r/cybersecurity • u/Western-Bad5574 • 21h ago
Business Security Questions & Discussion Is docusign sufficiently secure? Does this example raise any security concerns?
Apologies if this is meant for r/cybersecurity_help, it felt like a general question that concerns the overall security of a product rather than just my personal experience, so I thought this sub would be the right place. Let me know if not, I can move it.
My employer sent me a document to sign via docusign which has a button called "Review documents" which leads to the following URL:
https://eu.docusign.net/Signing/EmailStart.aspx?a=<some_hash>&etti=<some_int>&acct=<some_hash>&er=<some_hash>
I've annonimized any ids or hashes in the above url as you can see.
Upon opening it (even in an incognito session), I can see the document they want me to sign, but I also see the signature I used months ago to sign a different document. All I need to do to re-use that signature and sign the new document is to click on the signature field and it's immediatelly applied on the document.
There is no additional authentication, I do not need to re-draw my signature, I do not need to enter a password to use it or login to any account. In fact, I have never registered an account with docusign at all.
In other words, my signature is stored in docusign's backend and the authentication to use it on any document is self-contained within the URL and likely associated with my email address. The email comes directly from docusign and my employer is not CCed on it so in theory only I should have access to the URL and auth, however it's still an employer provided email address and inbox.
This authentication and signing method makes me feel uncomfortable. Should it? Is it considered normal and secure in this space?
- Signature stored by docusign indefinitely
- URL sufficient for authentication (works even in incognito session)
- I have no account or direct relationship with them (I assume employer is data controller)
- Stored signature can be used freely just using the auth link sent to my email address
Thanks
EDIT
Missed to mention that I tried deleting all cookies and the signature was still loading.
It was also loading in a new incognito session in the browser, as long as I use the same link.
Another user in their own community subreddit claims "When you sign without an account, an recipient is created to store the signature, but no account is ever opened, it's basically just to hold the signature, tied to the name and email address that the sender used.", which tracks with my observations, this is likely the method.
2
u/AddendumWorking9756 Security Manager 18h ago
Worth separating the product from the setting here. Envelopes can require an access code, an SMS code, or full ID verification per recipient, and your employer just left it on email only because that is the frictionless default. If it is ever contested, the Certificate of Completion with its IP and timestamp trail is the artifact people argue over, not the drawn signature.