Copy link to clipboard
Copied
I've received a signed .pdf as an email attachment issued from Adobe sign. I was able to open the .pdf without being asked for a password or to install any certificates. When I check the document security, the 'Document Open Password' field is set to 'No'. I'm concerned that anybody who access to the.pdf would be able to Open and read it. This could include anybody who is able to access any of the mail servers used in the transmission of the emal. Am I being over paranoid ?
Greetings!
To add a little more color to the previous observation (in case anyone references this thread in the future), Adobe Sign does have controls to apply a password to the signed PDF before it is sent to the recipient.
Further, customers in muti-license accounts have the ability to either a) not attach the PDF to the Signed and Filed email, or b) suppress the email entirely.
The assertion that "Adobe Sign does nothing to restrict access to the document" is only true if the account/agreement i
...Copy link to clipboard
Copied
You're perfectly correct. Adobe Sign does nothing to restrict access to the document contents, the digital signature applied merely certifies that someone signed it at a certain time. Anyone who gets hold of the PDF (through whatever route) can read it.
Since email is fundamentally an insecure transport medium, with the vast majority of SMTP hops happening in plain text, you should never use a document management service that sends out email copies for any confidential or legally-protected purpose.
Copy link to clipboard
Copied
Thank you for the quick answer. Much appreciated.
Copy link to clipboard
Copied
Greetings!
To add a little more color to the previous observation (in case anyone references this thread in the future), Adobe Sign does have controls to apply a password to the signed PDF before it is sent to the recipient.
Further, customers in muti-license accounts have the ability to either a) not attach the PDF to the Signed and Filed email, or b) suppress the email entirely.
The assertion that "Adobe Sign does nothing to restrict access to the document" is only true if the account/agreement is configured by the user to work that way. The options for security are available.
Customers that generate agreements which contain or collect personal/sensitive information should strongly consider delivering only the email, without the attached PDF.
Signers that want a copy could then be advised to create a free account with Adobe Sign and download a copy directly from the authoritative original. Yes, that is perhaps a lot of friction, but that friction is security.
Copy link to clipboard
Copied
Thank you for your post - however, I did add this option on but my test email to a family member did NOT password protect the document or the link. The CC that I recieved was password protected but the "clients" email was not. Further, when my family member forwarded their link to me - I was able to open it without a password!!
Any advise?? I truly need a HIPPA compliant options and I need to send it today. I didn't forsee this as an issue...