Improve email forward security to prevent impersonation and other risks
When you forward a signature email to another party, this new party can sign as you without anyone the wiser. I perceive this as a potential security breach.
Steps to reproduce:
As sender, prepare a document to be signed by signer1.
Disable the signature forwarding toggle.
Send by email.
As recipient1, forward the email to recipient2 (email forward, NOT the button in the body of the email)
As recipient2, open the document and observe that you are signing as recipient1.
On the top of my head, automated email forwarding are particularly problematic in this case, among other security concerns. Also consider someone forwarding the email to share the document for others to see, oblivious to the fact that this sharing method enables signature impersonation.
I understand forwarding an email is assumed a voluntary act on the part of recipient1, and I also understand the use of Recipient verification could be enforced if this phenomenon is suspected.
But if possible at all, such email forwarding should void the unique signature link automatically, especially when the option signature forwarding is toggled off. This is especially counterintuitive (hence can participate in a false sense of security / blind spot).
This behavior really sheds a different light on the attached certificate to downloaded pdfs; "✓Email verified". Well...