4. Trustworthy communication
The disadvantage of email communication is that it is not very trustworthy. How can we increase the trustworthiness of messages and attachments?
Did it happen?
Mirek is 26 years old and works as a clerk in the internal affairs department of the regional office. When he arrived at work, he found three urgent emails. His manager asked him to send him contracts that were subject to trade secrets. She urged him, arguing that the supplier was about to declare bankruptcy, which could mean a problem. She wanted to read and verify the contracts. Mirek quickly handled it in a time crunch. He was surprised that his manager was writing to him from a private email, but since she was on vacation and writing about an urgent matter, he didn’t pay attention. As a recent graduate and a new employee, he didn’t want to object. Later, he found out that it was a scam that his manager had nothing to do with. Someone had borrowed her identity.
Electronic signatures
The pitfall of electronic communication is low trustworthiness. To increase its trustworthiness, electronic signatures were invented. Electronic signatures prove that we really sent the message and that it was not altered in any way. But be careful! The term “electronic signature” can be confusing for many users. Some people imagine a scanned handwritten signature, some a signature on a tablet using an electronic pen, some clicking the “I agree” box, and some copying an SMS code. In a way, an electronic signature is all of the above. In a way, it is none of the above. The confusing thing is that the legal perspective on the matter is often different from the IT perspective. Legend has it that a group of lawyers once debated electronic signatures and when they couldn’t agree, they invited IT experts to join the debate. They say they are still debating to this day. Let’s take a closer look.
Simple electronic signature
These are all the methods mentioned above. For example, the aforementioned scanned signature attached to the document. It is a well-known practice, which according to legal interpretations is also sufficient for concluding contracts. We receive a draft contract by e-mail, print it, sign it, scan it and send it back. Legally, this is fine. The problem is that such a signature is easy to remove from the document and misuse at will. With a simple electronic signature, it is also not possible to guarantee that it was attached to the document by the person to whom the signature belongs. It is also not possible to guarantee that no one has modified the document after signing. If we wanted to use such a signature, for example, for official communication with Czech authorities, we would not be able to do so.

The illustration shows that a simple electronic signature is, from an IT perspective, like a piece of paper stuck to a contract.
Source: advokatnidenik.cz/2020/05/04/podepisovani-soukromych-listin-vcera-dnes-a-zitra/
Guaranteed electronic signature
A simple electronic signature is “created with a pen”, a guaranteed electronic signature is “created with a certificate”. As users, we can literally buy a certificate for a few hundred. We get it stored on a chip card, for example, and install it on our device. The certificate has two parts. Public and private. The public part asks: Did Jan Novák sign the document? And the private part answers: Yes, Jan Novák signed it. A guaranteed electronic signature guarantees that it cannot be removed, copied, or misused from the document. It also guarantees that no one has modified the document after it was signed. However, if we wanted to use this signature for official communication with Czech authorities, we would not be able to do so. Why? Jan Novák is not like Jan Novák. The problem is also that if the user is not careful with his device, his certificate can be stolen or copied. Although no one can remove, copy, or misuse our signature from the document, they can steal our certificate, i.e. our “pen”.
Guaranteed electronic signature with a qualified certificate
This type of signature guarantees all of the above, but it can also guarantee the identity of the signer. It guarantees that the document was actually signed by Jan Novák, born on December 14, 1992, with permanent residence in Blansko. Why? Because we obtain a qualified certificate from a so-called certification authority, which thoroughly verifies our identity against documents when issuing a certificate. Certification authorities, such as the Czech Post, can say: “We guarantee that we have verified this Jan Novák against documents and issued him this qualified certificate.” If we want to use this signature for official communication with Czech authorities, we are doing well. However, the disadvantage of the signature remains. The certificate, i.e. the “pencil”, can be stolen.

The illustrative image shows the approximate prices of qualified certificates from PostSignum as of March 2022.
Source: postsignum.cz/certifikaty.html
Qualified electronic signature
The highest level of electronic signature. It guarantees all of the above, but with improved security. We do not install the qualified certificate on any device. It remains on the chip card that we receive during setup. It is technically impossible to steal it from the card. Moreover, the card itself is not enough for signing. We only connect the card to our device when we want to sign. And similarly to paying with a payment card, we need to know the PIN. People pay more attention to things they can pick up than to something that is “installed somewhere”. That is why the card with the certificate is protected in a similar way to an identity card. That is why current identity cards can be issued with a chip that makes them the carrier of a qualified certificate. We can use this type of electronic signature for official communication with Czech authorities.
Data mailbox
A data mailbox is used to send and receive trusted messages, so-called data messages. When setting up a mailbox, the identity of the applicant, the future owner, is verified. Therefore, a data message sent via a data mailbox has the same legal force as a guaranteed electronic signature with a qualified certificate. The disadvantages are also similar in the event that someone unauthorized gains access to the data mailbox. What are the interesting differences? An electronic signature can be paired with an e-mail mailbox and messages can also be sent abroad. Data messages can only be sent to data mailboxes, which are a “Czech invention.” An e-mail with a proper electronic signature can be used to communicate directly with a specific official, while a data mailbox can only be used to communicate with the entire office as a whole.

The illustration shows the appearance of the data box as of March 2022.
Source: mojedatovaschranka.cz/static/ISDS/help/page5.html#5
Pocket puller
| 1. Electronic signatures | 2. Simple electronic signatures | 3. Guaranteed electronic signatures | 4. Qualified electronic signatures |
| There is no electronic signature like an electronic signature. The legal and IT perspectives on this issue differ significantly. Only some types of signatures increase the credibility of communication. | A scanned signature and its variations do not guarantee the identity of the signer or that the document or message has not been altered after it was signed. Such signatures have no security value. | Guaranteed electronic signatures are better in terms of security. Guaranteed electronic signatures based on a so-called qualified certificate have a higher value. We can obtain this from a certification authority. | A qualified electronic signature is considered the strongest in terms of security. The certificate is stored, for example, on a secure chip card that is connected to the device. We also need to know the PIN. |