USPS Providing Electronic Postmarks
isn't my name writes "Back in 2000, Clinton signed the ESIGN Legislation which set forth the requirements for making electronic signatures. But many questioned the weakness of its definitions that allowed an e-mail address to be used as an electronic signature. Well, it seems the USPS has come up with something stronger. They even have a Java and MS COM SDK's Apparently, the USPS feels that the strong legal protections against interfering with the US mail will apply to the EPM program. It seems that AuthentiDate is doing all the heavy lifting. According to the whitepaper on their site, it provides non-repudiation and legal timestamps of documentation by having the customer use a public-key to sign a hash of the document, which is then sent to AuthentiDate's servers which combine that with a timestamp and sign with their key. So, AuthentiDate does not have access to any of the data in the documentation. It sounds very similar to the free PGP Digital Timestamping Service, but it likely is more likely to be legally defensible in a US Court. They also have a new plug-in for MS Word documents. Interestingly, despite the mention of the SDK and it's ability to work with any documents, the only login setup I could find just allows you to use the MS Word version."
I've been working on something similiar for another division of the US government.
;).
The biggest thing driving this are two issues:
1. Government Paperwork Eliminiation Act - signed by Clinton, it basically tells the various agencies:
1. "reduce paperwork by having forms available online".
2. "When possible, have those forms electronically signed."
The problem is that most government agencies, except maybe the IRS, and then in limited form, really don't have any kind of system set up for doing #2. They're getting pretty good at #1 (having documents available online), but #2 has been a challenge.
The biggest challenge is initial setup. For the Department of Agriculture, you can do electronic signatures over the web. But first you must physically show up at one of their offices, validate your identify, and then you're good to go.
That works all right for them, but suppose you're somebody like the IRS, with around, oh, 200 million "clients". Now you have to process them all, validate their identity which means having them show up at a local office (long lines and all). Then there's the issue of what system to use, validation procedures, how to keep Joe American from forgetting their password, and if they lose it, how do they get it back in a way that's secure and doesn't cost a lot of money?
2. Money. Believe it or not, most people in government agencies really want to save money, not spend all of it.
Honest.
So by having electronic signatures, they can reduce paperwork, install workflow systems so that when a document is digitally signed it can be forwarded right to the people who need to see it to be reviewed in minutes instead of days, without all the messy paper getting lost and so on.
I'll probably be checking out the USPS's system to see what they do. If it's reasonable, secure, ensures privacy, and truly has an open API that would allow other agencies to develop systems based on it, it may be the electronic signature "standard" that some government agencies are looking for.
Guess I'd better RTFA now
52 Weeks, 52 Religions with John Hummel
That it's word only ATM (as far as I also can find out from the site) is irrelevant... Well, nearly so. With the Java SDK any application from any OS appearently can easily be enhanced with their Electronic Postmark capabilities.
What I'm wondering about is the "Nationwide reach and trust" point they list in "Benefits of EPM".
Does the strong encryption make it illegal to use this for international communications?
I'm a dreamer, the world is my playpen. But hey, I'm a serious person, I can't dream all the time.
The EPM is designed to deter and detect any fraudulent tampering or altering of electronic data.
...
Hell, they weren't even able to deliver the bubblewrapped hard-disk I sent in a triple-thickness FRAGILE-sticker-equipped box I overnighted to my business partner in one piece
"A door is what a dog is perpetually on the wrong side of" - Ogden Nash
I am sick and tired of having to FAX my damn signature around the place
1. print the form
2. sign it
3. scan it
4. fax it
I mean, come on - how outdated is this method?
If the Banks let us use online banking to transfer all our money around, surely a digital signature system can be built.
But then, I am not an encryption expert so what do I know.
You can't expect to wield supreme executive power, just because some watery tart threw a sword at you
I find it troubling that a government that is supposedly FOR free and open competition in the marketplace decides to use a proprietary interface as a legal standard for electronic signatures. Surely there is a platform and application neutral solution that can be utilized not only by Micrsoft's office applications but also by those that choose to use other means -- be they Linux, Macintosh or other. For example, a significant number of law firms still use WordPerfect Office.
Of course, Microsoft Word is by and far away the market leader in word processing, as is their IE product. But also consider that Microsoft is a convicted monopolist and now comes the government to further propogate their disproportionate market share which was gained (as decided by the courts) by illegal means.
Makes you wonder, exactly whom does our government represent? This would appear to be another brick in the edifice of evidence that it is not us, the people, but instead, them the corporate interests.
Boo!
My only comment to this is that fact that for it to really work each person who uses it will need a (public) key. In order for that to work you need to validate the users' identity.
Does this mean that I will goto my local post office and sign-up, get I&A (Identification and Authentication) done and then get my key?
Are the keys real public keys ie: PKIX and PKCS standards?
Actually Word is not suitable for the purpose anyway. A word document may contain macros and scripting which change the way the content is rendered *after* it is signed.
So be very careful when you trust a digital signature on a word document, next week it may say something quite different...
I think depending on a regulated email system like this to prove legal timestamping is foolish. Any number of things can delay an email - would you send your taxes by email five minutes before they were due? If a late timestamp meant a fine?
Typos... that's just how I role.
Is calling the service a postmark truly correct in the traditional use of the postal serivce? This just looks like a Government sponsered notary service.
Now if we can get a true email version of registered mail where every server in the chain signs the message, that would be something useful
I make my face look like this and concerned words come out.
it provides non-repudiation and legal timestamps of documentation
...
It gives a whole new meaning to the term "going postal" when you find out that authentic-looking digitally-signed Nigerian business proposition wasn't such a good deal after all
"A door is what a dog is perpetually on the wrong side of" - Ogden Nash
You know, using such a service to put a date on your sourcecode is a good idea in case you ever end up having to prove when you first coded it (or at least, had it in your possesion); for example, if you need to go after a company stealing your code (GPL non-compliance) or if a company comes after you (SCO?).
SCO employee? Check out the bounty
You think, that if this were in any way influenced by MS, there would be a Java SDK? MS hates Java.
Just because the first sample implementation is in Word, doesn't imply there is some conspiracy. The USPS probably uses Word internally and wanted to make the sample usefull for them. With the JavaSDK you could use this in Linux, FreeBSD, hell even embedded applications.
Take off your tinfoil hat.
Now if USPS would get electronic efficiency, that would be quite a good new feature!!!!
May the source be with you!
10 links in one article - I like to keep up on stuff but that article had more links than a full day at FARK (and far less boobies)...
Of course the USPS should sponsor a company to do this.
Much better then just working with the existing projects.
you mean like in this phrase?
...
i-t-apostrophe-s slick i-t-s bits fit i-t-s kits.
Stupid grammar nazis
I couldn't find any price quote for the SDK: just a contact. I'm assuming with the USPS' budget problems, that they'll charge for this.
Does anyone know if they're charging and how much?
There is no spoon or sig.
And of course, there is a free PGP timestamping service, but unfortunately, that does not have the backing of the USPS.
Anyone know of something similar that is cheap?
Want to do this now as an end user ?
go to http://www.getstamped.com/
I know that a lot of people reading /. hates copyrights and patents... but of these digital postmarks stand up in court, they can be of great benefit to individuals and small entrprenurs in their efforts to compete with 'the big guys'
... and possibly give others the confidence to share their creations.
People can publish their ideas, essays, music on the internet complete with a copy of the digital postmark, and should a big fish try to patent or claim copyright or patent on the material, the small-time individual can point at the digital postmask and prove their ownership.
I personally would support this... I would love to be able to share some of the ideas I have - but I do not want someone else to come along and try to patent them or claim that it was their's first. Such a digital postmark would give me the confidence to share
Just my 2cents worth.
-- The universe began. Life started on a billion worlds...
-- Except on one where stupidity was there first.
I talked to the PR people and a hardcore tech from the company at Comdex. I bitched them out about the MS only, and used the usual arguements. One of the things they said was that linux support was on the list, and more importantly, the next version of Adobe products would support thier tech. I know Acrobat was on the list, but I don't remember if the rest of their programs were.
:).
I guess it is time to start writing all those people I got cards from at Comdex and write an article on this
-Charlie
But it does seems like the USPS's implementation that has only allows Microsoft Work Docs. Only for now I hope.
Instead of making clients use java...this should be a simple webservice. Submit a document, get back timestamped document. That way you could do it from pretty much any platform.
but it likely is more likely
now just how likely is that ????
This is just one step closer for the postal service to be able to charge for each e-mail sent (at least those that are signed). Guess it's not an urban legend for much longer!
</TinHat>
sarchasm: The gulf between the author of sarcastic wit and the person who doesn't get it.
This might be a little hypersensitive but I feel a little nervous about putting this signature system in the hands of a company with no proof that the code nor the process is secure. I know OS code is not flawless but at least it can be peer reviewed. Also, what if the company goes out of business. I have no problem with a company managing the sinatures, but I am just a little apprehensive about betting only on the future of a company. Also, this does not seem even a little bit innovative. Essentially they are talking about doing a digital signature. We were doing very similar projects in my CS security class using OS security tools. Digitally signing a hash is nothing new. Maybe I am being naieve, but I don't think so. If I am being naieve, please explain how.
LEPP
Tampering by a macro or script would change the file, thereby making it incompatible with the hash, no?
Not necessarlity. If you have a macro that re-writes the document, the hash would change, and the tampering would be caught.
But: If you make a macro that doesn't change the contents of the file, but rather a macro that changes just the view, the hash would be the same.For example: You write a document that contains both correct and false information. Before a certain time, the correct information is shown. If you open the document after a specified date, the macro changes what is shown to the reader.
For this wanishing ink to work
- it must be possible to write such a macro.
- the reader must trust all macros.
- the reader must not be savvy enough to examine the raw word file.
Irene KHAAAAAAN!
In UK, the move to digital signature was pioneered by Inland Revenue (IRS for Americans). The Government's Gateway provides the digital certificate, which then can be used to digitally sign online forms.
However there were concerns that the implementation is too proprietary, risking dependence to few vendors. Considering what the Gateway's doing, I think these concerns are valid.
There were also little silliness along the way, such as the 50 poundsterling discount by Inland revenue (IRS for Americans) if you submit your tax online and sign it with your certificate BUT the certificate itself cost 50 poundsterling as well, etc.
But I haven't followed it for quite a while now, hopefully things are better now.
There's probably a sourcecode escrow service like that somewhere (perhaps sourceforge?), or you can register it with the US copyright agency, whatever it's called (as a literary work).
The WGA (Writer's Guild of America) lets you email in a file in whatever format, they timestamp it and will support you in court, let you download it whenever (as a backup).
I believe it's free if you're a member, or ~50 US$ otherwise, but I'm not sure how long they keep it. At least 10 years, and I think more like 30 or 50.
Umm, well, if you are worried about that, just register your code with the U.S. Copyright Office - that is the whole reason for the Copyright Office's existence - to register copyrights and provide legal recognition that every court MUST accept, that you registered copyright on something on a certain date (granted it doesn't prove you actually OWN the code you copyrighted - see e.g. groklaw.net articles about how both Novell and SCO claim to have registered the copyrights for ATT Unix with the copyright office).
That is the legally RECOGNIZED way to 'timestamp' your code. By sending it to the copyright office.
There is an article by PGP Corporations CTO Jon Callas about it. His tagline is "Do we need another version of digital timestamps?"
What he has to say looks like plain common sense to me:
His conclusion: "To me, this seems like a solution in search of a problem." He even mentions open standard file formats. Nice read.
In the protocol descriptions, the customer who wants to sign a document first produces a hash and signs that. That is sent to the USPS who combines it with a timestamp and then signs the whole thing.
So, you can verify the persons signature and verify the time that it was submitted for an electronic postmark. Based on the language in their whitepaper, they are really looking at setting up a system that is as legally strong in court as a physical signed document.
I do wonder about the fact that they are only keeping the verification data online for seven years, though.
Before submitting the article, I e-mailed to ask about this and the pricing. Did not get a response until after I had submitted to Slashdot, but here is the link for requesting an SDK.
:)
And here is the link for pricing. Note, I was told that the introductory pricing period has passed and I was also told that the entire website was due for an update in the next week or two. Had I known that when I submitted the Slashdot article, I would have waited a bit. Maybe a good slashdotting will get a redesign that can handle a heavy load.
ZapMail, except this time it being legal comes from a digital signature AND a money trail, instead of just a money trail. It didn't work before, so I'm skeptical.
When are they gonna' stop smashing everything they ship to bits?
And how long before a Linux version and applicable plug-in is available for OpenOffice.org? I mean, I'd love to be able to take advantage of this type of technology, but until it's ported to Linux, it's of no use to me!
It's bad enough that the signature system only works with Microsoft Office, but it doesn't look like it supports Office on the Macintosh--it would appear that people don't even have to pay lip service toward supporting more than the MSFT hegemony.
Everyone keeps talking about the non-repudiation of digital signatures, but it's possible for your signature to end up on documents you didn't actually sign. What are you supposed to do once this happens; how does one prove they didn't sign the document?
USPS delivers a digital, signature-certified mail system
It is no where to be found in usps.gov anymore.
I e-mailed for more info and was provided this link to request a Java SDK:
https://www.uspsepm.com/crm/sdkRegister.adate
Why did they come up with something new that requires special SDKs and probably uses a new file format, instead of just using OpenPGP?
As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
Can somebody explain to me how a Microsoft Advertisement landed itself on a Government website (https://www.uspsepm.com/epm/epm_office_ext/index. htm)? The domain is owned by the USPS. Am I missing something here? I was under the impression that commercial advertising was not permitted on government help domains...
the site is "powered by" Authentidate. At 80 cents for each (25 min), who do I have to bribe to get that contract!
The grass is only greener, if you don't take care of your own lawn.
Is it just me, or is that electronic postmark the ugliset thing you've ever seen? That's like signing a love letter with a big Hallmark ad...
The Philosophy of Liberty | lewrockwell.com
Hell, I thought Authentidate was a dating service that guaranteed the gender of your potential date.
Every transaction on the Internet I complete must somehow involve them, if the merchant is unwilling to accept a USPS money order, delivered via the USPS I will have nothing to do with them. Look up the fraud division, they go completely bizerk when anyone uses them to commit fraud, they want to send you to federal pound you in the ass prison, they live for catching scammers.
They still have a 2.5 million reward for the person who sent the anthrax letters. Along with 100K for information for the murder of a mailcarrier, does your job put bounties on people who kill you?
Would you really have the desire to mess with the people who define "going postal".
IF IT WERE OPEN!
I had missed that they were attempting to patent it. Yes, I do think a patent on this would be pretty ridiculous. I'm certain you could find the system described in many published works. I'll bet the patent is in the automating of the process using their API--but likely worded so broadly that it can be used to go after many other implementations.
No more blocklists a la SPEWS...
Sun could easily gain a huge advantage for StarOffice (over Microsoft Office) by offering this feature for free in StarOffice. It should be easy to develop and very cheap to provide.
Perhaps a simple timestamp/hash version could be included in the free OpenOffice, with a more advanced certificate based or user-ID authenticated option in StarOffice.
This would also be perfect for Adobe to offer for Acrobat PDF files.
If free and non-proprietary, it would quickly become a popular standard, and perhaps THE standard.
so then requiring a fingerprint for a USPS client certificate would violate the commonly held economic rationale:
:)
that this sort of mechanism annoys and risks alienating honest customers, provides little tangible deterrant to actual criminals, and yet costs significant amounts of money to implement and maintain.
We had a terminology gap
// "Can't clowns and pirates just -try- to get along?"
As long as they set broad terms on usage this will prevent control of the process by some Johnny comelately.
I once had a very similar idea and developed a working perlscript implementation. But I never had the time to release it officially. So if someone is interested in a free (as in freedom aswell as gratis) timestamping service you may download my package from the below link and email me comments:
t ar.gz
http://bokstavera2.sourceforge.net/GPGNotary-1_0.
(remove the space in the link).
While this will be a great boon to people looking to defend copyrights, there is a downside to this legal defensibility: what happens if someone gains access to your PC? I can just imagine trying to defend myself in court by saying that while there is a signed and dated document delineating my plans to murder someone, I did not actually commit the act nor did I even write the document. Fun fun.
Correct. It's covered by the "examine the raw word file" criterium.
Irene KHAAAAAAN!
The mail I sent:
"Good day,
I was merely wondering wether or not EPM will be offered as an international service, rather than merely national as the " Nationwide reach and trust " point in "Benefits of EPM" on your website seems to suggest.
If it is to be only national, this will obviously obstruct the adoption of EPM somewhat.
Also, if it is national only, is this due to laws against exporting strong encryption?
Yours truly,
My Name - Norway "
Reply:
"
The USPS EPM has legal standing in the United States. To your point, however, we can not state with any certainty how it will be viewed by other countries' legal systems. However (and this is a BIG however) many postal organizations around the world are also developing their own EPM - type systems. And our UN chartered global postal administration (Unviersal Postal Union, located in Berne) is in the middle of creating standards and getting each of the world's postal administrations to build EPM systems that adhere to a certain minimum set of criteria. And, as you know, postal organizations worldwide have agreements in place to help each other deliver mail without the process being cumbersome to the sender or recipient. So the UPU will also handle similar agreements behind the "Postal-offered EPMs" of the world.
The situation you are concerned about does exist today, but folks are working on making the EPM standards international and reciprocal. It will take a while (as all standards organizations do) but it will come together eventually.
I hope my answer helps.
Leo Campbell
EPM Program Manager
"
I'm a dreamer, the world is my playpen. But hey, I'm a serious person, I can't dream all the time.