Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Mac’s pdf viewer Preview has a signature capture feature built in that’s pretty slick. I use it all the time and haven’t encountered an objection. Tbh I’d wonder why you need to fuzz up and fake scan the image. If someone’s requiring that the doc be “signed in ink” or some such, more power to you!


From the link:

"For bureaucratic reasons, a colleague of mine had to print, sign, scan and send by email a high number of pages. To save trees, ink, time, and to stick it to the bureaucrats, I wrote this script."

So yes, it does seem like there are situations where a "digital" signature is insufficient.


My bank sometimes requires a “wet” signature and have rejected digitally signed PDFs from MacOS Preview before. This tool will come in handy.


My bank used to reject scans but accept faxes... bureaucratic reasons.


I don't know directly, but I've heard that there are special laws regarding fraud via fax. Even though fax has no technical protection, it may have legal ones, that might give the counterparty some recourse if things went bad.


In Germany, a fax is legally considered an original copy, a scan/print is not, despite a fax often being a scan that’s then transmitted via fax protocols. Law hasn’t caught up with technology yet in that area.

You also get a confirmation from the recipient when using fax.


All the while we actually have a pretty good law about digital signatures since basically forever, but ~nobody supports those. (and they missed the chance of using the new ID cards to establish them more widely, which was really stupid)


> despite a fax often being a scan that’s then transmitted via fax protocols

...what's the alternative to that "often"? What is a fax machine, if not a scanner attached to a modem?


Dialup modems speak the protocol, or at least they used to, so it was possible to send or receive a fax without a physical copy of the document. Just by "printing" from word to the modem and entering a phone number. I remember writing an excel macro to iterate over a list of customers and send a personalized word document to them. (This was 20 years ago I think and not all of our customers had an email)


VoIP fax services. Webpage allows upload, sends the fax over voip, which ends up at another voip server, decodes back into a fax. Never turns analog.


Conventional fax machine transmits document while it scans it as it has (almost) no memory. Like analog TV camera, just much slower.


Sure, but that's still "a scanner attached to a modem." Nothing about a scanner implies that it must buffer the input, just like nothing about a printer implies that it buffers the output.

There are/were "line printers" doing "latch a character from the input line, print the character, unlatch" serial output (which were so common that Unix pipes are designed around the foibles of outputting to such devices.) Most POS thermal receipt printers are still line printers!

I don't know as much about scanners, but I can't imagine that the original (digital, attached to a computer) scanners weren't also "serial scanners"—i.e., rather than a 1D scan head with a long CCD strip that could latch an entire line at a time into a shift register, they would have had 2D scan-heads that would scan one pixel at a time, in a "read brightness, signal ready, wait for return line to unlatch" serial loop. No memory required, just terribly slow.


When the relevant laws were made, fax machines were purely analog devices, not a scanner attached to a modem. And once fax was legally privileged, it stuck around exactly because it was legally privileged - despite the change in technology.


Again, my question:

> fax machines were purely analog devices, not a scanner attached to a modem

Why would an analog scanner not still be a scanner? I'd call whatever component that's in even the oldest fax machines "a scanner." Even if it is "enitrely analog" (continuous brightness intensity read, like a tape head or record-player stylus) you'd still call the process of converting light from a sensor passing over a document, into electricity, scanning, and you'd still call the component that does that "a scanner." Just like speakers and microphones are still "speakers" and "microphones" whether they're just transducers attached to wires, or have a whole ADC+USB/Bluetooth signal path leading out of them. Am I wrong?


Yes, in the same sense that an analog telephone is recording you by translating your voice into electricity. But, at least to me, if it is voice -> electricity on wire -> speaker, it feels much less like recording than saving a buffer of voice in memory, packetizing, and then sending, even if they are both just electricity on a wire.


Everything has Colour, not just bits


Sounds like their document management system was tied to a fax line and they didn't want to bother upgrading. IT departments at banks have like, zero budget.


I read on NH yesterday (or perhaps the day before) that in the USA HIPAA (Health Insurance Portability & Accountability Act 1996) carves our a special exemption to consider faxes ‘secure’.


It does.


Faxes are considered secure.


I'm declaring myself as considered a Triceratops . Doesn't make it true.


If you pass a law stating you are a Triceratops, it would become 'true' in the legal sense... and since we are dealing with legality, it being declared 'secure' does matter


It depends on the threat model. If I need to prove to a court in the US, then I'm signing paper and faxing it. To do it differently would be more expensive to prove.


Right, the legal system considers it secure.

I'm talking about the technical sense. Where there is no encryption at all, anyone with a phone line splitter can listen in, and the machines are usually not in a secured area so anyone could just pick up the fax and walk away. Not secure at all.


I don’t think you need to argue that fax is not technically secure on HN. Pretty sure we are all on the same page there. What matters is legal precedent and existing policy in various countries.


> I don’t think you need to argue that fax is not technically secure on HN. Pretty sure we are all on the same page there.

dd36 and swixmix seem to be taking the other side of that argument.


If I were taking that side, I wouldn’t have qualified my statement. Gov’t and courts consider it secure. HIPAA compliant, etc.


It depends on what your threat model is. The attacks you're talking about are real, absolutely.

For the threat model of a physically local attacker with either the right timing (for grabbing an incoming fax) or the right knowledge (for the phone system equivalent of tcpdump), you're quite right that fax is insecure. Likewise for state sponsored adversaries or certain organized crime groups.

But if you just want to make it hard for people scanning the internet to see what juicy corporate espionage they can find and resell, without specifically targeting you, fax is probably less vulnerable to that threat model than, for example, an undermaintained email server. Likewise if you piss off script kiddies somewhere on the internet with botnets and exploit kits, your website is probably a bigger risk than your fax machine.


They're secure in the sense of being low-risk for active content shenanigans and a small surface area for vulnerabilities. Attacking a network through a .tiff of a fax is a lot harder than attacking it through an email, pdf, word doc, http session, etc.


Behold...the power of lobbyists. Fax industry sure got their money's worth that year that passed.


Schwab (the bank in the US) started rejecting my signatures, on the basis that several documents I submitted had identical signature images. I worked around that by making a new signature, but you could imagine them escalating to also complaining about the fact it was not wet ink.


I had an application to open a new bank account rejected because my signature was not close enough to the one they had on file. I tried resolving things over the phone, but no luck. So I closed all my other accounts and switched to a different bank.


I had a similar problem once at my bank while submitting some inconsequential form but for bureaucratic reason the signature in the form had to match with what they had in the file.

As I had opened account with them years back, I couldn’t recollect what I had signed then. The clerk at the desk helpfully turned her display for me to take a quick glance at the signature in the file which I copied in the form. Thanked her well.


Several years ago my bank had to store three signatures because I couldn't (and still can't) produce two identical ones. Last year I had to update some documentation and they had to store two more signatures, so now I have 5, but any other signature will be different anyway. The reason is likely that, as a leftie, since being a kid I had to suffer a few attempts to force me writing with the right hand, something I trained by myself much later in my 20s out of curiosity, but quickly forgot due to lack of practice. I never perfected my horrible handwriting and resorted to block capitals immediately after school; then computers and printers solved the problem. Unfortunately it seems there's no way to get rid of this archaic thing called signature that for me translates into wasting lots of time; I'd rather leave a blood sample on paper if I could:)


Interesting, but makes sense they check documents for that.


I love this feature of Preview, though I also sometimes have people that insist on receiving a wet ink signature...

Dropbox's "Scan Document" feature is great for getting around that. It turns a photo into what looks exactly like a scan. I just sign the document in Preview, and then use the Scan Document feature to just "scan" the document as its displayed on my screen. The result seems indistinguishable from a printed wet ink copy also scanned with Dropbox.


A scanner is just a really elongated camera so this is a pretty good way to emulate it


The reification of signatures and paper documents has to stop.

I can set up Apple Pay and use it across devices to make payments worth tens of thousands, but I can’t use the same technology to authenticate a document.

It really boils the blood.


I can't for the life of me understand why the only valid ways to save a signature image for Preview is (1) your computer's camera, and (2) scrawling on the touch pad.

I have a previously-scanned signature that I'd like to re-use. I'd love to simply import the file. Instead I have to print it out and then hold it in front of the camera, trying to get it aligned. It's madness. Is it supposed to be more secure for some reason?


Why do you need to print it? Is it so difficult to redo your signature? That shouldn't be so difficult for you...


Sometimes a printer is closer than a pen, unfortunately....


And, importantly, its location is more predictable.


Can't you just drop a .png on there? I think that works and adds it to the library. But I might recall that from somewhere else.


Every bank application I've done has required print + sign + scanned, I got refused when I tried sending them PDFs signed in Preview/Acrobat


thankfully over here they have to honor digital signatures, no exceptions.


Yep, and here the government even provides you with a free qualified certificate to sign.


That doesn't work for the US, because any constraints on use are politically unpalatable. Any capability that the government creates thus turns into a security vulnerability to be exploited by business.

For example, even just assigning everybody unique identifiers (social security number, drivers' license number) has allowed businesses to demand these identifiers to track customers in privately-held surveillance databases. This system has already grown out of control with little sign of stopping.

A "secure" e-signature token would lead to even more businesses demanding your "identity". Imagine having to pay twice as much for groceries for wanting to keep your purchases personal!

I'd much rather suffer the small work of (print, sign, scan, cache, burn) until I see some reigning in of private surveillance databases.


SSNs are problematic because they are expected to be both public and confidential. In reality, they're public.

The federal government refuses to issue actual public IDs, which would solve the problem nicely, for political reasons. They can't retract Social Security.


That is one reason they're problematic, but not the problem I described. Public IDs would make the problem I am describing worse, as even more businesses would unashamedly ask for them. People's feeling of "oh isn't that private" is one of the few things holding back everyday retail businesses from asking for them.


I don't think it would be any worse than the status quo. Some businesses might not ask for your SSN in particular, but adtech can identify you pretty uniquely regardless. And in the meantime, a million businesses have your sensitive, private SSN, and a relatively high risk of data breach.


have you considered adding a good PII protection laws to circumvent that? GDPR seems to work pretty well.


Yeah. but the signature will simply be a new layer on the PDF. So you can: 1) replace it easily. 2) Extract the signature without any jpeg noise.

Also, I like rasterized contracts / text, instead of a small pdf + an image, as it's easier to tamper with


I used that for some mortgage documents (pre-closing) that they could email me, but needed a 'wet' signature. I happened to be out of town so accessing a printer and scanner wasn't easy.

I used Preview for the longest time before they questioned 1 of the documents.


I only had issues so far when I accidentally didn’t convert the signed page back to an image.


I wonder if you can use "print to PDF" after the signature has been attached to the PDF.


This is what I do. However, my bank has occasionally rejected PDFs because all the signatures were identical, indicating the use of a digital stamp.


This is why,overtime, I have scanned few more versions of my signatures & converted them to a font.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: