Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
0

Integrity issues with Digitally signed pdf in Mac preview

New Here ,
Jan 30, 2023 Jan 30, 2023

hi i have macpro with intel chip and mac os Ventura 13.2. i use acrobat reader 2022.003.20314.

i use the DSC from eMudhara. 

 i digitally sign the pdf in acrobat and save it.

 

when i open in acrobat the digital signature is fine, it say the digital signature is valid.

when i open the same pdf in macPreview, i can simply delete the Digital signature. 

 

any onne encounter this issue?

 

TOPICS
Security digital signatures and esignatures , Standards and accessibility
4.6K
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Advocate ,
Jan 31, 2023 Jan 31, 2023

What exactly do you consider an issue here?

Digital PDF signatures are designed to allow a recipient of the PDF to check whether it is in a state you signed (with a possible small set of allowed changes you can select upon signing). If someone removes the signature, it isn't there anymore, so a later recipient sees (by the absense of your signature) that the document they received is not in the state you signed.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Jan 31, 2023 Jan 31, 2023

Hi MikelKlink

what you shared is one prespective.

the ability to remove the digital signature means the integrity of the PDF is invalidated and the end receipent may not even be aware of this situation. the man in the middle could affix another Digital signature, which invalidates the objective of using DS in the first place. this is my conncern/issue.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Jan 31, 2023 Jan 31, 2023

The man in the middle wouldn't be able to apply your digital signature so be sure to train the recipients to do their due diligence when acting on files that have been signed.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Advocate ,
Jan 31, 2023 Jan 31, 2023
quote

the man in the middle could affix another Digital signature, which invalidates the objective of using DS in the first place. this is my conncern/issue.

 

As others here have already expressed, the recipients you send those PDFs to need not only to check whether there is a valid signature but also whether the signer is the expected signing person (or a person from the expected signing organization).

Remember, instead of manipulating your PDF that man in the middle could simply create and forward a new PDF from scratch which looks like your PDF with minute but relevant changes and affix another digital signature. Thus, even if the PDF signature scheme somehow would interweave the signature with the content to prevent easy signature removal, nothing would be gained.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Jan 31, 2023 Jan 31, 2023

Mac Preview is a terrible application that corrupts PDF files simply by opening them, so this is not surprising.

After you "delete" the signature in it, though, what do you see if you save the file and then open it in Acrobat? Does it signature appear at all? Or just as invalidated?

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Jan 31, 2023 Jan 31, 2023

hi try67

after the signature is deleted in preview, and saved and then opened in acrobat, the content can be seen, but the signature has vanished.

 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
LEGEND ,
Jan 31, 2023 Jan 31, 2023

You are correct. This is inevitable. Signatures can be removed, even if Adobe software blocks it. The recipients must be properly trained and motivated to check signatures (not look on the pages) otherwise there was no point in signing at all. 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Jan 31, 2023 Jan 31, 2023

It's worse than you think. Even if you certify the PDF, then add the signature, Preview removes both... though even that isn't quite accurate. The signatures are actually still there but Preview ignores the permissions set to disabler editing and does an append save so that it appears the the document is no longer signed. However, when you attempt to edit the file in Acrobat, it still respects the permissions. See the image below. Notice how the signature panel is blank but the file is still considered to be signed. This is a serious flaw in Apple Preview.

2023-01-31_08-29-59.png

The good news is, it's easy to detect a PDF that has been corrupted by Preview (which in my opinion is every PDF file modified by Preview) by looking at the document properties.

2023-01-31_08-34-00.png

This information doesn't solve the problem but it is a way to detect that a problem has occurred. Unfortunately, we don 't control Apple. We can only alert them to the issue.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Advocate ,
Jan 31, 2023 Jan 31, 2023
LATEST
quote

This information doesn't solve the problem but it is a way to detect that a problem has occurred. Unfortunately, we don 't control Apple. We can only alert them to the issue.

One shouldn't focus too much on Apple / Preview here. Yes, they indeed are a prominent bad example, but as PDF is an open format, anyone can create an application to manipulate PDFs quite arbitrarily. Heck, if you know what you're doing, a text editor suffices...

Thus, if you don't see that Quartz producer line, it doesn't mean your copy of the PDF is not corrupted or manipulated.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines