Aller au contenu principal
PDFCraft
Retour au blog
Sécurité

PDF passwords and permissions, explained

Open passwords, owner passwords, AES-256 and permission flags — what each one protects, what it doesn't, and how to use them properly.

Par PDFCraft Team3 min de lecture

"Password-protected PDF" covers two very different things, and mixing them up leads to both false confidence and needless frustration. Here is what is actually happening inside the file.

Two passwords, two jobs

The user (open) password is the one everybody understands: without it the document cannot be opened at all. The file's contents — page streams, images, embedded fonts — are encrypted with a key derived from that password. With a strong password and modern encryption, the content is unreadable to anyone who does not have it.

The owner (permissions) password does not prevent opening. It controls a set of permission flags: whether the reader may print, copy text, edit, annotate or fill forms. A PDF viewer that respects the standard enforces these flags for anyone who opened the file with the user password (or with no password, if none was set). Someone who knows the owner password can lift the restrictions.

The important consequence: permission flags are a request, not a guarantee. They are enforced by well-behaved viewers, but the data itself is decryptable by anyone allowed to open the document. Do not rely on "disable copying" to protect confidential text — rely on the open password, or better, on not sharing the file.

Which encryption is used

PDFCraft's Protect PDF tool encrypts with AES-256 (revision 6), the strongest scheme defined by the PDF 2.0 standard and supported by every current reader. Older RC4 40-bit or 128-bit encryption, still produced by some legacy software, can be broken by brute force in minutes to hours and should be considered obsolete.

Encryption is only as strong as the password. A four-digit PIN protected with AES-256 is still a four-digit PIN. Use a passphrase of several words or a generated password of twelve or more characters, and share it through a different channel than the file itself.

Setting protection with PDFCraft

  1. Open Protect PDF and upload your document. The file is processed on the server (encryption needs qpdf) and deleted automatically afterwards.
  2. Enter the password readers will need to open the file. Optionally set a separate owner password; if you leave it empty the open password is used for both.
  3. Tick the permissions you want to allow: printing, copying text and images, editing, comments and annotations, and form filling.
  4. Download the protected file and verify it by opening it — you should be prompted for the password.

Removing protection

Unlock PDF removes encryption from a document you are authorised to unlock. If the file has an open password, you must provide it — there is no way around the mathematics, and PDFCraft does not attempt to brute-force or bypass encryption. If the file has only an owner password (it opens without a password but blocks printing or copying), the restrictions can be removed directly, which is legitimate when you are the document's owner or have permission from them.

What password protection does not do

  • It does not stop someone who knows the password from removing it and redistributing the file.
  • It does not hide the document's existence, its page count or its file size.
  • It does not sign the document or prove who created it. For integrity and authorship you need a digital signature backed by a certificate, which is a separate feature from encryption.
  • It is not a substitute for access control. If the file should only be seen by three people, send it to three people.

Used for what they are — a strong open password for confidentiality, permission flags as a polite fence — PDF security features work well. Used as the only line of defence for genuinely sensitive material, they disappoint.