Cyber Security

Shadow Attacks

All about Shadow Attacks - and why MOXIS users don't need to worry.
Shadow attacks: This futuristic-sounding term has recently been used to describe a possible attack on the signature verification of PDFs. The readers are primarily affected, but not the entire process. XiTrust explains what it is actually about – and why MOXIS users have nothing to worry about.
While paper-based documents are naturally easy to manipulate, digital PDF signatures offer far more security: they ensure that digitally signed PDFs cannot be manipulated at a later date – at least not without the PDF software’s signature verification recognising and reporting the changes. In July, a team of researchers from Ruhr University Bochum uncovered three potential methods with which the signature verification of PDF documents can evidently be manipulated or circumvented. The researchers communicated the vulnerabilities to the manufacturers via the BSI’s CERT organisation as part of a so-called responsible disclosure process. This is a common process in IT security and gives manufacturers time to secure their software with updates before vulnerabilities are published. Almost all manufacturers of PDF readers have already closed these security gaps. It is therefore imperative that you use the latest version of your PDF viewer. Most providers can handle all of these exploits very well. MOXIS is not directly affected, as most attacks occur after signing. Moreover, every document in MOXIS can be downloaded retrospectively exactly as it was signed, meaning that any manipulation after the signature process can be proven and documented.
Testen Sie die führende E-Signatur-Plattform MOXIS kostenlos.

Test MOXIS free of charge for your company..

Get to know the leading e-signature platform and benefit from the advantages of legally secure digital signatures – no credit card required.

Share this article.

Video highlights.

YouTube

Mit dem Laden des Videos akzeptieren Sie die Datenschutzerklärung von YouTube.
Mehr erfahren

Video laden

Don’t scribble, just sign.

Save your paper for the really good ideas. Sign digitally with MOXIS.
YouTube

Mit dem Laden des Videos akzeptieren Sie die Datenschutzerklärung von YouTube.
Mehr erfahren

Video laden

MOXIS Fall Release 2023

The MOXIS Fall Release 2023 will make digital signing with MOXIS even easier, more efficient and more individual.

YouTube

Mit dem Laden des Videos akzeptieren Sie die Datenschutzerklärung von YouTube.
Mehr erfahren

Video laden

Digitally signed …

… sustainably won! Digital signatures for energy suppliers: practical insights and success stories

More from our blog.

Part 2: Using MOXIS to digitalise law firms and legal departments

DSAG Annual Congress 2023: XiTrust sets an example for change and sustainability with MOXIS in SAP

New Data Protection Act for Switzerland – Important facts about the new DPA

The XiTrust blog.

In our blog, we address current topics and the latest developments relating to digital signatures. Additionally, you’ll get exclusive insights into the world of XiTrust.