Guides

PDF Passwords Explained: Open Passwords, Permissions and Real Encryption

PDF security confuses people for one specific reason: the format supports two different passwords, they look identical in most interfaces, and one of them provides real protection while the other is closer to a polite request.

Knowing which is which explains a lot — including why some "locked" PDFs can be unlocked instantly and others cannot be opened at all without the password.

The two passwords

The user password (also called the open password)

This is the one that does real work. With a user password set, the contents of the document are encrypted. A viewer cannot show you a single page until the correct password produces the key that decrypts the content streams.

Without the password there is nothing to see — not a blurred version, not a preview, just ciphertext. If you forget this password, the document is gone. That is not a limitation of any particular tool; it is what encryption means.

The owner password (also called the permissions password)

This one sets flags: no printing, no copying, no editing, no extracting pages. Your PDF reader reads those flags and greys out the corresponding buttons.

Here is the important part. The document is still encrypted, but the key needed to decrypt it is derived in a way that does not require the owner password — any conforming reader can open and decrypt the file without it. The restrictions work only because readers choose to honour them.

So a permissions-only PDF is protected by convention rather than by cryptography. Removing the restrictions is not "cracking" anything; it is rewriting the file without the flags. That is what Unlock PDF does, and why it is instant.

What this means in practice

  • Want a document that only certain people can read? Set a user password. Nothing else achieves that.
  • Want to stop people copying text or printing? A permissions password states your intention and stops casual copying in mainstream readers. It will not stop anyone who does not want to be stopped.
  • Assume that anything a reader can display, a reader can also export. A screenshot defeats a no-copy flag, and OCR turns the screenshot back into text.

None of which makes permissions useless — they signal intent, they prevent accidents, and in some workflows they are required. They are just not a security boundary.

The encryption underneath

PDF encryption has been revised several times, and the version used matters more than the password you choose.

  • RC4 40-bit. Original PDF encryption. Broken by brute force; treat any file using it as unprotected.
  • RC4 128-bit. Better, but RC4 itself is no longer considered sound and has been retired across the industry.
  • AES-128. Introduced with Acrobat 7-era PDFs. A modern, well-analysed block cipher, and supported essentially everywhere — which is why it is the practical default for a file that has to open on someone else's machine.
  • AES-256. Stronger key, defined in later revisions of the format. Worth using when you control both ends; slightly riskier when you do not, because older readers and some mobile apps cannot open it.

Protect PDF uses AES-128, which is the balance point between genuine strength and opening reliably on whatever the recipient happens to have.

The password is the weak part, not the cipher

Nobody attacks AES. They attack the password, by guessing, and the encryption key is derived from what you typed. So the entire security of the document rests on that choice.

Practical guidance:

  • Length beats complexity. Four or five unrelated words are stronger and far easier to communicate over the phone than P@ssw0rd!.
  • Do not reuse a password you use elsewhere. This one has to be shared with the recipient, which means it will end up in a message somewhere.
  • Send the password through a different channel than the file. A protected PDF and its password in the same email thread is one compromised mailbox away from no protection at all.
  • If the document matters, use a password manager to generate and store it.

Can a forgotten open password be recovered?

Honestly: no, other than by guessing it. There is no master key, no back door, and no support line. Services claiming to recover open passwords are running dictionary and brute-force attacks — which succeed against weak passwords and fail against decent ones. If you are the document's author, look for the original source file instead; recreating the PDF is usually faster than attacking it.

Permissions passwords are a different matter. Those restrictions can be removed from a file you already have, because the content was never sealed against you in the first place.

A note on the legitimate use of unlocking

Removing restrictions from a document you own or are entitled to use — a form you need to print, a report you need to extract a page from, a manual with copying disabled by a setting nobody meant to apply — is ordinary document work. Removing them to redistribute material you have no right to is not, and that is a question about the content, not the tool.

Where the work happens

Both operations involve handing over a password and a sensitive document at the same time. When they run in your browser, the file is decrypted or encrypted by JavaScript in your own tab, and the password never leaves the page — there is no request to inspect, because there is no request. For a task whose entire purpose is confidentiality, that is worth more than a privacy policy promising the same thing.

In short

A user password encrypts the document and cannot be bypassed. An owner password sets flags that readers voluntarily obey and can be removed in seconds. If you need real protection, set an open password, choose a long one, and send it separately from the file.

Questions about PDF passwords

A user password encrypts the document so it cannot be opened or read without it. An owner password only sets permission flags such as no printing or no copying, which readers choose to honour — the content itself can still be decrypted without that password.

Because they only carry a permissions password. The file is not sealed against the person holding it, so removing the restriction flags is a rewrite rather than an attack. A document with an open password cannot be handled this way.

Not by any means other than guessing it. There is no master key or back door, so recovery services simply run dictionary and brute-force attacks. If you created the document, rebuilding the PDF from the original source file is usually the faster route.

Yes. AES-128 is a modern, well-analysed cipher and is not the weak link — the password you choose is. It is also supported by essentially every reader, which matters when the file has to open on someone else's machine.

Only casually. Mainstream readers honour the flag, but anything that can be displayed can be captured, and text can be recovered from a screenshot with OCR. Treat permissions as a statement of intent rather than a security boundary.

Try it yourself

Free, no account, and your files never leave your device.

Protect PDF

← All posts