useful in Europe, google will need to meet the requirements of the regulations, and specify a trust level.
Use of technology doesn't change that. The only time a court would throw out a signature made online is if the online platform was somehow deceiving the parties - for example by showing different text to each side when they click 'i agree'.
If you can't see the other person signing the agreement, you need to verify that the right person is signing it. It's much the same issues that exist with simple passwords versus 2FA; shared accounts, piracy, identity theft, etc.
eIDAS is a set of standards for verifying identity that is backed by law. It allows businesses to follow protocols (some similar to 2FA) with the assurance that it will be held up in court.
However, notice that Google has not said they are compliant with any regulation.
https://www.theguardian.com/world/2023/jul/06/canada-judge-t...
Accepting the terms, just as a handshake, on a deal, can bind one.
https://www.swanngalleries.com/news/autographs/2023/01/the-s...
https://nationalpost.com/news/canada/farmer-ordered-to-pay-a...
The nuance here us that:
- the emoji was bring used to reply with an OK
- this was used in the past on other contracts between the two
Note that judge looked into the meaning of the emoji, looked into how it was interpreted before, and said "but nevertheless under these circumstances this was a valid way to convey the two purposes of a ‘signature,”‘ Keene wrote in his decision."
Note purposes of a signature, not signature. FYI, making a mark is still legal, judges know it, yet that language was not used.
And you don't look into how a emoji was used by other people, if it is being used as a uniquoe "mark" aka "signature" aka "trade mark".
Because a mark, a signature is unique. An emoji is as un-unique as a word such as YES.
This is also why someone cannot trademark a colour, or a generic font. Trademarks aka marks aka signatures mist be unique.
In this case, the decision was "he accepted the deal", just as a handshake or verbal OK.
This particular case hinges more on whether the emoji :thumb_up means agreement or acknowledgement. However if the person had habitually been agreeing with a mark then that would weigh in favor. It's not clear without the exhibit of previous text messages, but strongly implied by the wording, that this was indeed the case.
So this was accepted as a written contract with mutually agreed terms. There was no verbal addendum or additional terms.
> They also said they will only be adding an audit trail later this year. This is really sketchy because I believe it means you, nor anybody else can actually verify if it has been signed.
From the help page it seems obvious that both the sender and signers are able to check whether the contract has been signed. "1. Open the respective PDF file in Drive or through the link in the email notification. 2. Click View details in the upper right corner of the PDF to open the right side panel and view eSignature details."
Are you saying that the only possible valid implementation of an audit log is one appended to the contract pdf?
> Can Google not send people a simple email with a link?
Obviously they could. But equally obviously from your description, this is not a feature where sending one email with one link is sufficient. Based on the help page the final signed contract is "saved in your Drive", an operation that's not meaningful for a random email address that won't have an associated Google Drive. It seems likely that this is a feature that would be blocked on e.g. embedding the audit log in the pdf as per the discussion above.
> Obviously they could. But equally obviously from your description, this is not a feature where sending one email with one link is sufficient. Based on the help page the final signed contract is "saved in your Drive", an operation that's not meaningful for a random email address that won't have an associated Google Drive. It seems likely that this is a feature that would be blocked on e.g. embedding the audit log in the pdf as per the discussion above.
None of this really matters. I totally agree with the parent comment: having an e-signature product that is only usable by other Gmail users (and of course their is really no way to know if any particular email address is a Gmail user) makes it useless. What, so if I need some docs signed I'll get half of them signed with DocuSign and the other half with Docs? Of course not, I'll just use the product that works with anyone.
Google used to have this same "can only share docs with other Drive users" feature, though it's improved somewhat. In general I think the enterprise doc sharing features are so bad in Drive that the only way I can wrap my head around it is to think that Google is scared of antitrust concerns if they too closely tried to emulate features from the likes of Dropbox, Box and others.
Recently, they have also improved the UI on Google Docs and Gmail making it much less laggy.
On my old NUC computer, it makes a big difference.
It seems that middle-management is becoming a bit less sclerotic.
I’ve seen US Fed agencies reject signed documents when the signature is typed out, so the need exists.
> From the screenshots, I think it is only a fake wet signature. I'm not sure how valid that is
Welcome to 2023! I've bought a house, incorporated a company, signed a work contract and contracted a lawyer just based on Adobe mobile wet signatures on PDFs.
I use the Preview App that comes standard on OSX. You scan a signature on a piece of paper with your webcam. Then you can just "paste it" anywhere, I even give it a dark blue shade.
I had a single person give me shit and say they needed "ink on paper" insisting me to print/sign/scan. I just ran the PDF file through a website that makes it look like it was scanned with some imperfections and tilt. I wouldn't be able to tell it myself.
I don't trust any websites for that. Instead I display the document on the laptop monitor where the page has a white background but everything beyond the page is black. Then I use my phone's builtin scanner to "scan" my laptop screen.
I honestly did look at conformed signatures etc with a desire to do things "properly". However, all too often it was a problem - so fake signature it is.
I do one extra step and "print to pdf" so that signature and annotations (if I have typed in content on a form) are flattened in the final pdf.
Adding to your list, even government documents as well as those related to my medical practice and licensing/registration stating "electronic signatures are not accepted" have taken the wet signature from Apple.
Presumably this is all valid?
This seems perfectly acceptable in my jurisdiction. Then again, Kentucky is pretty laid back. By statute, an electronic signature is just a mark made electronically that is intended by the signer to be a signature. That's about it. Same as if I were to sign by hand, but electronic.
Call me naive, but these laws that make electronic signatures some complicated thing seem messy to me. It's a signature. If you want to verify ID, then do that, but don't conflate the two.
Google Docs have been improving a LOT over the last year or so.
Office 365: Regardless of how you feel about Microsoft products, this is actually a fully featured online version of Word, unlike Google Docs which has a subset of the features and layout.
Notion/Airtable: A good portion of the use cases for Google Docs/Sheets (at least in your run of the mill tech company) are better served by Notion in terms of better structure, components, templates, and so on. The hacks that I have seen people do to get around limitations in Google's suite of products just to do something fairly conventional is a shame.
Wish I never had to use this Google suite of products if it wasn't for my employer.
It got a lot simpler since they nuked tags in favor of folders.
If you're doing contracts, how about a webform where you ask the signatories to answer 5 questions to prove they understand the terms then click submit? That is miles more legally defensible than an e-signature.
IT sign-off and buying new IT services is hard in many large businesses. This means that it's almost always worth using a built-in feature of software you already have, than going for external software. Add to this the fact that companies almost never have one company account, each team re-buys the same software because services are hard, and the fact that most companies already use DocuSign matters a bit less.
Much of Slack's growth has been built on this[^1]. You can sign up for a free account and start inviting your immediate team. Paying for a small team is well under the typical auto-approved expenses limit, and when you've sunk your cost, got a bunch of people onboard, and proved the value, only then do you go to IT to get it rolled out across the business.
Individuals using this sort of thing, termed "shadow IT", is a good way to grow usage. This feature of docs seems well positioned to grow that way even if DocuSign is available.
[^1]: I worked on a team that was required by the business to use MS Teams. While we waited for the Teams workspace to be provisioned and all the authentication crap to be sorted out we signed up for Slack, invited everyone, and got work done for the 6 months it took to get a working Teams workspace.
Major limitation for now though is:
> Non-Gmail users: the ability to request an eSignature from non-Gmail users
Hopefully it's addressed sooner (September/October) rather than later (November/December).
Although strictly speaking if they would only want to do AdES and not QES, they wouldn't have to be in the EU Trusted List, would they?
It's like a gadget in Europe then.
But still, it is useful.
It can be used if you want to ask your daughter to promise to "Get good grades at school" in exchange for an extra Christmas gift, for example.
And make it look like official.
It's like pretending to be signing.
A partner company willing to test it is going to take 3 months to review and choose to adopt it, another 3 months trying to convert a few internal flows, and another 6 months to observe how it changes processes and whether it's an improvement or not.
The point here is to get it right, not to get it quick. Enterprise software is the literal opposite of "move fast and break things".
Seems all we need is:
Consent to do business electronically — All parties must agree to conduct transactions electronically, either explicitly or implied.
Intent to sign — E-signatures are only valid if the signer intended to sign. Signature requests need to be declinable.
Association of signature with the record — Signers must make a visible mark or statement on the e-document.
Attribution — Whether a name or a unique mark, the signature must be attributable to the person signing and only linked to them.
Record retention — Signed electronic documents must be saved, viewed, or printed by either party and stored for future reference.
DocuSign on the SSO Tax site: https://sso.tax/
I would like esignatures to be backed by strong electronic authentication, like EIDAS
...vs cryptographic proof someone had access to your ID card
Which isn't what we are discussing here, this was the point… :)
At least their terms of service don't suggest any kind of general legal indemnification of customers, only a limited one around loss of confidentiality caused by security breaches in their systems.
https://beststocks.com/jump-financial-llcs-significant-reduc...
Those articles are auto-generated from regulatory filings. Down in that article they write about a 270 share investment, that's neither size nor notable.
I should have known better.
In countries with legally binding digital signatures (I.e. Argentina) you need a cert issued following identity verification.
Most countries that accept eSignatures don't require digital certificates. There aren't many other countries as strict as Argentina. See for ex https://www.hellosign.com/blog/electronic-signature-laws-aro...
On what basis is it determined that particular signing tech is admissable
https://www.businessinsider.com/judge-ruled-thumbs-up-emoji-...
It’s also been statute since 2000 [1].
[1] https://en.m.wikipedia.org/wiki/Electronic_Signatures_in_Glo...
Also, I wonder if the person signing the document has to agree to Google's entire ToS in order to sign the document.
Congress could fix both issues with some well-thought-out legislation:
- Signatures from these things have to support external validation via standard tools (e.g., Google uses PGP or whatever to sign the signature + document + metadata).
- If the act of accessing or signing a contract implicitly incorporates other contracts, then either (a) the signature is non-binding of (b) the incorporated contracts are rendered unenforceable, regardless of whether they were agreed to via other means.
“Google Docs ships with esignatures now… but how long until Google kills another one of their products? Stay safe with DocuSign, import your Google Docs signatures and keep them forever, with or without Google.”
Hm... I briefly was a part of the Google Toolbar team back in 2008. How would it be relevant today? All of the features that I remember, are now a part of the browser itself (whether it's Firefox, Safari, Edge or Chrome/Chromium).
That said, the eSignature for Google Docs feature would definitely benefit from some strong (preferably, legal & irrevocable) commitment to keep it alive for 40+ years or more. Otherwise, I fail to see how it's useful.
I know I’m beating a dead horse^W^W^W dead Google products but, they really do kill a lot of popular products
That being said, if they add eSig for Google Docs I agree; I don’t see why nor how they’d kill that individual feature unless they kill Docs all-together. Which, hopefully, they won’t do for many years yet.
So how come I can't access chats from before mid-2013? Not even by Google Takeout?
(It so happens that some of the most important conversations in my life happened in 2012, so I'm to date super annoyed that, for no good reason, 2013 is some kind of cut-off date.)
inbox vs gmail play music vs youtube music
Much of the listed "casualties" were throwaway wrapper apps that have perfectly fine webapp replacements, apps for platforms that no longer exist, duplicates, and stand alone apps that are now features of bigger apps etc.
https://chat.openai.com/share/9b69427a-b28c-4080-b097-6a0a78...
The HN/LLM concordance ratio is approaching 1. Eventually, I can just remove comments and then fill them in with ChatGPT instead.
True, but is this no pricing? At a glance it appears to be available only to Workspace customers, which I believe you have to pay for (at least I've been paying for it for years).
I'd argue it's the least valuable data. They can't look at it, they have regulatory, legal and contractual commitments to protect it, they have paying customers that will be very angry if it's lost or unavailable, and yet they can't mine it or train models with it or monetize it.
I can only imagine the pain this will cause people when they try to execute/sign a contract, and Google randomly locks your account … preventing you from logging in.