{"id":529,"date":"2015-09-11T08:17:40","date_gmt":"2015-09-11T16:17:40","guid":{"rendered":"http:\/\/unmitigatedrisk.com\/?p=529"},"modified":"2015-09-11T09:35:47","modified_gmt":"2015-09-11T17:35:47","slug":"paper-in-a-digital-world","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=529","title":{"rendered":"Paper in a Digital World"},"content":{"rendered":"<p>Paper processes are a normal part of person to person exchanges, and like the written signature, we can be sure their use will not disappear overnight. This means it is even more important that we evolve the relationship between our physical and digital experiences that involve paper so they can work more fluidly.<\/p>\n<p><span style=\"font-weight: 400;\">Sometimes these exchanges begin as a physical interaction and transition to the digital but almost always, it is the digital embodiment of that transaction that is relied upon once the exchange ends. This is because these digital representations make it possible to instantly access the data contained in them and correlate it to other data enabling quicker and better decisions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is particularly important to keep in mind when we consider that paper based workflows are, broadly speaking, privacy preserving workflows. Only those people who have physical access to the associated documents have knowledge of their contents. Their physical nature also makes it possible for those who have possession to freely review these documents with others. This is not true of most digital workflows where the records are commonly stored in clear text in some database or cloud storage service.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There is also a long history of effective independent forensic analysis of paper documents and written signatures. While there are certainly many things that can be determined from forensic analysis of a digital document, attributing it to an individual, or detecting that it has been tampered with is often next to impossible. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">It is possible to provide these same properties with digital documents and do so with even greater assurances with the intelligent application of cryptographic based signatures and encryption. \u00a0Despite this, these approaches are seldom used, the primary reason given by vendors is providing them requires investment in complex key management solutions and often results in sub optimal user experiences. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Those that do offer cryptographic signatures seldom use them to represent the signer&#8217;s intent and instead rely on digital facsimiles of the signer\u2019s physical signature. They then notarize that they saw a given ip address, at a given time attach that facsimile of a signature. This technically exceeds the legal minimum requirements in the United States but fails to meet the minimum expectations most other countries mandate for electronic signatures.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Even once you design a solution that achieves all these properties you are not done providing an equivalent digital alternative. These person-to-person exchanges often require both paper and digital artifacts and as a result you will need to be able to link the two together. This is not too dissimilar than how an \u201coriginal\u201d contract with its ink signature is often treated as the authentic \u201csource of truth\u201d. In these hybrid digital and physical interactions one party may have processes or compliance requirements that require a paper representation (and something that approximates a physical signature) of the interaction. while the others involved may prefer the convenience of the digital representation. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">So what are the things you minimally need to look for in a digital signature solution beyond usability if it is to deliver the same or better properties as existing paper based solution?<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Each signer:<\/span>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">cryptographically signs the document;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">attaches a facsimile of their physical signature\u00a0to\u00a0the document.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The final document:<\/span>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">is cryptographically notarized with metadata about the signing;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">includes a timestamp and the cryptographic metadata needed to verify the signature long into the future;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">can be encrypted end-to-end ensuring only the parties associated with of the document can read it;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">is assigned a unique identifier that is placed plainly in the document so when it printed its digital embodiment can be easily found;<\/span><\/li>\n<li style=\"font-weight: 400;\">includes a log of activities that took place during the signing process;<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">is archived so it can easily be retrieve later in case of a dispute.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The document and signature formats used are based on broadly accepted standards so:<\/span>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">it will be readable and verifiable far into the future;<\/span><\/li>\n<li style=\"font-weight: 400;\">it can be read and verified in third-party applications;<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">enforcing the agreement does not require participation of the solution provider in case of dispute.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">A free web based reader is available that:<\/span>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">does not require registering to read the document;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">enables participants to share the documents with others;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">can validate the signatures without the need for plug-ins or desktop applications;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">works as well on mobile and tablet as it does on the desktop;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">can be easily and freely integrated into your own applications.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">An API that makes it possible to integrate into your own applications the signing of:<\/span>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">documents;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">web forms.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">With these bases covered you have something that should be able to withhold the test-of-time just as paper processes have been able to do.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Paper processes are a normal part of person to person exchanges, and like the written signature, we can be sure their use will not disappear overnight. This means it is even more important that we evolve the relationship between our physical and digital experiences that involve paper so they can work more fluidly. Sometimes these [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[4],"tags":[157,173,174],"class_list":["post-529","post","type-post","status-publish","format-standard","hentry","category-thoughts","tag-digital-signatures","tag-paper","tag-signatures"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=529"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/529\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}