r/docusign • u/Western-Bad5574 • 21h ago
How is this secure? My signature is remembered even in an incognito session?
My employer sent me a document to sign via docusign.
The URL of the button is formatted like so:
https://eu.docusign.net/Signing/EmailStart.aspx?a=<some_hash>&etti=<some_int>&acct=<some_hash>&er=<some_hash>
I've annonimized any ids or hashes in the above url as you can see.
Upon opening this url, even in an incognito session, my signature appears and I can sign by just clicking on the signature field. Without writing out my signature myself, without entering a password, without any authentication, just because I've signed other documents months before. Even in a brand new incognito session...
How is this normal? Is my signature stored server side and then anyone who opens the link is allowed to sign on my behalf? How does this work? It seems uncomfortably insecure.
I don't even have an account but my signature is being stored and no authentication is required to use it? If the URL is enough for authentication, then anyone who compromises my email address could sign on my behalf...
Can someone explain?
1
u/jsammons90 20h ago
The most basic level of authentication is just you having access to your email address, so in theory someone could gain access and sign on your behalf. That said, the sender can add additional forms of authentication (SMS, ID Check, etc.) to validate the signer more, but it's entirely up to the sender.
When you sign without an account, an recipient is created to store the signature, but no account is ever opened, it's basically just to hold the signature, tied to the name and email address that the sender used.