Show HN: OpenSign – Open source alternative to DocuSign
github.com
github.com
Is that the case? And if so, is there evidence OpenSign has done this kind of SME research to make sure the electronic signatures are legally binding, or is this more "we brought in some devs and UI designers and built something" without actual legal review and guidance?
For the US one, at least, they give examples of where electronic signatures are pretty common and straightforward, and where you need to be careful.
Software-wise, they have features to help you show evidence of who signed, where, and when in multiple ways. Nothing magical, though.
If there were secret sauce, you would think they’d mention it prominently, but they don’t.
https://www.docusign.com/products/electronic-signature/legal...
Eh sorry, I’m just sad about Rocket Chat.
To be fair, this is an entirely reasonable way to do business, but it's also a bit funny.
Nothing prevents an AGPLv3 fork if OpenSign goes proprietary in future.
I'd rather this approach than yet another non-standard Amazon-proof licence.
Couldn't they have accomplished that just by asking for GPLv3 instead of AGPLv3? That would let them do so without letting them make the self-hosted version non-free, unlike asking for MIT.
> Nothing prevents an AGPLv3 fork if OpenSign goes proprietary in future.
Yes, but this would be true for almost any FOSS license offered and regardless of what they ask of contributors.
> I'd rather this approach than yet another non-standard Amazon-proof licence.
I very much agree with this.
Covid made this acceptable.
Who holds the secret key that actually signs the document? If this is in fact a self-hosted, open-source, project then clearly the user does, and they could sign a different, tampered, version of the document after the fact. I would hesitate to use the term "tamper-proof" in that situation. Right now your documentation doesn't make it clear how this actually works.
I'll also point out, that even if you were using my OpenTimestamps scheme or some other secure timestamping system, I would still hesitate to call the solution "tamper-proof". The problem is that even with timestamps someone can in many situations pre-generate alternate versions of a document in advance. Calling this type of system "tamper-resistant" is better IMO.
This,fortunately, is a feature of the PDF digital signatures standard.
DocuSign supports those mainly through some interop connections where, for example, a qualified signature vendor provides an API that DocuSign can use to sign the document.
It was odd because I handled federal and state contracts in previous job, they don't have a problem with e-signature.
These are the regulations you’ll want to adhere to in order to provide parity with digital signature authority of traditional commercial providers (in the US at least).
Great work btw!
(Not an attorney, not your attorney, but happy to chip in fiat so you can consult with counsel and obtain an opinion letter from one in support of your project)
So, if you look at e-sign, UETA, and NY’s Electronic Signatures and Records Act, then you have fairly comprehensive coverage across the US.
Also not an attorney, and this is also definitely not definitive legal advice!
Edit: I suppose in all except the free self hosted one, OpenSign would be the trusted third party, which I guess is more plausible. Unless the paid customers are given something close to root to administrate them. Still, a trusted third party is generally based on recognition. Even if I really dislike a company I eventually acknowledge they're trusted if it lasts long enough, like with ID.me. I didn't use ID.me until it was required for logging into the IRS and now I grudgingly admit that I think it's an extra security check on logging in. So until you're big like DocuSign I wouldn't view you in quite the same way as a trusted third party.
That does bring a question, are your paid customers prevented from going under the hood in such a way that they would also have to be trusted at such a level along with OpenSign?
--
This to say I'm open to using OpenSign, because there are plenty of uses where I would be open to using something that doesn't have this "trusted third party at the level of DocuSign" feature. The "digital notary public" analogy is apt. I sometimes sign documents with a notary, and other times without.
So that leaves the challenge of becoming a well known trusted third party, which is a challenge but doable.
If there’s a dispute over the veracity of a signature, it’s probably helpful to have a third party say “according to our server logs and software stack, this was signed by johndoe@example.com at 12:41pm on August 3rd, from the IP address XX.XXX.XXX.XX, and they authenticated with their email and password”. If I’m self-hosting, it’s marginally less convincing when I’m before a court if I say *my* software stack says that, since I have more direct control over it.
So, I agree DocuSign doesn’t have a special status, other than being a relatively neutral third party to that dispute. But if a signature’s validity is being questioned, that third party status is probably somewhat helpful.
Disputes over eSignatures come up allllll the time. And if you mention that it was "DocuSigned"... although you have done nothing aside from name-dropping... it will essentially end the dispute. Not saying that it should. Just saying that it does.
Edited to add: mild disclosure, I’m working on a product that has e-sign as a feature. It’s not really the main thrust of the application, but probably worth mentioning here.
Article 26 (linked below) describes the requirements for an electronic signature to be legally binding.
https://www.eid.as/#article26 https://en.m.wikipedia.org/wiki/EIDAS
If something is hard, that's an argument for making a standard not for profit version of it, so it becomes a common good instead of platform rent seekers keeping out competition by saying it's "too hard".
Like a slumlord who collects rent and does nothing to even maintain the property. Except perhaps vote down YIMBY reforms.
Rent seeking would be designing a product for collecting rent (not a one time payment) for a product (e.g. SaS) that doesn't wear out or has separate maintenance costs. Like a house that is rented the value comes from the income stream and it likely is adjusted by something like inflation.
Not renting would be selling a product for a one time fee, perhaps even if there are many customers (you still get to play ticket pricing games like the airlines so different people pay different amounts at different times, but not as variable as rent). Making the product non-transferable blurs the rent line a bit. Also not rental is the maintenance or improvement on the product (or the house) since that is new work that is being done.
It used to be that only physical objects were rented and services were inherently work and required new effort/ingenuity to be solved each time. However, with the introduction of art reproduction (visual, audio, physical) and copyright/patent, as well as, non-perpetual licensing of software this is no longer the case. It's possible to hold a piece of intellectual property and collect perpetual rent with little or no future investment.
It does create a different incentive structure that can be quite customer hostile.
It's not just general and optional recurring payments.
- actual rent-seeking (as you say, not really true for companies such as Microsoft and Google, except where you see e.g. government documents needing to be submitted in Word. But that's very likely incompetence on behalf of the bureaucracy rather than Microsoft)
- having a dominant market position due to having a very high quality product, or set of products that work together well
- a random grudge phrased as rent-seeking, because the Twitter user in question doesn't know what rent-seeking is, but has seen their friends accuse companies of it
I don't know what the proportions are, but I suspect the former is minimal to nonexistent for e.g. Google.
The Federal Esign Act provides: 15 USC 7006(5):
The term “electronic signature” means an electronic sound, symbol, or process, attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign the record.
When dealing with government entities, you may run into policies of those entities that require use of a pre-approved service. For example: https://www.sos.ca.gov/administration/regulations/current-re...
All that said, I have both implemented electronic signature in my own software and reliably recommended clients running sales ops just buy DocuSign. Familiarity and credibility can matter way more than legal or technical details...or not at all.
While I think that’s generally true that online signatures are acceptable in most circumstances, I’d be careful to blindly believe it as a blanket statement.
What happened this year specifically?
Dobbs was in June 2022, but that isn't even close to the first time that the Supreme Court overturned precedent from 50+ years prior -- Brown v Board largely overturned Plessy v Ferguson ("separate but equal") from nearly 60 years prior.
And, we've had plenty of Supreme Court precedents overruled since the 19th century. According to Congress: https://constitution.congress.gov/resources/decisions-overru...
(Most of those never rose to the level of landmark decisions, but Plessy certainly did.)
The legal precedent was made in the initial supreme court ruling, all someone needed to do in the legislature is codify it into law.
But no, laziness and re-electabilty on both sides, led to the ruling being overturned in the second examination of Roe.
Eliminating abortion protections was based on "we don't think the founders meant that" which is a form of consideration never before used.
This kind of test is effectively in the eye of the beholder. You can say whatever you want and disproving it requires Goldilocks evidence.
You can't talk about the case law the American system was based on even if it was adopted wholesale and unchanged. You can't talk about the intervening decades and how the legal system handled things.
You need to basically quote the founding fathers talking about a specific topic or the Supreme Court can say "no I disagree" and overrule you.
Textualism and originalism have been in play for decades -- off the top of my head: 2008's DC v Heller basically codified today's broad interpretation of the second amendment's protections.
I don't personally agree with the decisions (among other things, the resulting patchwork application of laws has meant that your access to abortion is dependent on how strong your state's Democratic bent in the statehouse(s) is), but it's not novel to the past decade, even. The only new development from the past 5-10 years is the presence of 5 votes on the court willing to overturn Roe's long-standing precedent.
Of course it is similar it was a test bed to pull this.
At least DC v Heller could point to actual facts to back up it's interpretation. Dobbs just dances around the idea saying "we believe" a lot and super focusing on the Supremacy clause in a way not seen in... I couldn't even say how long ago it was that the SC said it couldn't restrict something in that way.
What, the Federalist Society? In as far as the last three justices willing to overturn Roe were hand-selected by them, yes, but there was little doubt that any of them would vote to overturn Roe even before their confirmations.
> At least DC v Heller could point to actual facts to back up it's interpretation. Dobbs just dances around the idea saying "we believe" a lot and super focusing on the Supremacy clause in a way not seen in... I couldn't even say how long ago it was that the SC said it couldn't restrict something in that way.
On one hand, there's a difference between who authored those opinions (say what you will about Scalia, but his application of originalism didn't have as clear of a partisan bent). On the other, there was clearly an effort to thread the needle such that both Thomas (who wanted Dobbs to go so much further) and Roberts (who has started to think about his court's legacy and its public perception) were willing to sign onto said opinion.
I suspect we would have had the same style of opinions 5 years ago if it had been Ginsburg instead of Scalia who passed away in 2016.
I am not saying he is partisan but it is hard to say he is neutral when Originalism has been used as a hammer to eliminate Liberal ideas like "maybe we shouldn't regulate modern guns used to kill dozens like muskets" or "what right does the state have over what health care a woman chooses with regards to the most dangerous thing she will do in her life".
I'm not saying Roberts is actually neutral, for what it's worth. He just doesn't want his court to be seen as particularly partisan. He and Kavanaugh are just the closest we have to the center of the current court.
https://www.nationalnotary.org/knowledge-center/remote-onlin...
Essentially, "no one ever got fired for signing with DocuSign" (play on IBM).
I'm late to the party here, but if the authors want real world examples, please reach out.
Documents from/to any agency, including anything that has any tax relevance, - generally speaking (there are many caveats) - shall be signed with services compliant with the e-signature standards provided by Regulation 2014/910/EU (in short: PADES, CADES, XADES).
Out of curiosity: is there a similar requirement in terms of e-signature in the US when documents need to be sent to some agency, such as the IRS?
The purpose of someone like Docusign is to provide a trusted third party to provide evidence.
For most purposes GPG signed email (or anything else with a similar signature) would work perfectly well provided you could prove who the keys belong to. In fact it would be better than DOcusign who can (from the few documents I have signed) ultimately only really show they sent an email with a signing link to your email address.
The last one from them has a warning:
"Do Not Share This Email This e-mail contains a secure link to DocuSign. Please do not share this e-mail, link or access code with others."
Docusign always saves the IP addresses and timestamps for any signatures. In addition it can be set up to require 2FA prior to accepting a signature - eg our lawyers will set it up to require an SMS 2FA confirmation and I've heard them say that this is a hard requirement for deeds as opposed to simple contracts (tho whether that's down to law firm policy, Docusign policy or court precedent I don't know).
FYI, USAGE.md seems to be missing.
Also, a suggestion: while I agree with other posters that this isn't a replacement for the third-party trust model DocuSign provides, you might as well use my OpenTimestamps project to timestamp the documents OpenSign produces. Being able to prove that a document was in fact created in the past, before a dispute existed about the document, is significantly better than not being able to prove that. OpenTimestamps is free and open source, using Bitcoin so that you don't have a trusted third party. Timestamps made with OpenTimestamps are free, as merkle trees are used to allow the whole world's documents to be timestamped with a single Bitcoin transaction.
A good example of how it's been used recently is by the official election authority in Guatemala to timestamp polling documents in their recent presidential election: https://www.youtube.com/watch?v=g0nnM5_Z90E
https://github.com/OpenSignLabs/OpenSign/blob/main/INSTALLAT...
And it says you can auto-deploy to DigitalOcean (neat) and to a local server, and instructions are included for both.
There's the bit on AWS S3 which makes sense but then no build/install instructions for local deployment. are those somewhere else?
The org I work for would love to self-host on-premise a digital signing solution so they definitely won't use external dependencies like AWS. Theoretically they could swap with minio but last time we used it it was not a drop-in replacement yet.
It's not a problem if Minio is bundled into the self hosted stack as long as it's officially supported (paying for support is also okay).
Depends on whether AGPLv3 works for you or not (or whether you decide to pay them), I guess: https://min.io/pricing
I've actually been looking for more open alternatives, but haven't found much.
Zenko CloudServer seemed to be somewhat promising, but doesn't seem to be managed very actively: https://github.com/scality/cloudserver/issues/4986 (their Docker images on DockerHub were last updated 10 months ago, which is what the homepage links to; blog doesn't seem active since 2019, forums don't have much going on, despite some action on GitHub still)
There was also Garage, but that one is also AGPLv3: https://garagehq.deuxfleurs.fr/
The closest I got was discovering that SeaweedFS has an S3 compatible mode: https://github.com/seaweedfs/seaweedfs
Not only that DocuSign does ID verification if you pay them which is required for a bunch of contract types. This does definitely not!
No open source startup is going to win there because it's about entities and process, supported by technology not technology on its own. The technology is absolutely worthless without the framework and legal entities surrounding it. It's a unique position no one really understands that well.
A digital signature is a legal construct that stands up in court.
The movement might have begun, but you need to change your perception. You have to stop talking like a technocrat and address the business problem that signatures solve.
Not losing it is another.
The people to preserve trust with are all potential signatories (ie. the public), not the initiating counterparties. Because there are many more of them.
Of course this reputation problem is one you'll share with banks, PayPal and every other "official" type entity that phishers want to jump on.
Now most "Docusign" communications go straight to my spam folder or /dev/null if arriving by email and not from (forwarded) a whitelisted business I already have a relation with. Those that come directly from Docusign (as sender even if DKIM passes) are ignored unless I think there's a reason to be contacted.
Docusign is one of the juiciest spoofing targets for phishing attacks because people act rashly to what they think is something requiring a signature. They also have no timeout on repeat sends, relentlessly spamming users to sign something, which makes them look exactly like, well.... phish-spammers.
Try not to make these same mistakes as Docusign.
Of course, I also used https:/.opentimestamps.org to store the hash of our contract on bitcoin's block chain, because that way we both had proof that the contract existed in a certain form on that date. (I never needed that proof, because he was a good landlord, and I paid rent on time.)
My point stands, legally either a signature has to be notarized or it doesn't. If it doesn't, any signature can be effective. I'll agree that 3rd party hosting provides an element of independence, however, legally it's not required, and could be done by anyone. E.g., a self-hosting a solution that required the signer to upload a video of them clicking I AGREE would provide just as much certainty as anything Docusign can.
It's not the technical infrastructure, it's about trust. LE only solved the problem of safe transport, but not verification of authenticity of the endpoints. That's what incurs such cost.
What's even worse is that in Germany most companies and authorities refuse to accept those digitally signed PDFs.
Since the project is open-source, update the documentation with local setup, architecture, design decisions made
[EDIT]: referring to (my own) article: https://vadosware.io/post/the-future-of-free-and-open-source...
One thing I do think that people misunderstand is that a company can absolutely take your project and run it as a service -- they just have to contribute code back if/when they modify it.
The real canary is requiring signed CLAs.
I guess that's one way around the CLA -- they don't need one if they force all contributions to be MIT in a file most people wouldn't read.
In the end people the actual likelihood of someone making a credible legal threat is low so it all seems somewhat spurious but great way to go around the overt beacon that requiring CLA signing is.
[0]: https://github.com/OpenSignLabs/OpenSign/blob/bb846442ecbaa3...
> There’s one caveat everyone is missing this is only a problem if you planned on modifying the software and not contributing back!. If you either do not modify the software or contribute back your changes you’re free to host and offer services built on AGPL.
I'm a bit worried about what all these companies will do once smaller/larger players change their stances appropriately and start hosting their software as a service. Will people run to BSL/Elastic/SSPL?
Otherwise anybody could run the service and pretend that anybody else signed any documents they want at any time they wanted.
I am not familiar with DocuSign internal but it looks like people are identified by their email. So only if you can click the link received in their email, it can be them.
I guess a problem with DocuSign is still that anybody can sign up for a new email and pretend to be anybody they want.
If there’s anyone familiar with this or from the product team would sincerely appreciate any insights on this scenario.
Looking at the AGPL license, where would the licensing prevent or impact building an independent source code plug-in to integrate n to a piece of software that calls the hosted service via API, or an unmodified self-hosted copy?
For me it helps spread awareness and use of a well made open source signature tool.
Why would you want to store nuclear waste? Think about it. Even if you can, is that really what you want? Forever?
There are probably more incentives and less legal liability storing nuclear waste than sensitive documents.
It's not that other companies cannot do it, it's that nobody wants to do it.
I ask because I am genuinely curious and hoping to learn a bit about IP law.
Theft is theft, no reason to get IP law involved.
Infringement can happen without intent. I don't know who would be liable, the open source company with little revenue, or the customers who are just using the software.
Say big Hooli company builds product/platform “A” and charges arm and foot for usage. Having tried the platform I personally find it ridiculous anybody is paying for this because I successfully (lone developer) hack together a trimmed down working clone of the core system *in under a week*. Furthermore, core aspects of Product/Platform “A” are open-source technology, in non trivial ways (like I’m not saying “oh they use YML for config files”, I’m saying “core engine component they’re using is explicitly open source”).
If I decide to open source my clone, am I asking for trouble?
This is all hypothetical, I’m not soliciting actual legal advice.