Is PDF password protection actually secure?
Some PDF protection is mathematically sound and some is a suggestion, and the lock icon in your reader does not tell you which.
The short answer
PDF password protection is secure when the file has a user (open) password, uses AES encryption, and the password is long and not guessable. An owner password on its own is not security at all: the content is readable by any software that chooses to ignore the restrictions. Old files using 40-bit RC4 can be opened regardless of the password.
So the honest answer is three answers, depending on which kind of protection you are looking at.
Owner passwords are a request, not a lock
The difference between the two PDF passwords is covered in detail elsewhere, so here is only the part that matters for security. A file with an owner password but no user password opens for anyone. Technically it is still encrypted, but the key is derived from an empty user password, which every reader already knows. That is how it opens without a prompt.
The restrictions on printing, copying and editing are a set of permission bits stored next to the encryption settings. A compliant reader checks them and greys out the buttons. Nothing enforces that. Any program that decrypts the file, which is every program that can display it, has the content in memory and can do what it likes with it. Removing those restrictions needs no password at all.
Owner passwords are fine for signalling intent, like discouraging casual copying of a published report. They are not a way to keep anyone out.
User passwords plus AES are real encryption
A user password changes things fundamentally. The key that decrypts the content is derived from the password itself, so without the password there is no key, and without the key the page content is just noise. No reader can show it, and no setting can switch the protection off.
PDF has gone through several encryption schemes, recorded as revisions of the standard security handler, and they are not equally strong.
- Revision 2: RC4 with a 40-bit key. The key space is small enough to search exhaustively, so these files can be opened whatever the password was. Treat them as unprotected.
- Revisions 3 and 4: RC4 or AES with keys up to 128 bits, derived from the password with MD5. The cipher holds up in practice, but RC4 has known weaknesses and should be avoided for anything new.
- Revision 5: AES-256, checked with a single SHA-256 hash of the password. The encryption is strong but each password guess is cheap to test.
- Revision 6: AES-256 with a deliberately expensive hashing loop, so every guess costs far more. This is the current scheme.
The password is the weak point
Once the cipher is AES, nobody attacks the encryption. They attack the password, by trying candidates until one produces the right key. Every revision from 3 onwards is strong enough that this is the only practical route in.
That makes password choice the entire question. A date of birth has around 36,000 possibilities across a century, which a laptop can try in moments. A customer number printed on the letter that came with the file is not a secret. An eight-character password of lowercase letters can be exhausted. Four or five unrelated random words, or a long random string from a password manager, puts the number of guesses out of reach even against the cheaper revision 5 check.
The other half is delivery. A strong password sent in the same email as the file protects nothing from anyone who can read that email. Send it by a different channel: a text message, a phone call, a password manager share.
What encryption does not hide
PDF encryption covers strings and streams, which is where page content, images and text live. It does not encrypt the file's structure. Someone without the password can still see how many pages the document has, their dimensions, and roughly how large each one is.
Metadata may be readable too. Newer revisions allow a file to be encrypted with its metadata left in the clear, so a title or author field can sit in plain text alongside encrypted pages. The file name is never protected, so do not put the sensitive part in it.
Making and checking a protected file
To protect a file properly, set a user password, not just permissions. World of PDF's Encrypt PDF applies AES-256 using revision 5 of the security handler and sets the same password for opening and for permissions, so the file genuinely cannot be opened without it. Because it renders each page to an image before encrypting, the output text is not selectable. Given the revision 5 check, a long password matters even more there.
To check an existing file, look at the document properties or security panel in a desktop reader, which usually names the encryption method. If it says 40-bit RC4, or if the file opens without a prompt, it is not protecting the content. To remove protection from a file you can open, the Remove Password tool decrypts RC4, AES-128 and AES-256 files in your browser using the password you already have.
Frequently asked questions
Can a password-protected PDF be hacked?
A file with only an owner password, or with 40-bit RC4 encryption, can be opened easily. A file with a user password and AES encryption can only be opened by guessing the password, so a long random one makes it impractical.
Is AES-256 PDF encryption secure?
The cipher is. The weak point is the password, because anyone without it has to guess. A short or predictable password undoes the strength of the encryption.
Can someone remove PDF permissions without the password?
Yes. Permission restrictions are flags that readers choose to honour. The content is decryptable without the owner password, so the restrictions can be stripped.
Is a date of birth a safe PDF password?
No. There are only tens of thousands of possible dates, and they can all be tried quickly. Banks use them for convenience, not security.
Does PDF encryption hide the number of pages?
No. Encryption covers page content and text, not the file structure, so page count and page sizes remain visible without the password.