pdf password protection

PDF Password Protection

Why passwords are useless & how to protect a PDF without passwords

  Free Trial & Demo

“Fantastic product… outstanding support.”

“We would recommend Locklizard to others”

“The clear leader for PDF DRM protection”

“Our ebook sales have gone through the roof”

“Simple & secure – protects IPR from theft”

Trusted by:

Why you should NOT password protect PDF files

  Password protecting PDF files: why use passwords?

Passwords have a strong historic precedent in protecting access to computers and files.  Originally, it was the only mechanism that could be implemented – smart cards and biometrics were just a gleam in manufacturers’ eyes (and some say still are).

Over time, however, they have received increasingly bad press as a security mechanism. This is largely because systems have been implemented poorly, with little understanding of security or human psychology.

The usual approach to password management is to insist on one that has 6-8 characters and numbers and changes regularly.  This approach makes people pick easy passwords so that they have a snowball in hell’s chance of remembering. The same applies when people pick passwords for protecting encrypted PDF documents (or zip files or anything similar).  It is difficult to choose a password that you can easily pass on to the recipient and be sure they get it right unless you choose a short and simple one.

Managing PDF passwords & controlling use


Managing PDF passwords is, in itself, a nightmare:

  • Who has which password?
  • Has it been changed?
  • Can they update it?
  • What happens if you update it?
  • How do you get the password to the recipient securely?
  • If they ‘lose’ it how do you replace it?
You cannot stop users from sharing the password(s) with other people, and you have no way of being able to detect that

And therein lies the problem.  Short passwords that are easy to remember and type are just as easy for an attacker to crack with a dictionary system.  They can break it in minutes, if not seconds.  Even an exhaustive search for all numbers and letters for 8-character positions is stunningly quick – see Removing PDF Passwords.

Sadly, PDF passwords are still popular (as are zip passwords), despite the fact that they are easily passed on to unauthorized users and are often cracked.

This is the catch-22 of passwords: you must share the password for the security to be usable, but in doing so, severely compromizes it.  If you’re using a password to enforce PDF security or DRM, any rights you gave the recipient can be passed on by simply sharing the password.

We therefore have to conclude that PDF passwords are not an effective way to implement PDF security.  They are difficult to manage and easy to defeat.

Password security basics


If you do decide to go the password security route, there are several aspects you need to keep in mind.  Creating passwords that follow these rules will increase the time it takes a password cracking program to compromise them (though it won’t stop users from sharing the passwords with others):

  1. DON’T use a PDF password that’s human-readable: Any password that a human can “read” will be easier for a machine to crack. Dictionary words, dates, names, common keyboard patterns (asdf, 123), capitals only at the start of words, repeating characters.  All of these are easy targets for cracking tools.
  2. DO use acronyms: Completely random passwords are difficult to remember.  Passwords that are difficult to remember are more likely to be stored insecurely (on a post-it note or plaintext file).  The best balance between memorability and security is to create an acronym from a phrase (12+ characters, NOT a common idiom), and add capital letters, numbers, and special characters.
  3. DON’T re-use passwords: Isolate the impact of a password compromize as much as possible.  Reusing passwords or using variants of the same password means that if one PDF is compromized, all of them are.
  4. DO use password generators and password managers: The requirements above will make it harder for you to manage, create, and remember passwords.  This is unavoidable, but you can mitigate it somewhat by randomly generating your passwords and securing them in a password manager.  However, the password manager holds the keys to your entire kingdom, so you better make sure it uses a strong password, 2FA, and even biometrics/a security key where possible.

10 Reasons NOT to password protect PDF files

Although it seems like a good idea to password protect a PDF because it’s easy, most implementations are not effective.  Below are 10 reasons why you should not PDF password protect files.

  • Password Maintenance

    Strong PDF passwords are difficult to set up and use.

  • Password Administration

    You have to administer a list of PDF passwords – ideally one for each document.  This can soon become a burden.

  • The Adobe PDF Open Password must be shared

    The Adobe Acrobat document open password must be given to others in order for users to view PDF files.

  • Passwords are easily shared with unauthorized users

    PDF passwords can be easily shared because they are sent in a readable format.

  • Passwords are easily stolen

    PDF passwords can be easily stolen.  They are often left exposed in plain text documents so that they can be easily remembered or copy/pasted.

  • You don’t know who has access to your protected PDF files

    There is no way of knowing how many people are using a PDF password that has been given away or stolen.

  • Passwords are easily forgotten

    Users often forget passwords and are more likely to try and remove them as a result.

  • PDF Password Removal tools can remove passwords in seconds

    There are many free PDF password removal programs that will easily remove Adobe Acrobat passwords, including the open password.  Even applications like Google Drive and Google Chrome can be used to remove PDF passwords – see Adobe PDF security issues.

  • 16 character ASCII passwords can be cracked in an hour

    It takes just 1 hour to crack 16-character ASCII passwords when a common password has not been used (password crackers check against a commonly used password list first).  If a commonly used password has been used, then it takes seconds or minutes.

Why do people password protect their PDF files?


The simple answer is laziness or lack of research.  They assume that passwords provide ”enough” protection, despite the fact that anybody can search the Internet and buy products that will remove them in seconds.  Search for:

  • pdf password
  • pdf password protect
  • pdf password protection
  • pdf password security
  • password protect pdf
  • password protect a pdf file
  • how to password protect a pdf
  • protect pdf with password

And at least three of the first ten search queries are for pdf password crackers.

Document-level password protection technically isn’t DRM (digital rights management).  And because of the plug-in architecture of Acrobat and PDF readers, it makes PDF a less-secure platform for DRM.” – ElcomSoft CEO Vladimir Katalov.

At a click of a button, pdf-Recover will remove the password regardless of whether it has been encrypted using the latest 256-bit AES encryption.  The result is an exact replica of the original PDF without any security settings whatsoever – pdf-Recover removes all of the restrictions implemented.

So, whilst you can use Adobe to password protect a PDF file for free, the security you are getting is not adequate.

If you are still not convinced, see Removing PDF Passwords and  PDF Security cracks and flaws.

If PDF passwords are not recommended, what should I use to protect my PDF documents?


The key to a secure system is to avoid the user having to know or be involved with passwords at all.

This is best achieved by ensuring that, in a cryptographic system, keys are exchanged securely and secretly, so that even the user is not aware of, and therefore cannot compromise, the security of the system.  Only if you take these steps can you be confident that the protection method you have used is resistant to both deliberate and careless compromise.

It is an accepted fact by all security professionals that the people most able to compromise any security system are the authorized users.  That is not to say that users are deliberately dishonest or even malicious − rather that in most cases they are overly helpful or fail to understand the security functions that they are expected to perform.  This is why phishing and social engineering attacks are among the most common.

Though it’s not easy to design, a system that does not require direct user involvement with passwords or keys is preferable.  Otherwise, the integrity of the system hinges on humans, who are fallible.

  PDF DRM Security without passwords

Safeguard PDF Security and Enterprise PDF DRM do NOT use PDF password protection to protect your PDF documents.  They ensure your PDF documents are encrypted and protected against unauthorized use and misuse without the use of passwords.

Using Safeguard Writer, you can protect a PDF file without passwords and apply DRM controls to prevent PDF copying, saving, modifying, and printing.

Safeguard uses public key technology rather than passwords.

  • PDFs are individually encrypted locally on your desktop and protected using a unique key that is stored, encrypted, on a licensing server.
  • This key is securely and transparently relayed to an authorized client computer (a device that an authorized user has registered their license from) when a protected document is opened.
  • Keys are locked to authorized devices so that they cannot be shared with others.
  • Protected PDFs cannot be copied, printed or shared unless you have specified otherwise.
  • You can set document expiry dates and instantly revoke your PDF files.
  • There are no passwords for users to enter, manage, forget, or pass on to others.

Safeguard uses US Gov strength AES encryption to encrypt PDFs, public key technology, DRM and licensing controls to ensure your PDFs remain protected at all times.  See our DRM Technology.

How to protect PDF files without passwords

Locklizard enables you to protect PDF files without passwords by combining 256-bit AES encryption, a secure viewer application, and a licensing system with transparent and secure key management.

Here’s how to protect a PDF document without passwords using Safeguard Secure PDF Writer
  1. Right-click on a PDF report on your computer and select ‘Make Secure PDF’.

    Creating a protected PDF file

  2. Select the copy protection controls you want to apply.  By default, editing, copying, and printing are disabled.

    Encrypting a PDF without passwords or certificates using Locklizard Safeguard PDF DRM

  3. Press the Publish button to protect the PDF.
  4. Select the users you want to give access to your protected PDF files using the cloud-based Admin System:

    Safeguard Admin System

  5. Then distribute your protected PDF documents just like any other file.

FAQs

Can you password protect a PDF online?

You can, but it’s not usually a good idea.  It means uploading your PDF file to somebody else’s server unprotected.  You have no way to verify what they will do with your unprotected copy after you upload it.  Online tools also use the same password security as Adobe Acrobat and the protection will therefore be easy to remove.

How do I remove password protection from a PDF?
  1. If you know the password, simply remove it in Adobe Acrobat settings.
  2. If you don’t, the PDF permissions password is easy to remove – a free PDF password removal site or app will get rid of it instantly.
  3. The open password is more difficult, and you’ll want to use paid software like Elcomsoft to crack it.
Can you password protect a PDF file in an email?

All email clients that support attachments will allow you to add a password protected PDF. A good password can make it harder for an attacker to extract information should a user’s account be compromized or an email intercepted.  However, there are still aspects to consider – namely, how to transmit the password to the recipient securely and the fact that the recipient can share the password with others.  There are safer ways to send a PDF by email securely.

Can I protect a PDF from editing without a password?

Yes, if you use Locklizard to protect it.  Locklizard enables you to restrict PDF editing without passwords and stop users from copying and pasting content, screen grabbing, printing, sharing and more.

Can I password protect a PDF without Acrobat?

Yes, but it is no more secure.  You can encrypt a PDF without Acrobat using more secure methods such as certificates or DRM.

Can you print a password protected PDF?

Yes, it is easy to remove the permissions by using free software online.  If you want to prevent users from printing PDFs then you need to use a PDF DRM system that does not use passwords.

PDF Password Protection Articles

A History of PDF Password Protection

PDF documents were first developed during the early 1990s as a means of sharing documents among users who had heterogeneous platforms

Read More →

Overview of PDF Password Protection

PDF Password Protection has been around for a long time but does it work? Here we look at it in terms of the good, the bad and the ugly.

Read More →

Why PDF Password Protection is not secure

Is PDF password protection secure? Most people are of the opinion that PDF password protection helps to keep their PDF data secure.

Read More →

Using Passwords to Protect PDF Files

Increasingly, people have become concerned that documents they send out, particularly in PDF format, may be open to re-distribution or misuse.

Read More →

Removing PDF Password Protection

A well-known technology website offered technical experts the opportunity to crack a 10,000+ entry-encrypted password document and asked

Read More →

How to Password Protect PDF Files

Adobe was the earliest pioneer in producing PDF documents. Over the years they added a number of security controls to protect PDF

Read More →

Cracking Password Protected PDF Files

How Easy It Is To Crack Password Protected Pdfs? Answer: Very. There are a number of advantages in using PDF documents, and chief amongst the

Read More →

Password protecting PDF files

Here we cover the use of a password to protect the opening of a PDF document rather than a permissions password (which is easily removed)

Read More →

PDF Security issues, flaws, and cracks

Information on PDF security issues, vulnerabilities, flaws and cracks in Adobe PDF and other PDF Security products.

Read More →

Customer Testimonials