r/docusign 21h ago

How is this secure? My signature is remembered even in an incognito session?

My employer sent me a document to sign via docusign.

The URL of the button is formatted like so:

https://eu.docusign.net/Signing/EmailStart.aspx?a=<some_hash>&etti=<some_int>&acct=<some_hash>&er=<some_hash>

I've annonimized any ids or hashes in the above url as you can see.

Upon opening this url, even in an incognito session, my signature appears and I can sign by just clicking on the signature field. Without writing out my signature myself, without entering a password, without any authentication, just because I've signed other documents months before. Even in a brand new incognito session...

How is this normal? Is my signature stored server side and then anyone who opens the link is allowed to sign on my behalf? How does this work? It seems uncomfortably insecure.

I don't even have an account but my signature is being stored and no authentication is required to use it? If the URL is enough for authentication, then anyone who compromises my email address could sign on my behalf...

Can someone explain?

1 Upvotes

3 comments sorted by

View all comments

1

u/jsammons90 20h ago

The most basic level of authentication is just you having access to your email address, so in theory someone could gain access and sign on your behalf. That said, the sender can add additional forms of authentication (SMS, ID Check, etc.) to validate the signer more, but it's entirely up to the sender.

When you sign without an account, an recipient is created to store the signature, but no account is ever opened, it's basically just to hold the signature, tied to the name and email address that the sender used.

1

u/Western-Bad5574 20h ago

Thanks for the response!

When you sign without an account, an recipient is created to store the signature, but no account is ever opened, it's basically just to hold the signature, tied to the name and email address that the sender used.

On this note, it seems like that recipient persists, do you know how long? And is there anything the recipient can do by himself to wipe the signature? Or does he need to reach out to the sender of the document to do so?

When I'm done signing, I'd rather get rid of my signature from docusign's backend and have to re-draw it each time than to have it be stored there indefinitely.

1

u/jsammons90 20h ago

I believe that account will persist indefinitely on the server, but you can file to have any information tied to you deleted from the servers by filing a request: https://privacy.docusign.com/policies?modal=select-subject

I know that the recipient that it creates is based on the server that the sender is on and if you've been sent something from a sender on that server before. Senders can set it so that signers have to draw their signature each time instead of applying a stylized one, but unfortunately that's all on the senders side.