Whenever we move a process online, there is a temptation to describe the physical steps we eliminated. No travel. No paper. No physical meeting. No waiting room. Fine. The more interesting question is what replaced them. Remote notarization is a good example. A traditional in-person notarization has a very obvious trust model. There is a human being physically in front of another human being. Identification is presented.

The notary can directly observe the signer. The act occurs in a physical place. That doesn’t make fraud impossible. It makes the security assumptions relatively easy to understand. Move the interaction online and those assumptions change. We haven’t eliminated trust. We’ve moved it into technology. Now the system may depend on identity-proofing services. Credential analysis. Communications security. Video. Audio. Electronic journals. Recordings. Authentication. Platform access controls.
Electronic signatures. Electronic seals. Network connectivity. Storage. Retention. And, depending on the system and jurisdiction, other controls intended to establish confidence that the remote person is who they claim to be. This isn’t inherently less secure. But it is differently secure. That distinction matters. Engineers call this changing the attack surface. The old process has vulnerabilities. The new process has vulnerabilities. They aren’t necessarily the same vulnerabilities.
For example, physical distance stops mattering nearly as much online. That’s wonderful for legitimate users. It is also wonderful for attackers. An attacker no longer necessarily needs to be physically close to the victim, notary or property involved. At the same time, a well-designed remote platform can create records that simply don’t exist in a traditional physical encounter. Technology can strengthen some controls while weakening or replacing others.
This is why I dislike arguments about whether “online” is inherently safer or inherently more dangerous. Those statements are too broad to be useful. Show me the architecture. How is identity established? What happens when a credential fails validation? What does the notary see? What gets recorded? How is that record protected? Who can retrieve it? How are credentials secured? How are sessions authenticated? What happens if an account is compromised?
What happens when video freezes? What happens when the technology is uncertain? And increasingly: What happens when the face on the screen isn’t necessarily a reliable representation of a real person? Generative AI makes that last question particularly important. For most of the history of video communications, seeing and hearing someone live was powerful evidence that you were interacting with that person. That assumption is becoming weaker.
We need security models that acknowledge that. The answer can’t simply be “use AI to detect AI.” That may become one layer. It should not become the entire foundation. Again: defense in depth. Independent evidence. Credential validation. Identity proofing. Behavioral and transaction signals. Strong platform security. A trained human notary. Appropriate records. Controls that fail safely. This is the same lesson that appears throughout cybersecurity.
Never ask one control to be perfect. Assume every control has failure modes and build the system so that an attacker has to defeat several of them. Remote notarization is going to continue evolving because the underlying value proposition is obvious. Distance is expensive. Scheduling is difficult. People increasingly expect services to be available digitally. But convenience doesn’t eliminate the need for trust. It makes trust architecture more important.
The interesting future isn’t paper versus digital or physical versus remote. It’s designing systems where we can explain, clearly and precisely, why we believe the person on the other end is really the person they claim to be. That’s the actual product. Everything else is implementation.
Discover more from Christine Alifrangis
Subscribe to get the latest posts sent to your email.