How to Password-Protect a PDF (and What PDF Passwords Can and Can't Do)
Putting a password on a PDF is the simplest way to send a payslip, contract, medical letter or bank statement without anyone else being able to read it. It works well when the password is strong and shared sensibly. It does much less than many people assume when it comes to stopping printing or copying. Here is how PDF passwords work, how to choose one that holds up, and how to add one in a couple of minutes.
Two different PDF passwords
A PDF can have two passwords, and they do very different jobs.
- The open password (called the user password in the PDF standard) encrypts the document. Without it, the pages can't be displayed at all. This is the one that protects privacy.
- The permissions password (the owner password) controls limits such as no printing, no copying text and no editing. Someone who opens the file with the open password still sees everything; the limits only change what their software lets them do next.
The PDF Association, the industry body behind the PDF standards, describes the pair this way: an owner password sets "controls on what information others can alter", while user passwords "allow anyone with those passwords to open the document." It also notes that "The latest ISO 32000 default for this is 256-bit AES encryption." When PDF 2.0 was published in 2017 it added 256-bit AES while deprecating all shorter bit lengths, so AES-256 is the one to use.
What a PDF password can't do
- Limits are a request, not a lock. To show a page, a reader has to decrypt it, and it is up to the software to honour "no printing" or "no copying". Most readers do, but not all, and a PDF that has limits but no open password can have them removed without any password at all.
- It can't control what happens after opening. Anyone with the password can print to a new PDF, take screenshots, or forward the file along with the password.
- It can't be taken back. There is no expiry date and no way to revoke access to a copy you have already sent.
- It doesn't hide the file name, or the subject and text of the email it is attached to. Name the file and write the message with that in mind.
- It can't make up for a weak password. Whoever has the file can try guesses on their own computer, as fast as it will go, with no lockout after ten wrong attempts.
Choosing a password that holds up
That last point is why the password matters more than the encryption setting. To show the scale, imagine an attacker who can test one billion guesses a second. That figure is an illustration, not a measurement; real speeds depend on the hardware and the file. Here is how long trying every possibility would take:
| Password | Possibilities | Time to try them all |
|---|---|---|
| A date of birth from the last 100 years | About 36,500 | Instant |
| Any 6-digit number | 1,000,000 | A thousandth of a second |
| 8 random lowercase letters | About 209 billion | About 3.5 minutes |
| 4 random words from a 7,776-word list | About 3.7 × 10¹⁵ | About 6 weeks |
| 5 random words from the same list | About 2.8 × 10¹⁹ | About 900 years |
| 12 random characters (letters, digits, symbols) | About 8 × 10²² | About 2.5 million years |
The 12-character row uses the 81 characters our Password Generator picks from when all four boxes are ticked: 26 capitals, 26 small letters, 10 digits and 19 symbols. You can check any row yourself: for 8 lowercase letters, 26⁸ (26 multiplied by itself 8 times) is 208,827,064,576, and dividing by a billion gives about 209 seconds.
Two good ways to get a strong one:
- Random words. The UK's National Cyber Security Centre recommends three random words for everyday accounts. For a file that can be attacked offline, use more: four or five genuinely random words, not a phrase or a quotation.
- A generated password. Use the Password Generator with a length of 16 or more; its default of 20 is fine. The US standards body NIST, in its digital identity guidelines, sets a minimum of 15 characters for a password that is the only thing protecting an account.
Never build it from a date of birth, phone number, employee number or the recipient's name. Our guide to creating a strong password covers this in more depth.
Share it separately. Send the file by email and the password by phone call, text message or in person, never in the same email. For documents you send regularly, agree a password once in person and store it in a password manager.
How to password-protect a PDF with our tools
- Open PDF Protect and click Browse to choose your PDF. If it already has a password or restrictions, type its current password in Current password of this PDF so it can be protected again.
- Type your password in New password and again in Type it again. A strength rating (Weak, OK or Strong) appears as you type, and Show passwords lets you check for typos. The minimum is 4 characters, but aim for far more.
- If you want limits, open Limits and encryption (optional) and tick Block printing, Block copying text or Block editing. Type a Permissions password (optional) if you want to lift them yourself later; if you leave it empty, a random one is used. It must be different from the open password.
- Leave Encryption on AES-256 (recommended). Choose AES-128 only if the recipient has a very old PDF reader that can't open the file.
- Click Protect PDF, then Download protected PDF. Open the new file once to check the password works before you send it.
The file is encrypted in your browser and never uploaded. PDF Protect always sets an open password, so it can't make a file that only has limits, which is the weak kind of protection anyway.
Changing or removing a password
To change a password, run the file through PDF Protect again: it asks for the current password, then applies the new one. To remove protection from a file you own or are allowed to change, use our PDF password remover. Type the password if the PDF asks for one to open, or leave the box empty if it only blocks printing or copying, then download the copy without a password. Text, links and bookmarks are kept; only a PDF with an unusual type of protection comes back as pictures of the pages, with a Picture quality (only if needed) choice for that case.
Our tools can't guess or recover a forgotten open password, and with a strong password nobody else realistically can either. That is the point of the encryption, so keep the password somewhere safe, such as a password manager.
Common mistakes
- Sending the password in the same email as the file.
- Using a date of birth, phone number or ID number as the password.
- Relying on "no copying" or "no printing" to protect confidential content.
- Putting sensitive details in the file name or the email subject.
- Losing the password: without it, the file can't be opened.
- Choosing AES-128 when AES-256 would work.
Sources
Spotted a mistake or something out of date? Tell us and we'll fix it.