the one benefit i see is as a final “lock in your answer” function for any form you’re submitting.
And did they have to stop allowing written signatures because of AI scraping? Or is it just because they never looked legible at all?
Submitted 4 days ago by FinjaminPoach@lemmy.world to [deleted]
the one benefit i see is as a final “lock in your answer” function for any form you’re submitting.
And did they have to stop allowing written signatures because of AI scraping? Or is it just because they never looked legible at all?
physical signatures are just asking you to write your name in a box…
Not a huge difference.
No I disagree, the idea with ohysical signatures is that you write it in cursive, so in theory nobody will do ot exactly the same way as you write it - but then people can forge things, and since people don’t actually write their name the exact same way every time, forgery is essentially as good as perfect.
Nobody has relied only on signatures to verify that a person signed it, since forever. Especially because forgery was always a thing.
This is why documents that are important aren’t just signed by one person; they’re signed by witnesses who presumably will vouch for it. (Like notary public’s are a thing.)
For lesser contracts they first verify you are in fact you.
There’s no functional difference online- to within a reasonable standard.
Sorry that’s not right. You can see my other comment about the ESIGN Act here: lemmy.world/comment/25214883
Note: it also points out how the top response is just… well, wrong.
And, most young adults don’t sign in cursive anymore, so, aside from terrible handwriting, their printed name isn’t really much different than a typed name.
You might disagree, but that doesn’t mean you’re right. A signature does not require cursive. It doesn’t even have to be legible. It’s a mark that you make signifying that you agree to whatever it is you’re signing.
Signatures have never required cursive. Historically, people who couldn’t read or write would just put an X in the signature spot and that was valid. Yeah, there is a marginal benefit to physically signing something in cursive, but the purpose of signing it has always been more of a final agreement step.
If handwriting and spelling and how I signed it actually mattered at all legally, then I could sign a different name when I buy a car, get keys, drive away, and later in court, say “well I never agreed to pay for this car, look at my signature, it says Frank Sinatra”. Same goes for a true forgery. The evidence I didn’t sign it myself is my statement in court saying “I didn’t sign this”, and whatever signs there are that I didn’t benefit from this.
In parts of the world, paperwork is managed with stamps and a mark. Your doctor in latin america will stamp a blank prescription pad with a stamp that has their name and license number. They will then make a recognizable mark over the stamp. Same with your lawyer and all government offices. The point isn’t that someone can use handwriting analysis - which is just fluff - and rather that they possess the stamp and those who would read the paperwork recognize their particular mark.
“in cursive”
Laughs in years of deviating but programmed hand movements from which letters are rarely decipherable…
I was at a grocery store back when you had to sign the little digital screen for a card transaction and I finished signing, but the cashier got distracted and didn’t accept the signature for a while, so I just doodled Godzilla taking a skyscraper next to my name.
My best friend was there with me and from that day forward, I’m not sure if he’s ever signed something without adding a Batman logo after that day.
That would be precisely an example of how signatures are not arbitrary, but rather marked in our own unique quirks.
Except that you can draw whatever you want and it can be different each time in theory. Some may enforce consistency, but there’s no legal requirement of it.
Had my identity stolen. Thief bought a car with a loan they got online. Forged my signature at the dealer half a country away. I hired a lawyer because BofA are fucking criminals.
Me: “This is clearly not my signature on this document. Doesn’t that mean anything?”
Lawyer: “Nope. Not a thing.”
WTF.
Now anything asking for my signature is squiggles unrelated to the written language.
What else happened?
Went to court. Judge ruled in my favor. In the meantime I had contacted the Consumer Protection Bureau (US). Back when they had teeth and funding. BofA must have had a whole department that dealt with CPB because that shit got resolved quick. Took more than two months and around $1500 to get it cleaned up.
My credit is locked at all three agencies now. Highly recommend everyone do it. The fact it isn’t locked by default is asenine.
Obligatory “bofa deez nuts”
Digital signatures are much more than “just typing your name in a box”. The few times I digitally signed a doc I didn’t even have to do that, just click on a big green button.
It’s all connected to how you authenticated before you got to that point.
I think @mentaledge@sopuli.xyz explained it well.
The actual shape of your signature hasn’t really meant much for some time. As recently as 2005, Visa’s contract had the most bizarre requirements.
You are supposed to sign the back of your card. If you paid with the card, you had to sign the receipt. The cashier was supposed to examine the signature on the card and the signature on the receipt and decide if they matched.
But. If the card was not signed, the cashier was supposed to insist that the person present sign the card, and then the cashier was supposed to compare the signatures right there. We were also forbidden by contract from asking for ID.
It was like this further back than 2005. I worked retail in the mid 90s and it was the same. And if the signatures didn’t match, well. Oh well. We had no power to do anything about it. The number of self-righteous idiots I had who thought that they were clever when they would sign their cards as Mikey mouse and then freak the hell out when I never bothered to check because it didn’t matter if it was signed Mickey Mouse or Ronald Reagan and you signed the receipt with your actual name. We couldn’t do anything! God they’d get so mad. Thank god we had great management that would back us.
The point of the signature isn’t the mark, but that the affirmation on the document can reasonably be tied to you. For most of history, it has been tied to a certain mark, whether it be a signed name, a stamp or embossed seal, or even a drawing. That system generally breaks down in the digital age.
A low hanging fruit that is seen to work is having the mark of approval get tied to an account under the control of the signee. It isn’t so much that you made the mark but that it is tied to an email address you control. So even if you don’t sign it with an actual signature, it still gets tied to you.
It almost feels like I’m just trolling everyone by pushing back now, but:
The point of the signature isn’t the mark, but that the affirmation on the document can reasonably be tied to you. For most of history, it has been tied to a certain mark, whether it be a signed name, a stamp or embossed seal, or even a drawing. That system generally breaks down in the digital age.
In the context of only-physical documents, is that affirmation not helped by having certain marks and/or styles of signing that are typical of your own signing? Thus the specific mark contributes to the affirmation.
For a physical only document, the mark is something relatively difficult for others to perform. Even then, signatures by themselves usually only carry a certain amount of weight by themselves; either the risk of borne by the other party or additional measures are taken like requiring witnesses including notaries.
To answer the next question you’ll probably ask, it is considered to be far more trivial for someone to apply someone else’s mark digitally than it is in person. Anyone with a pdf editor can apply someone else’s signature to a document without their knowledge.
Signature matching/analysis isn’t particularly scientific, so in general a physical signature is used for clear authorization, not identification. When you log in to something to sign your identity is already set by other means, so all the signature needs to do is say “yes, I agree to this”. E signatures in the US were legally formalized awhile ago, so it’s not really a controversy.
I scanned the responses, and didn’t see anyone who mentioned this.
The point at which the U.S. allowed you to “sign” your name by typing was when the E-Sign Act was passed. That was in 2000, long before LLMs were really a concern.
The reason was to make online commerce easier. Verbal contacts could and continue to be enforced, but enforcement requires more effort than with a written contact.
At the time I thought the law was passed by people who didn’t understand technology and how easy this made it for people to commit fraud or screw over consumers. However now I realize they just didn’t give a fuck.
The truth is, wet signatures have been absolutely worthless for … well forever. The first time I had a credit card was in the late 80s and even back then it didn’t make any sense that I was signing receipts in the grocery store.
It does as much as does “testifying under oath” does to magically stop you from lying.
i.e., putting your hand on a significant bit of text and saying some special words doesn’t stop you from lying, but it DOES create / enhance penalties if you do.
I think a digital signature is also a way they can prosecute for impersonating someone for identity theft. By you typing and saying “this is me” if it’s not, they can use that as evidence.
Neat
I think that’s probably it, or pure cargo cult because “we’ve always had signatures so something’s got to go in that slot”. The whole idea of random scrawls for “authentication” has been weird all along. As if everyone walked around knowing what everyone’s signatures should look like. And if you do know, you can just… write it that way.
Remember back in the day when you used to have to sign the back of your credit card.
I would write in that block “ASK TO SEE ID”. At least 100 cashiers would read that and then just stare at me.
Yeah. That’s because nobody cares.
We just wanted to get through the line, we don’t care who’s paying your tab.
then like the post office says they won’t take it unless there is a sig so I have to write see id and have a sig which of course my id has a sig.
financial institutions had your signature on file and would compare it back in the day. It made sense at one point but it does not gel well once making copies and images of everything became commonplace.
The digital signature is things you don’t see. The visual signature is more for ceremony as it’s referring to our past to smooth the transition
You might be confusing this with a browser fingerprint. There isn’t a magic ghost signature that appears in the data when you consent to sign by typing your name in to a box. It’s really just the box.
Your signature can be whatever you want to sign. I sign different things all the time. The legality is just in you consenting and making your mark.
Your signature looks different every time you sign it, and it being an exact replica was a way to spot a forgery. A signature has never been some sort of security feature.
Where have “they” stopped allowing written signatures?
Let me try and rack my brain for everything I’ve digitally signed
It’s not that they’re not allowing written signatures but that they’ve removed them from everything because it’s all done online - they have no space to try and write one with your mouse or your finger, like usual.
If you show up in person they get one on a tablet, though, usually.
Proper digital signatures are very secure and prove that you have possession of the signing key and that the document has not been modified since. Unfortunately those keys are very expensive (unless your employer gets them for you), so usually when people sign something in Acrobat or whatever it will just use a self-signed certificate at best. This does still prove that the document hasn’t been modified since it was signed, but it doesn’t prove anything about who signed it.
MentalEdge@sopuli.xyz 4 days ago
The visual signature part of a “aigital signature” is purely cosmetic. The actual signature is the entire file being cryptograohically signed using a örivate key you possess, which any recipient can thenverify came from you using a public key.
This is the case for all government issue signatures (like when using the private key inside a chipped government id card) or any other signature created using a key pair from a issuing authority.
If its not a digital signature in this way, the other way is literally just a file. It can be a vector or an image file, or a straight up scan of a physically signed document. It’s just a picture. It has no digital verification whatsoever.
Fmstrat@lemmy.world 20 hours ago
What? No it’s not. This whole comment is wrong, sorry.
When a website has you type a name as a signature it’s a legal representation of that signature. There’s nothing cryptographic at all about it. Wjere would you even store the key? I’ve made ways to use Webauthn keys to do this, but no signatory uses these methods.
And that’s not how ZKPs in government IDs work, either. You never sign with them, you only verify.
Ref: My job is cryptographic signature protocols, and I have a draft at IETF for one of them.
MentalEdge@sopuli.xyz 20 hours ago
I claimed no such thing. That is not a digital signature
A_norny_mousse@piefed.zip 4 days ago
I’ve done that a few times, in GIMP (or Photoshop), and was always a little surprised that it seemed to be enough. Maybe I unwittingly “forged” my own signature? That’s legally murky…
obelisk_complex@piefed.ca 4 days ago
How is it legally murky? Someone asks if that’s your signature on the document and do you remember signing it, and it is and you do, so you say yes. End of discussion.
It’s only a problem if you’re claiming it’s not your signature. But then, they have to prove it’s your signature, you don’t have to prove it’s not. I’m not sure you can prove it’s not your signature, hence burden of proof being on the other party.
MentalEdge@sopuli.xyz 4 days ago
It’s really just a digital way to do the equivalent of printing the document, signing it, and scanning it again. Which is also accepted in a lot of situations.
jdr@lemmy.ml 4 days ago
Surely they’re talking about the likes of DocuSign, which doesn’t involve any user-controlled keys
Bazoogle@lemmy.world 4 days ago
The only private key with docusign is the fact you has access to the email inbox. And it’s not even a private key, just a symmetric key in the link of the email. They might do some basic user agent and IP checks for suspicious activity, but if someone you know has access to your email DocuSign wouldn’t know the difference
FinjaminPoach@lemmy.world 4 days ago
🤯
Well that explains everything. Thank you very much!
atx_aquarian@lemmy.world 4 days ago
That didn’t quite explain everything. I want to add that there are “type your name to sign” forms that are just what you described, just bytes spelling out your name. In those cases, you’re right, those bytes don’t have your handwriting to prove anything, but they do accomplish something. If the form is secured behind a login and not a totally buggy heap of garbage, then the act of typing your name on that form demonstrates that whoever logged in deliberately expressed their approval. And whatever level of identity verification is needed for login is then playing the part of demonstrating who did that. That’s not perfect, but the level of evidence might match the level of risk enough to justify that mechanism to the company providing it, and it’s important to consider all factors: not just system cost, but end user tolerance.
E.g., there was (maybe still is?) a “ham” radio logging system that had end users generate their own PGP signing key pair to sign their log books, which are simply a list of who they talked to over the radio, always for non-commercial purposes (by law). Many questioned whether a secure web site with good 2FA might suffice and be much more convenient, manageable, and adequate risk level for most users.
“Digital signature” is a proper term that should mean what the parent comment explained–public key crypto “signing” (a hash of) a document’s content–but “sign here by typing your name” will inevitably get called a signature and, obviously, is also digital, just not a real “digital signature”.
boonhet@sopuli.xyz 4 days ago
In the US, they don’t do the cryptographic signatures, they do the image. There are document signing services where you just type your name and it creates a “handwritten” signature from that name and that’s legally binding apparently.
I found it very funny when I had to sign a contract with an American company that way. Not sure it would’ve been legally binding in my jurisdiction, but the contracts was more or less “don’t tell anyone about exact details of the sizable bonus you’re about to receive, or we’ll revoke it, also you’ll have to stick around for half a year to receive the other half”, when the company got sold to private equity and the original owner decided to give us all something to remember them by.
Natanael@infosec.pub 3 days ago
Old school contract law was always about expressed mutual understanding, and predates widespread ability to read and write so didn’t require papers (but did like having witnesses of the agreement).
You still see surviving requirements of some contract signings needing witnesses.
It’s still the same in the digital age, if you can demonstrate all participants agreed then the form doesn’t matter much (aside from in regulated fields, some have their own requirements on form).