Security
How to password-protect a PDF, and what it really protects
Add an open password and the file is genuinely encrypted. Nothing can read it without that password. The separate permission settings, like blocking copying, are requests that only some readers honour.
Most letdowns with PDF protection come from expecting it to do more than it does. One half of PDF security is strong. The other half is more like a polite request.
Two different things
PDF security is two separate features that share one settings box.
The open password (encryption). The file's contents are locked with a key made from your password. Without it there is nothing to read, only scrambled data. No reader, no tool and no website can show the document. This is real encryption and it works.
Permissions. A set of settings stored inside the file saying what a reader *should* allow: printing, copying, editing, commenting, form filling, rearranging pages. Encryption doesn't enforce these. It is up to whatever program opens the file to respect them.
Mixing the two up is why people block copying, open the file in Chrome, select the text, and decide the tool is broken.
What happens with each
Take a PDF, set an open password, and block copying. Then try to get the text out.
Without the password: nothing works. No PDF reader or other program can open the file at all. This is the part that protects you.
With the password: Adobe Acrobat and Reader grey out Copy and Select All. Foxit and most desktop readers do the same. Chrome's built-in PDF viewer ignores the setting and lets you select whatever you like. Many other programs that pull text out of PDFs ignore it too.
So a permission is stored in the file, but it isn't a lock.
Does that make permissions useless?
No, but they do a different job from what people expect.
They are useful for telling software that follows the rules what you want. If you send a report to a client who opens everything in Acrobat, marking it as no-copy makes Acrobat refuse to copy from it. For that reader, it works.
They won't stop someone determined. Anyone who wants the text from a document they can already open will get it, permissions or not. They can use a different reader, run OCR on a screenshot, or retype it.
In practice: if it would be serious for the wrong person to read the document, rely on the open password. Treat permissions as a signal that someone can ignore.
Choosing the encryption
PDFs support several types of encryption, and the difference matters.
| Cipher | Verdict |
|---|---|
| AES-256 | The current standard, and the only one ISO 32000-2 recommends. Use this. |
| AES-128 | Still sound. Needed only for readers older than Acrobat 9 (2008). |
| RC4 128-bit | Long broken. Avoid. |
| RC4 40-bit | Broken decades ago. Trivially cracked. |
Some tools still produce RC4. A file encrypted with RC4 looks protected but isn't. If a tool doesn't tell you which type it used, be careful.
Protect PDF uses AES-256 by default and names the cipher on the result screen.
The owner password
There is a second, optional password. Its job is to lift the restrictions for whoever holds it, while the first password controls opening the file at all.
This matters more than it seems. If the owner password is set to the same value as the open password, everyone who can open the document can also remove its restrictions. Then the permissions do nothing.
Leaving the owner password blank is fine. The restrictions stay in place, with no second key that lifts them.
Choosing a good password
Encryption is only as strong as the password behind it. AES-256 with the password 1234 will barely slow anyone down.
- Length beats complexity.
harbour-mango-tuesday-lampis far stronger thanP@ssw0rd!and much easier to remember. - Do not reuse a password you use elsewhere. This file may be emailed onward, forwarded and stored in places you will never see.
- Send the password separately. If you email the PDF and the password in the same message, the password protects nothing. Send one by email and the other by phone or message.
- Write it down somewhere you trust. This is important, because of the next point.
There is no recovery
If you lose the password to an AES-256 encrypted PDF, the document is gone. Paying for recovery software won't bring it back. There is no master key, no back door, and no service that can help, ours included.
Put it in a password manager before you close the tab.
Removing protection later
If you have the password and want to remove it (the recipient asked for an unlocked copy, or the file is going into a system that can't handle encryption), Unlock PDF does that. You will need the password.
There is a second case that confuses a lot of people: a PDF that opens fine but won't let you print or copy. That file has permissions but no open password. There is no password to type, because none was ever set.
A note on what protection cannot do
Encryption protects the file while it is a file. It does nothing once the document is open on someone's screen. They can photograph it, screenshot it, read it aloud or print it and scan the paper.
That is true of every document format, not only PDF. Protection stops casual access and accidental forwarding. It can't hide anything from someone you chose to give access to.
Common questions
I blocked copying but I can still copy the text. Is it broken?
No. The restriction is written into the file correctly, and Acrobat will grey out Copy. But it is up to the reader to respect PDF permissions, and Chrome's viewer and many other programs ignore them. Only the open password is enforced.
Can you recover my password if I lose it?
No, and nor can anyone else. AES-256 has no back door. Store it in a password manager before you close the tab.
What is the owner password for?
It lifts the restrictions for whoever holds it, while the first password controls opening the file. Leave it blank and the restrictions stay in place.
Should I use AES-128 or AES-256?
AES-256, unless the file must open in a reader older than Acrobat 9. Never accept RC4. It is broken.