Mac’s pdf viewer Preview has a signature capture feature built in that’s pretty slick. I use it all the time and haven’t encountered an objection. Tbh I’d wonder why you need to fuzz up and fake scan the image. If someone’s requiring that the doc be “signed in ink” or some such, more power to you!
"For bureaucratic reasons, a colleague of mine had to print, sign, scan and send by email a high number of pages. To save trees, ink, time, and to stick it to the bureaucrats, I wrote this script."
So yes, it does seem like there are situations where a "digital" signature is insufficient.
I don't know directly, but I've heard that there are special laws regarding fraud via fax. Even though fax has no technical protection, it may have legal ones, that might give the counterparty some recourse if things went bad.
In Germany, a fax is legally considered an original copy, a scan/print is not, despite a fax often being a scan that’s then transmitted via fax protocols. Law hasn’t caught up with technology yet in that area.
You also get a confirmation from the recipient when using fax.
All the while we actually have a pretty good law about digital signatures since basically forever, but ~nobody supports those. (and they missed the chance of using the new ID cards to establish them more widely, which was really stupid)
Dialup modems speak the protocol, or at least they used to, so it was possible to send or receive a fax without a physical copy of the document. Just by "printing" from word to the modem and entering a phone number. I remember writing an excel macro to iterate over a list of customers and send a personalized word document to them. (This was 20 years ago I think and not all of our customers had an email)
Sure, but that's still "a scanner attached to a modem." Nothing about a scanner implies that it must buffer the input, just like nothing about a printer implies that it buffers the output.
There are/were "line printers" doing "latch a character from the input line, print the character, unlatch" serial output (which were so common that Unix pipes are designed around the foibles of outputting to such devices.) Most POS thermal receipt printers are still line printers!
I don't know as much about scanners, but I can't imagine that the original (digital, attached to a computer) scanners weren't also "serial scanners"—i.e., rather than a 1D scan head with a long CCD strip that could latch an entire line at a time into a shift register, they would have had 2D scan-heads that would scan one pixel at a time, in a "read brightness, signal ready, wait for return line to unlatch" serial loop. No memory required, just terribly slow.
When the relevant laws were made, fax machines were purely analog devices, not a scanner attached to a modem. And once fax was legally privileged, it stuck around exactly because it was legally privileged - despite the change in technology.
> fax machines were purely analog devices, not a scanner attached to a modem
Why would an analog scanner not still be a scanner? I'd call whatever component that's in even the oldest fax machines "a scanner." Even if it is "enitrely analog" (continuous brightness intensity read, like a tape head or record-player stylus) you'd still call the process of converting light from a sensor passing over a document, into electricity, scanning, and you'd still call the component that does that "a scanner." Just like speakers and microphones are still "speakers" and "microphones" whether they're just transducers attached to wires, or have a whole ADC+USB/Bluetooth signal path leading out of them. Am I wrong?
Yes, in the same sense that an analog telephone is recording you by translating your voice into electricity. But, at least to me, if it is voice -> electricity on wire -> speaker, it feels much less like recording than saving a buffer of voice in memory, packetizing, and then sending, even if they are both just electricity on a wire.
Sounds like their document management system was tied to a fax line and they didn't want to bother upgrading. IT departments at banks have like, zero budget.
I read on NH yesterday (or perhaps the day before) that in the USA HIPAA (Health Insurance Portability & Accountability Act 1996) carves our a special exemption to consider faxes ‘secure’.
If you pass a law stating you are a Triceratops, it would become 'true' in the legal sense... and since we are dealing with legality, it being declared 'secure' does matter
It depends on the threat model. If I need to prove to a court in the US, then I'm signing paper and faxing it. To do it differently would be more expensive to prove.
I'm talking about the technical sense. Where there is no encryption at all, anyone with a phone line splitter can listen in, and the machines are usually not in a secured area so anyone could just pick up the fax and walk away. Not secure at all.
I don’t think you need to argue that fax is not technically secure on HN. Pretty sure we are all on the same page there. What matters is legal precedent and existing policy in various countries.
It depends on what your threat model is. The attacks you're talking about are real, absolutely.
For the threat model of a physically local attacker with either the right timing (for grabbing an incoming fax) or the right knowledge (for the phone system equivalent of tcpdump), you're quite right that fax is insecure. Likewise for state sponsored adversaries or certain organized crime groups.
But if you just want to make it hard for people scanning the internet to see what juicy corporate espionage they can find and resell, without specifically targeting you, fax is probably less vulnerable to that threat model than, for example, an undermaintained email server. Likewise if you piss off script kiddies somewhere on the internet with botnets and exploit kits, your website is probably a bigger risk than your fax machine.
They're secure in the sense of being low-risk for active content shenanigans and a small surface area for vulnerabilities. Attacking a network through a .tiff of a fax is a lot harder than attacking it through an email, pdf, word doc, http session, etc.
Schwab (the bank in the US) started rejecting my signatures, on the basis that several documents I submitted had identical signature images. I worked around that by making a new signature, but you could imagine them escalating to also complaining about the fact it was not wet ink.
I had an application to open a new bank account rejected because my signature was not close enough to the one they had on file. I tried resolving things over the phone, but no luck. So I closed all my other accounts and switched to a different bank.
I had a similar problem once at my bank while submitting some inconsequential form but for bureaucratic reason the signature in the form had to match with what they had in the file.
As I had opened account with them years back, I couldn’t recollect what I had signed then. The clerk at the desk helpfully turned her display for me to take a quick glance at the signature in the file which I copied in the form. Thanked her well.
Several years ago my bank had to store three signatures because I couldn't (and still can't) produce two identical ones. Last year I had to update some documentation and they had to store two more signatures, so now I have 5, but any other signature will be different anyway.
The reason is likely that, as a leftie, since being a kid I had to suffer a few attempts to force me writing with the right hand, something I trained by myself much later in my 20s out of curiosity, but quickly forgot due to lack of practice. I never perfected my horrible handwriting and resorted to block capitals immediately after school; then computers and printers solved the problem. Unfortunately it seems there's no way to get rid of this archaic thing called signature that for me translates into wasting lots of time; I'd rather leave a blood sample on paper if I could:)
I love this feature of Preview, though I also sometimes have people that insist on receiving a wet ink signature...
Dropbox's "Scan Document" feature is great for getting around that. It turns a photo into what looks exactly like a scan. I just sign the document in Preview, and then use the Scan Document feature to just "scan" the document as its displayed on my screen. The result seems indistinguishable from a printed wet ink copy also scanned with Dropbox.
The reification of signatures and paper documents has to stop.
I can set up Apple Pay and use it across devices to make payments worth tens of thousands, but I can’t use the same technology to authenticate a document.
I can't for the life of me understand why the only valid ways to save a signature image for Preview is (1) your computer's camera, and (2) scrawling on the touch pad.
I have a previously-scanned signature that I'd like to re-use. I'd love to simply import the file. Instead I have to print it out and then hold it in front of the camera, trying to get it aligned. It's madness. Is it supposed to be more secure for some reason?
That doesn't work for the US, because any constraints on use are politically unpalatable. Any capability that the government creates thus turns into a security vulnerability to be exploited by business.
For example, even just assigning everybody unique identifiers (social security number, drivers' license number) has allowed businesses to demand these identifiers to track customers in privately-held surveillance databases. This system has already grown out of control with little sign of stopping.
A "secure" e-signature token would lead to even more businesses demanding your "identity". Imagine having to pay twice as much for groceries for wanting to keep your purchases personal!
I'd much rather suffer the small work of (print, sign, scan, cache, burn) until I see some reigning in of private surveillance databases.
SSNs are problematic because they are expected to be both public and confidential. In reality, they're public.
The federal government refuses to issue actual public IDs, which would solve the problem nicely, for political reasons. They can't retract Social Security.
That is one reason they're problematic, but not the problem I described. Public IDs would make the problem I am describing worse, as even more businesses would unashamedly ask for them. People's feeling of "oh isn't that private" is one of the few things holding back everyday retail businesses from asking for them.
I don't think it would be any worse than the status quo. Some businesses might not ask for your SSN in particular, but adtech can identify you pretty uniquely regardless. And in the meantime, a million businesses have your sensitive, private SSN, and a relatively high risk of data breach.
I used that for some mortgage documents (pre-closing) that they could email me, but needed a 'wet' signature. I happened to be out of town so accessing a printer and scanner wasn't easy.
I used Preview for the longest time before they questioned 1 of the documents.