• Septimaeus@infosec.pub
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 months ago

    I’m curious about this. If demonstrable, many could sue for damages.

    For these government websites, what is the typical user workflow?

    1. An embedded Adobe applet (e.g. fill, sign, and submit on the government website)
    2. Token-based API (e.g. redirect or spawn child window/tab, user fills and signs on adobe site, user returned to government site).
    3. Something else, such as a document upload button with server-side validation for digital signing?