this post was submitted on 06 Aug 2026
89 points (96.8% liked)

No Stupid Questions

49576 readers
295 users here now

No such thing. Ask away!

!nostupidquestions is a community dedicated to being helpful and answering each others' questions on various topics.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules (interactive)


Rule 1- All posts must be legitimate questions. All post titles must include a question.

All posts must be legitimate questions, and all post titles must include a question. Questions that are joke or trolling questions, memes, song lyrics as title, etc. are not allowed here. See Rule 6 for all exceptions.



Rule 2- Your question subject cannot be illegal or NSFW material.

Your question subject cannot be illegal or NSFW material. You will be warned first, banned second.



Rule 3- Do not seek mental, medical and professional help here.

Do not seek mental, medical and professional help here. Breaking this rule will not get you or your post removed, but it will put you at risk, and possibly in danger.



Rule 4- No self promotion or upvote-farming of any kind.

That's it.



Rule 5- No baiting or sealioning or promoting an agenda.

Questions which, instead of being of an innocuous nature, are specifically intended (based on reports and in the opinion of our crack moderation team) to bait users into ideological wars on charged political topics will be removed and the authors warned - or banned - depending on severity.



Rule 6- Regarding META posts and joke questions.

Provided it is about the community itself, you may post non-question posts using the [META] tag on your post title.

On fridays, you are allowed to post meme and troll questions, on the condition that it's in text format only, and conforms with our other rules. These posts MUST include the [NSQ Friday] tag in their title.

If you post a serious question on friday and are looking only for legitimate answers, then please include the [Serious] tag on your post. Irrelevant replies will then be removed by moderators.



Rule 7- You can't intentionally annoy, mock, or harass other members.

If you intentionally annoy, mock, harass, or discriminate against any individual member, you will be removed.

Likewise, if you are a member, sympathiser or a resemblant of a movement that is known to largely hate, mock, discriminate against, and/or want to take lives of a group of people, and you were provably vocal about your hate, then you will be banned on sight.



Rule 8- All comments should try to stay relevant to their parent content.



Rule 9- Reposts from other platforms are not allowed.

Let everyone have their own content.



Rule 10- Majority of bots aren't allowed to participate here. This includes using AI responses and summaries.



Credits

Our breathtaking icon was bestowed upon us by @Cevilia!

The greatest banner of all time: by @TheOneWithTheHair!

founded 3 years ago
MODERATORS
 

the one benefit i see is as a final "lock in your answer" function for any form you're submitting.

And did they have to stop allowing written signatures because of AI scraping? Or is it just because they never looked legible at all?

top 50 comments
sorted by: hot top controversial new old
[–] MentalEdge@sopuli.xyz 58 points 2 weeks ago* (last edited 2 weeks ago) (9 children)

The visual signature part of a "digital signature" is purely cosmetic. The actual signature is the entire file being cryptographically signed using a private key you possess, which any recipient can then verify came from you by using a public key.

This is the case for all government issue signatures (like when using the private key inside a chipped government id card) or any other signature created using a key pair from a issuing authority.

If its not a digital signature in this way, the other way is literally just an image. It can be a vector or an raster, or a straight up scan of a physically signed document. It's just a picture. It has no digital verification whatsoever.

[–] A_norny_mousse@piefed.zip 9 points 2 weeks ago (2 children)

the other way is literally just an image (of your signature)

I've done that a few times, in GIMP (or Photoshop), and was always a little surprised that it seemed to be enough. Maybe I unwittingly "forged" my own signature? That's legally murky...

[–] obelisk_complex@piefed.ca 12 points 2 weeks ago

How is it legally murky? Someone asks if that's your signature on the document and do you remember signing it, and it is and you do, so you say yes. End of discussion.

It's only a problem if you're claiming it's not your signature. But then, they have to prove it's your signature, you don't have to prove it's not. I'm not sure you can prove it's not your signature, hence burden of proof being on the other party.

[–] MentalEdge@sopuli.xyz 8 points 2 weeks ago (1 children)

It's really just a digital way to do the equivalent of printing the document, signing it, and scanning it again. Which is also accepted in a lot of situations.

load more comments (1 replies)
[–] FinjaminPoach@lemmy.world 8 points 2 weeks ago (1 children)

🤯

Well that explains everything. Thank you very much!

[–] atx_aquarian@lemmy.world 2 points 2 weeks ago

That didn't quite explain everything. I want to add that there are "type your name to sign" forms that are just what you described, just bytes spelling out your name. In those cases, you're right, those bytes don't have your handwriting to prove anything, but they do accomplish something. If the form is secured behind a login and not a totally buggy heap of garbage, then the act of typing your name on that form demonstrates that whoever logged in deliberately expressed their approval. And whatever level of identity verification is needed for login is then playing the part of demonstrating who did that. That's not perfect, but the level of evidence might match the level of risk enough to justify that mechanism to the company providing it, and it's important to consider all factors: not just system cost, but end user tolerance.

E.g., there was (maybe still is?) a "ham" radio logging system that had end users generate their own PGP signing key pair to sign their log books, which are simply a list of who they talked to over the radio, always for non-commercial purposes (by law). Many questioned whether a secure web site with good 2FA might suffice and be much more convenient, manageable, and adequate risk level for most users.

"Digital signature" is a proper term that should mean what the parent comment explained--public key crypto "signing" (a hash of) a document's content--but "sign here by typing your name" will inevitably get called a signature and, obviously, is also digital, just not a real "digital signature".

[–] jdr@lemmy.ml 8 points 2 weeks ago (1 children)

Surely they're talking about the likes of DocuSign, which doesn't involve any user-controlled keys

[–] Bazoogle@lemmy.world 5 points 2 weeks ago

The only private key with docusign is the fact you has access to the email inbox. And it's not even a private key, just a symmetric key in the link of the email. They might do some basic user agent and IP checks for suspicious activity, but if someone you know has access to your email DocuSign wouldn't know the difference

load more comments (6 replies)
[–] FuglyDuck@lemmy.world 26 points 2 weeks ago (30 children)

physical signatures are just asking you to write your name in a box....

Not a huge difference.

load more comments (30 replies)
[–] A_norny_mousse@piefed.zip 11 points 2 weeks ago

Digital signatures are much more than "just typing your name in a box". The few times I digitally signed a doc I didn't even have to do that, just click on a big green button.

It's all connected to how you authenticated before you got to that point.

I think @mentaledge@sopuli.xyz explained it well.

[–] HobbitFoot@thelemmy.club 10 points 2 weeks ago (2 children)

The point of the signature isn't the mark, but that the affirmation on the document can reasonably be tied to you. For most of history, it has been tied to a certain mark, whether it be a signed name, a stamp or embossed seal, or even a drawing. That system generally breaks down in the digital age.

A low hanging fruit that is seen to work is having the mark of approval get tied to an account under the control of the signee. It isn't so much that you made the mark but that it is tied to an email address you control. So even if you don't sign it with an actual signature, it still gets tied to you.

load more comments (2 replies)
[–] EvilBit@lemmy.world 9 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

I was at a grocery store back when you had to sign the little digital screen for a card transaction and I finished signing, but the cashier got distracted and didn’t accept the signature for a while, so I just doodled Godzilla trashing a skyscraper next to my name.

My best friend was there with me and from that day forward, I’m not sure if he’s ever signed something without adding a Batman logo.

Signatures are arbitrary.

[–] FinjaminPoach@lemmy.world 2 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

That would be precisely an example of how signatures are not arbitrary, but rather marked in our own unique quirks.

"This guy drew a batman symbol on his signature!" "Oh yeah, EvilBit's friend always does that. That means you've got the real deal"

load more comments (1 replies)
[–] laranis@lemmy.zip 7 points 2 weeks ago (2 children)

Had my identity stolen. Thief bought a car with a loan they got online. Forged my signature at the dealer half a country away. I hired a lawyer because BofA are fucking criminals.

Me: "This is clearly not my signature on this document. Doesn't that mean anything?"

Lawyer: "Nope. Not a thing."

WTF.

Now anything asking for my signature is squiggles unrelated to the written language.

[–] FinjaminPoach@lemmy.world 4 points 2 weeks ago (1 children)
[–] laranis@lemmy.zip 5 points 2 weeks ago

Went to court. Judge ruled in my favor. In the meantime I had contacted the Consumer Protection Bureau (US). Back when they had teeth and funding. BofA must have had a whole department that dealt with CPB because that shit got resolved quick. Took more than two months and around $1500 to get it cleaned up.

My credit is locked at all three agencies now. Highly recommend everyone do it. The fact it isn't locked by default is asenine.

[–] oopsgodisdeadmybad@lemmy.zip 2 points 2 weeks ago

Obligatory "bofa deez nuts"

[–] airbreather@lemmy.world 6 points 2 weeks ago

It does as much as does "testifying under oath" does to magically stop you from lying.

i.e., putting your hand on a significant bit of text and saying some special words doesn't stop you from lying, but it DOES create / enhance penalties if you do.

[–] antihumanitarian@lemmy.world 6 points 2 weeks ago

Signature matching/analysis isn't particularly scientific, so in general a physical signature is used for clear authorization, not identification. When you log in to something to sign your identity is already set by other means, so all the signature needs to do is say "yes, I agree to this". E signatures in the US were legally formalized awhile ago, so it's not really a controversy.

[–] Tiral@lemmy.world 5 points 2 weeks ago (1 children)

I think a digital signature is also a way they can prosecute for impersonating someone for identity theft. By you typing and saying "this is me" if it's not, they can use that as evidence.

load more comments (1 replies)
[–] NABDad@lemmy.world 5 points 2 weeks ago

I scanned the responses, and didn't see anyone who mentioned this.

The point at which the U.S. allowed you to "sign" your name by typing was when the E-Sign Act was passed. That was in 2000, long before LLMs were really a concern.

The reason was to make online commerce easier. Verbal contacts could and continue to be enforced, but enforcement requires more effort than with a written contact.

At the time I thought the law was passed by people who didn't understand technology and how easy this made it for people to commit fraud or screw over consumers. However now I realize they just didn't give a fuck.

[–] IWW4@lemmy.zip 5 points 2 weeks ago

The truth is, wet signatures have been absolutely worthless for .. well forever. The first time I had a credit card was in the late 80s and even back then it didn’t make any sense that I was signing receipts in the grocery store.

[–] Limonene@lemmy.world 3 points 2 weeks ago

IMO, that's not a digital signature. That's a normal signature on a computer. Digital signatures involve cryptography. For example, OpenPGP.

[–] bhamlin@lemmy.world 3 points 2 weeks ago (1 children)

The actual shape of your signature hasn't really meant much for some time. As recently as 2005, Visa's contract had the most bizarre requirements.

You are supposed to sign the back of your card. If you paid with the card, you had to sign the receipt. The cashier was supposed to examine the signature on the card and the signature on the receipt and decide if they matched.

But. If the card was not signed, the cashier was supposed to insist that the person present sign the card, and then the cashier was supposed to compare the signatures right there. We were also forbidden by contract from asking for ID.

[–] Kite@sh.itjust.works 2 points 2 weeks ago

It was like this further back than 2005. I worked retail in the mid 90s and it was the same. And if the signatures didn't match, well. Oh well. We had no power to do anything about it. The number of self-righteous idiots I had who thought that they were clever when they would sign their cards as Mikey mouse and then freak the hell out when I never bothered to check because it didn't matter if it was signed Mickey Mouse or Ronald Reagan and you signed the receipt with your actual name. We couldn't do anything! God they'd get so mad. Thank god we had great management that would back us.

[–] CallMeAl@piefed.world 3 points 2 weeks ago (1 children)

Where have "they" stopped allowing written signatures?

[–] FinjaminPoach@lemmy.world 1 points 2 weeks ago

Let me try and rack my brain for everything I've digitally signed

  • recruitment/employment agency (about 2-5 different ones i think)
  • medical stuff? Definitely for private medical care like dentist and foot doc, whereas NHS can just ask for DOB and NHS number.
  • online registration at uni maybe

It's not that they're not allowing written signatures but that they've removed them from everything because it's all done online - they have no space to try and write one with your mouse or your finger, like usual.

If you show up in person they get one on a tablet, though, usually.

[–] Abyssian@lemmy.world 2 points 2 weeks ago

Your signature can be whatever you want to sign. I sign different things all the time. The legality is just in you consenting and making your mark.

Your signature looks different every time you sign it, and it being an exact replica was a way to spot a forgery. A signature has never been some sort of security feature.

[–] amio@lemmy.world 2 points 2 weeks ago* (last edited 2 weeks ago) (2 children)

I think that's probably it, or pure cargo cult because "we've always had signatures so something's got to go in that slot". The whole idea of random scrawls for "authentication" has been weird all along. As if everyone walked around knowing what everyone's signatures should look like. And if you do know, you can just... write it that way.

(Plenty of countries just have digital "signing" that's a bit more like something sane, a central authentication thing based on your ID number and 2FA.)

[–] IWW4@lemmy.zip 3 points 2 weeks ago (2 children)

Remember back in the day when you used to have to sign the back of your credit card.

I would write in that block “ASK TO SEE ID”. At least 100 cashiers would read that and then just stare at me.

[–] Rhynoplaz@lemmy.world 3 points 2 weeks ago (1 children)

Yeah. That's because nobody cares.

We just wanted to get through the line, we don't care who's paying your tab.

[–] IWW4@lemmy.zip 4 points 2 weeks ago

Absolutely!

[–] HubertManne@piefed.social 3 points 2 weeks ago

then like the post office says they won't take it unless there is a sig so I have to write see id and have a sig which of course my id has a sig.

load more comments (1 replies)
[–] boonhet@sopuli.xyz 1 points 2 weeks ago
load more comments
view more: next ›