ratgeber

PDF Security: Encryption, Permissions, and Digital Signatures

A clear guide to PDF security features, password types, encryption standards, permissions, digital signatures, and redaction. Know which to use when.

PDF Security, More Than Just a Password

When people think about PDF security, the first thing that comes to mind is usually a password. But the PDF format offers a full spectrum of security features, each serving a different purpose. Understanding which mechanism addresses which problem leads to better, more deliberate decisions about how to protect documents and communicate their status.

Two Types of PDF Passwords

The PDF standard distinguishes between two fundamentally different types of passwords: an open password (also called a user password) and a permissions password (also called an owner password).

The open password prevents the document from being opened at all without knowing the password. Anyone wanting to view the document must enter it first. This protection is appropriate for confidential documents shared only with specific, trusted recipients.

The permissions password does not lock the document from opening, instead, it restricts what someone can do with it once opened. Possible restrictions include: disabling printing, disabling text copying, disabling editing, and disabling commenting. The document is readable, but certain actions are blocked. This is appropriate for reports or e-books that may be read freely but should not be reproduced or modified.

The protect PDF tool supports setting both password types and configuring the permissions that apply.

Encryption Standards and What They Mean

Not all password protection offers the same level of security. PDF encryption has evolved through several standards: older 40-bit and 128-bit encryption, and the current 256-bit AES standard. Older encryption methods are considered weak and can be bypassed with freely available tools. Current AES-256 encryption is considered secure, provided a strong password is used.

What counts as a strong password? At least 12 characters combining uppercase and lowercase letters, numbers, and special characters. Short or predictable passwords, years, names, common words, provide no real protection against a systematic attack.

Digital Signatures, The Basics

A digital signature is fundamentally different from a scanned handwritten signature. It is a cryptographic mechanism that simultaneously verifies two things: the identity of the person who signed (authentication) and that the document has not been modified since it was signed (integrity).

If a digitally signed document is altered in any way after signing, the signature becomes invalid, this is immediately visible in any PDF viewer that checks signatures. This makes digital signatures significantly more reliable than scanned handwritten signatures, which can be copied from one document and placed into another with no technical obstacle.

The sign PDF tool enables adding a digital signature directly in the browser. For legally binding signatures meeting specific regulatory requirements, a qualified electronic signature service may be required.

Simple, Advanced, and Qualified Signatures

The EU eIDAS regulation distinguishes three levels of electronic signatures. A simple electronic signature is the lowest level, it includes a scanned signature, a typed name in an email, or clicking a consent button. It carries no special legal weight on its own.

An advanced electronic signature is linked to the signatory, enables identification of the signatory, and makes any post-signing changes detectable. It is created using data that only the signatory controls and requires a certificate, though not necessarily from an accredited trust service provider.

A qualified electronic signature (QES) is legally equivalent to a handwritten signature under eIDAS. It requires identity verification and a certificate from an accredited trust service provider. For contracts, regulatory filings, and legally binding documents, QES is the appropriate level.

Permanently Redacting Sensitive Content

A common misconception: placing a black rectangle over text in a PDF viewer makes the text unreadable. In many cases, it does not, the text can often be recovered by selecting and copying it, or by removing the overlay graphic layer. Genuine redaction goes further.

Proper redaction removes the selected text and images permanently from the PDF, including from the data layer that underlies the visible page. The redact PDF tool does exactly this: selected content is not merely covered but removed entirely and irreversibly. This distinction matters critically for legal documents, government records, and medical documents where privacy compliance requires that certain information genuinely cannot be recovered, not just obscured on screen.

Removing Password Protection, When It Is Legitimate

Sometimes it is necessary to remove protection from a PDF you previously secured, because the password is no longer needed or because the document needs editing. The unlock PDF tool removes protection from a document when the correct password is provided.

An important note: circumventing password protection on documents you do not own or have no authorization to access is illegal in most jurisdictions. These tools are intended for legitimate use, such as removing protection from your own documents that you secured yourself.

PDFs bearbeiten leicht gemacht

Probiere unsere kostenlosen PDF-Tools aus, ohne Registrierung, ohne Limits.

Alle Tools ansehen