Security
How to password-protect a PDF — and what it really protects
Add an open password and the file is genuinely encrypted — nothing can read it without that password. The separate permission settings, like blocking copying, are requests that only some readers honour.
There is a gap between what people think PDF protection does and what it actually does, and almost every disappointing experience with it comes from that gap. So it is worth being precise, because one half of PDF security is genuinely strong and the other half is best described as a polite request.
Two completely different things
PDF security is really two mechanisms that happen to live in the same dialog.
The open password (encryption). The file's contents are encrypted with a key derived from your password. Without it there is nothing to read — not scrambled text, but ciphertext. No reader, no tool and no website can display the document. This is real cryptography and it works.
Permissions. A set of flags recorded inside the file saying what a reader *should* allow: printing, copying, editing, commenting, form filling, rearranging pages. These are not enforced by encryption. They are enforced by the goodwill of whatever program opens the file.
Confusing the two is what leads someone to block copying, open the file in Chrome, select the text, and conclude the tool is broken.
What honestly happens with each
Take a PDF, set an open password, and block copying. Then try to get the text out.
Without the password: nothing works. Not a PDF reader, not a command-line tool, not a library. The file cannot be opened at all. This is worth stating plainly because it is the part that genuinely protects you.
With the password: Adobe Acrobat and Reader grey out Copy and Select All. Foxit and most desktop readers do the same. Chrome's built-in PDF viewer ignores the flag entirely and lets you select whatever you like. Text-extraction libraries ignore it too.
So a permission is a real thing recorded in a real place — it simply is not a lock.
Does that make permissions useless?
No, but it makes them a different tool than people assume.
They are useful for communicating intent to cooperative software. If you send a report to a client who opens everything in Acrobat, marking it as no-copy makes Acrobat refuse to copy from it. That is a genuine, working outcome for that reader.
They are not useful for stopping someone determined. Anyone who wants the text from a document they can already open will get it, permissions or not — by using a different reader, by running OCR on a screenshot, or by retyping it.
The practical rule: if the consequence of the wrong person reading the document is serious, the open password is the part to rely on. Treat permissions as a signal, not a defence.
Choosing the encryption
Modern PDFs support several ciphers, and the difference matters.
| Cipher | Verdict |
|---|---|
| AES-256 | The current standard, and the only one ISO 32000-2 recommends. Use this. |
| AES-128 | Still sound. Needed only for readers older than Acrobat 9 (2008). |
| RC4 128-bit | Long broken. Avoid. |
| RC4 40-bit | Broken decades ago. Trivially cracked. |
The awkward part is that some tools still quietly produce RC4, because the library they use only supports it. A file encrypted with RC4 looks protected and is not. If a tool does not tell you which cipher it used, that is worth a moment's suspicion.
Protect PDF uses AES-256 by default and names the cipher on the result screen.
The owner password
There is a second, optional password. Its job is to lift the restrictions for whoever holds it, while the first password controls opening the file at all.
The distinction matters more than it first appears. If a tool sets the owner password to the same value as the open password — some do, quietly — then everyone who can open the document can also strip its restrictions. The permissions become decorative.
Leaving the owner password blank is fine. It means the restrictions simply stand, with no second key that lifts them.
Choosing a password that is worth having
Encryption is only as good as what it is derived from. AES-256 with the password 1234 is not protection; it is a speed bump.
- Length beats complexity.
harbour-mango-tuesday-lampis far stronger thanP@ssw0rd!and much easier to remember. - Do not reuse a password you use elsewhere. This file may be emailed onward, forwarded and stored in places you will never see.
- Send the password separately. Emailing the PDF and the password in the same message defeats the exercise entirely. Send one by email and the other by phone or message.
- Write it down somewhere you trust. Which leads to the important part.
There is no recovery
If you lose the password to an AES-256 encrypted PDF, the document is gone. Not "gone unless you pay for recovery software" — gone. There is no master key, no back door, and no service that can help, ours included. Anyone claiming otherwise for a modern encrypted file is not being straight with you.
Put it in a password manager before you close the tab.
Removing protection later
If you have the password and want to remove it — the recipient asked for an unlocked copy, or the file is going into a system that cannot handle encryption — Unlock PDF does that, and you will need the password.
There is also a second case worth knowing about, because it confuses people constantly: a PDF that opens perfectly well but refuses to let you print or copy. That file has permissions but no open password. There is no password to type, and a tool that demands one for it is asking for something that never existed.
A note on what protection cannot do
Encryption protects the file while it is a file. It does nothing once the document is open on someone's screen. They can photograph it, screenshot it, read it aloud or print it and scan the paper.
That is not a flaw in PDF; it is true of every document format. Protection reduces casual access and accidental forwarding. It does not make information un-seeable by someone you have deliberately given access to.
Common questions
I blocked copying but I can still copy the text. Is it broken?
No. The restriction is correctly written into the file — Acrobat will grey out Copy. But PDF permissions are honoured by the reader, not enforced by encryption, and Chrome's viewer and most libraries ignore them. Only the open password is enforced.
Can you recover my password if I lose it?
No, and nor can anyone else. AES-256 has no back door. Store it in a password manager before you close the tab.
What is the owner password for?
It lifts the restrictions for whoever holds it, while the first password controls opening the file. Leave it blank and the restrictions simply stand.
Should I use AES-128 or AES-256?
AES-256 unless the file must open in a reader older than Acrobat 9. Never accept RC4 — it is broken.