When the video recording stops being evidence
The statutory framework for remote notarisation was built when a recorded video of a person holding their identification was strong evidence. That assumption is aging faster than the statutes.
Is a RON recording still good evidence?
Weakening, for a specific reason. A recording proves a session was captured. Whether what was captured was a person in front of a camera is a separate question, and injected video arrives through the same media stack a real camera uses.
- RON statutes generally require credential analysis, knowledge-based authentication and a recorded session. Each was strong when written.
- A recording establishes that a session took place, not that the person in it was who they appeared to be.
- A hardware signature over the document hash gives the notary an artefact that does not depend on the video's evidentiary strength.
Part of Title, escrow and closing wires
What the statutes require
State frameworks differ in detail and converge on a common set.
| Requirement | What it establishes | Current strength |
|---|---|---|
| Credential analysis | The presented identity document appears genuine | Moderate — synthetic documents are improving |
| Knowledge-based authentication | The signer knows facts about the identity | Weak — answers are in breach data |
| Live audio-video session | A person appeared and interacted | Weakening |
| Recording retention | An artefact exists for later review | Depends on the recording's evidentiary value |
The second row has been weak for years and is generally acknowledged as such. The third is the one that changed recently, and the frameworks have not caught up.
Why a recording is weaker than it looks
A recorded session is evidence that something was captured. Whether what was captured was a person in front of a camera is a separate question, and the video does not answer it.
- Injected video presents synthetic frames through a virtual camera, so the platform captures them as a live feed
- Real-time synthesis handles the interaction the notary uses to test liveness
- The recording preserves the synthetic content faithfully — it is an accurate record of a fabricated session
A reviewer watching the recording months later sees what the notary saw. If the notary was deceived, the recording preserves the deception rather than revealing it.
Where this matters most
Not every notarised document is worth attacking. Two categories are.
- Instruments affecting title. Deeds and mortgage documents transfer or encumber property. A forged instrument recorded in the public record creates a problem that takes years and litigation to unwind.
- Powers of attorney. A notarised power of attorney is a general-purpose authority instrument. Its value to an attacker is larger than any single transaction.
In both cases the notarisation is the control that the rest of the system relies on. Recording offices, title underwriters and counterparties accept a notarised instrument largely on the strength of the acknowledgement.
Adding an artefact that does not depend on video
# Alongside the RON session, not replacing it
Document: Deed of Trust, 1420 Fillmore Street
Hash: sha256:9c1f8a3e...d7b2
Signer: [name as it appears on the instrument]
Notary: [commission number, jurisdiction]
Session: RON-2026-0447, recorded
Signer authenticates with a credential enrolled at least
N days earlier, on hardware, with user verification.
→ signature over the document hash
→ notary countersigns
→ both travel with the instrument
The enrolment delay in the middle is doing real work. A credential enrolled during the session proves nothing about who enrolled it; one enrolled weeks earlier through a separate process gives the attacker a second problem to solve, at a different time, through a different channel.
What this changes and what it does not
| Question | Recording alone | Recording plus signature |
|---|---|---|
| Did a session occur? | Yes | Yes |
| Was the document the one discussed? | Inferred | Bound by hash |
| Did a specific enrolled credential authorise it? | No | Yes |
| Was the human behind the credential the named person? | Not established | Not established |
The last row is the honest limit and it is important. A signature proves control of an enrolled credential. Binding that credential to a real identified human is an enrolment problem that neither video nor cryptography solves on its own.
What changes is that the attack must defeat enrolment as well as the session, and enrolment happened at a different time through a different channel. Requiring two separate compromises is meaningfully harder than requiring one.
The regulatory position
Nothing in existing frameworks prevents adding a signature alongside the statutory requirements. A notary who performs credential analysis, knowledge-based authentication and a recorded session, and additionally obtains a hardware signature over the document hash, has exceeded the requirement.
Whether frameworks will eventually require it is a separate question and probably a slow one. In the meantime, a notary or title underwriter who wants a stronger artefact can have one without waiting for statute.
This describes regulatory structures at a general level and is not legal advice. Notarisation requirements are state-specific and change; take specifics to counsel.
Where this matters most
| Instrument | Why |
|---|---|
| Deeds and mortgage documents | A forged instrument in the public record takes years to unwind |
| Powers of attorney | A general-purpose authority instrument, worth more than any single transaction |
In both cases the notarisation is the control everything downstream relies on — recording offices, title underwriters and counterparties accept the instrument largely on the acknowledgement.
Objections and honest limits
“Credential analysis and knowledge-based authentication still apply.” They do. Knowledge-based answers have been in breach compilations for years and synthetic documents are improving. The session recording was the strongest remaining leg.
“A signature does not prove identity either.” Correct, and worth stating: it proves control of an enrolled credential. What it adds is that the attacker must also defeat enrolment, at a different time through a different channel.
This describes regulatory structures at a general level and is not legal advice. Notarisation requirements are state-specific and change.
Strengthening a RON act
- Require a credential enrolled days earlier. So enrolment is a second, separate obstacle.
- Bind the document hash into the signature. So the act covers this instrument.
- Have the notary countersign. Commission number inside the signed statement.
- Keep both with the instrument. It outlives the platform.
Terms used here
- RON
- Remote online notarization, conducted over audio-video with credential analysis and knowledge-based authentication.
- Credential analysis
- Automated examination of an identity document for authenticity indicators.
- Injection attack
- Feeding synthetic video into the capture path so the platform records it as a live feed.
Frequently asked questions
Do RON recordings have no value? They establish that a session occurred and preserve what the notary saw. They do not establish that the person on camera was who they appeared to be.
Why require the credential to be enrolled earlier? A credential enrolled during the session proves nothing about who enrolled it. Prior enrolment forces the attacker to defeat a second, separate process.
Does a signature prove identity? No. It proves control of an enrolled credential with user verification. Binding that credential to a named human is an enrolment problem.
Is adding a signature permitted under current statutes? Nothing prevents exceeding statutory requirements. This is general description rather than legal advice, and notarisation rules are state-specific.
Why require prior enrolment? A credential enrolled during the session proves nothing about who enrolled it. Prior enrolment forces a second, separate compromise.
Is adding a signature permitted? Nothing prevents exceeding statutory requirements. Rules are state-specific; take specifics to counsel.
Where this fits in Manav
Manav pairs the RON session with a hardware signature over the document hash, from a credential enrolled earlier through a separate process — so an attacker must defeat two things at two different times.
Sources and further reading
- Uniform Law Commission — Revised Uniform Law on Notarial Acts
- Published research on injection attacks against video identity verification.
- Land records and recording office requirements for acknowledged instruments.
- NIST — presentation attack detection evaluations