Privacy and security

What a PDF password actually protects

What does a PDF password actually protect?

Short answer

It depends entirely on which of the two passwords you set. A user password encrypts the file: without it the content cannot be read at all. An owner password encrypts nothing — it sets permission flags that ask readers to disallow printing or copying, and a reader is free to ignore them. Most people who think they have protected a document have set the second kind.

The two passwords are not two strengths of the same thing

The user password — real encryption

Also called the open password. Set one and the document’s streams are encrypted; the bytes on disk are ciphertext. No reader can show the content without the password, because the content is not there to show. This is genuine protection, and its strength is the strength of the password and the cipher.

123

Two passwords that do different jobs

  1. The open password. Without it the file cannot be read at all — the contents are encrypted.
  2. The permissions password. The file opens for anyone; it is printing, copying and editing that are marked as not allowed.
  3. Both can sit on one document, and they are not the same protection. Only the first keeps anybody out.

The owner password — a request, not a lock

Also called the permissions password. The file is readable by anyone. Inside it is a set of flags saying what a reader should allow: print, copy text, extract for accessibility, modify, annotate. Compliant readers honour them. Nothing enforces this. The flags are advisory, the content is not encrypted against the reader, and any tool that chooses not to consult the flags simply does not.

This is not a flaw somebody should fix — it is what the format says. A permissions flag is a note to well-behaved software, and it should be treated as exactly that much protection.

What permissions are, and are not, good for

Permission flags are worth setting for what they genuinely do: they state your intent, and they stop the accidental case. A colleague who was not going to copy your text anyway is now also prevented from doing it without noticing. A print shop gets a clear signal about what you meant.

They are worthless against anyone who does not want to comply, and it is important to be plain about that: removing them requires no cracking, no guessing and no special knowledge. They are a sign, not a lock.

So: use them to communicate. Do not use them to protect anything whose exposure would actually matter.

Encryption strength, and what it does not cover

Modern PDFs use AES, most commonly with a 256-bit key, which is not the weak point. The weak point is the password, because the key is derived from it. A short or common password can be attacked offline at whatever speed the attacker’s hardware allows, and the file gives no resistance — an attacker holds the whole document and can test guesses forever without anyone knowing. Older files using 40-bit or RC4 encryption should be treated as unprotected.

Two limits of PDF encryption are worth stating explicitly, because they are commonly assumed away:

  • Encryption is not redaction. Encrypting a document with a black box drawn over a paragraph protects the whole file from people without the password — and gives the paragraph away completely to everyone with it, because a drawn rectangle does not delete the text underneath. That is a different job: see how to redact a PDF permanently and redact PDF.
  • Encryption does not remove metadata. Author names, the producing software, timestamps and revision history are inside the file, protected only as much as the rest of it — and once someone has the password they have all of it. Remove PDF metadata is the tool for that, and what PDF metadata contains explains what is in there.

Choosing the right tool for the actual problem

  • Nobody unauthorised may read this. Set a user password with protect PDF, make it long, and send it by a different channel than the file. A password emailed alongside the document it protects has protected nothing.
  • This must not contain a particular piece of information. That is redaction, not a password. Remove the content.
  • I want people to read it but not reuse it. Permission flags state the intent; they will not stop anyone. If reuse genuinely matters, do not distribute the document.
  • I have the password and want to stop typing it. Unlock PDF removes the protection from a file you can already open. It is not a recovery tool: it needs the password, and a password you do not have cannot be removed.

One practical note on how this site handles it. Protect and unlock are server-processed, because the cryptography involved is not something to run in a browser tab — the file is sent over an encrypted connection, held only while it is being processed, and deleted afterwards. The password you type is forwarded to perform the operation and is never logged, stored or shown in any error.

Tools this article covers

Sources

Primary documentation for the claims above.

Last reviewed: September 24, 2026

Published by iBuildPDF.

More from the knowledge base

Browse the knowledge base