← Back to context

Comment by JCBird1012

5 hours ago

In my opinion, all of these open source/free/open document signing tools are neat on paper (and technically fulfill the goal of being able to verify a document's chain-of-custody/signature provenance) - but won't take off in any meaningful way legally because there's no entity behind them taking the responsibility for accuracy and culpability.

DocuSign/Adobe/whomever is trust anchor, it's an entity you can sue or subpoena if something goes wrong. Someone who's actually on the hook for making sure whatever's signed is accurate and truthful (outside of the reputational risk of fraud completely obliterating any trust in your platform)...

No amount of cryptographic verification substitutes for having a legal person on the other end who can be held accountable for actually verifying the document was signed accurately/process was followed.

Indeed. It doesn’t meet the requirements of EU qualified signatures or seals, for example.

  • What are the actual requirements?

    In USA we only have a few requirements from the E-SIGN act:

    Key Legal Requirements

    Intent to Sign: Parties must show a clear, provable action to sign the document. Electronic Consent: Parties must agree to use electronic records, with consumer transactions requiring specific advance disclosures.

    Signature Association: The system must capture an audit trail or text linking the signature to the specific document.

    Record Retention: Contracts must be accurately stored and remain accessible for future reference by all authorized parties.

    Consumer Disclosure Rules

    Hardware/Software Notice: Tell users what tools they need to access and save the records.

    Paper Copy Rights: Inform users how to get paper copies and whether any fees apply.

    Withdrawal Details: Explain how consumers can change their mind and cancel their electronic consent.

    • See eIDAS annexes I to III: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

      Certificates must be issued by qualified trust service providers (see section 3 for their requirements) who verify the identity of the certificate holder and ensure that the holder has sole control over the certified key. Among other things, this generally means that the key must be held in a certified HSM or smart card/USB key.

      The provider infrastructure is subject to supervision of the EU member states, who accredit bodies that perform the conformity assessments.

      The main purpose of all this is to ensure that the four requirements listed in article 26 are met:

      "An advanced electronic signature shall meet the following requirements:

      (a) it is uniquely linked to the signatory;

      (b) it is capable of identifying the signatory;

      (c) it is created using electronic signature creation data [private key] that the signatory can, with a high level of confidence, use under his sole control; and

      (d) it is linked to the data signed therewith in such a way that any subsequent change in the data is detectable."

      Let's Seal could attempt to argue that they do ensure these requirements, but their "control of a domain" scheme is unlikely to clear that bar, and they probably also don't secure their signing infrastructure in a way that would be deemed sufficient.

that's true. i think that if it's obvious that the audit is finding everything, every detail, every file, piece of data touched.... at what level do we need to verify?