A fax is not more secure than email

The way complex organizations assess technology and security is often very silly:

A: “Here is the signed document, as a PDF file that I scanned and emailed.”

B: “No good. We need a hard copy.”

A: “Well, I can mail one to you within about a week.”

B: “That’s far too long. Why don’t you just fax it?”

A boots laptop

A opens PDF file

A clicks ‘print,’ plugs laptop into telephone, sends the fax.

Result: a lower quality version of precisely the same thing is transferred, at greater expense.

  1. In fairness, the person asking for the fax probably doesn’t set policy. If the rule book says that a fax is a ‘hard copy’ and an email is not, there isn’t much that they can do.

  2. milan, congrats. you have pretty much summed up the inner workings of the french republic in one paragraph.

    i’ll see if sarko will give you a better offer to streamline the bureaucracy than EC will to fight climate change.

  3. Schneier Asks Why We Accept Fax Signatures

    Bruce Schneier’s latest commentary looks into one of my pet peeves: faxed signature requirements. He writes “Aren’t fax signatures the weirdest thing? It’s trivial to cut and paste — with real scissors and glue — anyone’s signature onto a document so that it’ll look real when faxed. There is so little security in fax signatures that it’s mind-boggling that anyone accepts them. Yet people do, all the time. I’ve signed book contracts, credit card authorizations, nondisclosure…” It’s amazing how organizations are sometimes willing to accept low-quality, unverified scans delivered over POTS as authoritative, when they won’t take the same information in a high-resolution scan delivered over (relatively secure) email.

  4. Fax Signatures

    “On October 30, 2004, Tristian Wilson was released from a Memphis jail on the authority of a forged fax message. It wasn’t even a particularly good forgery. It wasn’t on the standard letterhead of the West Memphis Police Department. The name of the policeman who signed the fax was misspelled. And the time stamp on the top of the fax clearly showed that it was sent from a local McDonald’s.”

  5. To clarify the above, there are at least two measures of ‘security’ to consider here:

    1) Security from interception.

    2) Security from forged documents.

    Fax is probably worse than email for (2), since the quality of the images is low and they are in black and white.

    When it comes to (1), that depends on the position and resources available to potential attackers. For instance, if you are worried that the IT people at your office might look at an email message, fax is probably more secure.

