Hacker News new | ask | show | jobs
by j_san 1039 days ago
Is this targeted for the US market or also the EU? Does this qualify as a an advanced electronic signature (AdES) under the eIDAS regulation?
3 comments

Author of open-pdf-sign here. AdES alone is difficult to do without proper signatures and user verification. Besides that, if Google would go for advanced electronic signatures, I'd expect it showing up in the EU Trusted List, which it isn't. So unless Google is not utilizing their own Google Trust Services certificate authority, I'd say it's unlikely that they will launch with AdES that are compatible with eIDAS.
Thanks for your answer, I appreciate it.

Although strictly speaking if they would only want to do AdES and not QES, they wouldn't have to be in the EU Trusted List, would they?

No it doesn't, not considered as a trusted (certified) provider and doesn't meet the level for secure user authentication.

It's like a gadget in Europe then.

But still, it is useful.

It can be used if you want to ask your daughter to promise to "Get good grades at school" in exchange for an extra Christmas gift, for example.

And make it look like official.

It's like pretending to be signing.

In other words: is strictly less useful than a "fake analog signature" script that uses imagemagick to paste a PNG/SVG with a signature (or a random one from a directory of signatures) on the last page of the document, and then to apply some or all of random {sub-2deg rotation, tiny gaussian blur, tiny non-linear transform, color threshold, strong desaturation}, to make it seem like the document was printed out, signed, and scanned back.
I skip the script and (if they bother asking) tell people I have a really good scanner, a really good pen and am incredibly consistent with my signature even when I sign totally different sizes.
Sounds like you have a handy script to paste here... :)
I don’t have any inside info here, but anecdotally, Google seems good at meeting regulatory requirements. I wouldn’t be surprised if it does meet this if it’s available in the EU.
Many Latinamerican countries also use digital signatures (e.g PAdES). I wonder if they support this? LATAM always seems to be forgotten by big tech.
Being available doesn't mean it's considered legally valid. I can sign with the private key on my national id…