PDF Passwords Were Broken in 1998. Here Is How the Encryption Evolved Since Then.
When Adobe Systems released PDF 1.1 in 1993, it included a feature that would become one of the most contested aspects of the format for the next three decades: password protection. The first version used 40-bit RC4 encryption. By the standards of 1993, this was reasonable. By 1998, it was publicly broken. By 2009, it was considered trivially crackable. By 2016, the specification had moved to AES-256.
The history of PDF encryption is a compressed version of the broader history of applied cryptography: constant obsolescence, constant catch-up, and the enduring gap between what people believe their password protection provides and what it actually provides.
40-Bit RC4: The Export Law That Decided Your Security
RC4 was a stream cipher developed by Ron Rivest at RSA Security in 1987. PDF 1.1 adopted it for document encryption in 1993, using a 40-bit key. The key length was not chosen for security reasons. It was chosen because US export regulations at the time restricted the export of cryptographic software with keys longer than 40 bits. Adobe wanted to sell PDF software internationally, so they complied with the export limit.
The practical consequence was that PDF passwords in this era provided minimal security. A 40-bit key has approximately 1.1 trillion possible values, which sounds like a lot but became tractable for serious attacks relatively quickly as computing power grew. Academic papers in the late 1990s demonstrated brute-force attacks against 40-bit RC4 that could recover keys in hours or days on hardware available at the time.
Adobe responded in 1999, after US export regulations were relaxed, by updating PDF to support 128-bit RC4 encryption. PDF 1.4, released in 2001, standardized 128-bit RC4 as the default. This was a significant improvement: 128-bit keys have 2 to the power of 128 possible values, a number that makes brute-force attacks against the key itself computationally infeasible with any conceivable hardware.
But PDF's password encryption had a structural problem that went beyond key length. The encryption scheme was vulnerable to dictionary attacks because PDF's password hashing was fast. A fast hash means an attacker can test millions or billions of candidate passwords per second. If a user chose a weak password, the encryption's cryptographic strength was irrelevant because the password itself was the weak link.
The Upgrade to AES and What It Actually Changed
PDF 1.7 in 2006 introduced AES-128 as an option alongside RC4. AES, the Advanced Encryption Standard selected by the US National Institute of Standards and Technology after a public competition that concluded in 2001, was a more modern cipher than RC4 and is considered cryptographically strong. PDF 2.0, released in 2017, removed all RC4 options entirely and standardized AES-256 as the required encryption algorithm.
AES-256 with a strong password is cryptographically secure by current standards. The AES-256 cipher itself has no known practical weaknesses. A correctly implemented AES-256 encrypted PDF opened by brute-force would require testing 2 to the power of 256 possible keys, a number beyond the reach of any plausible computing system.
The important qualification is "with a strong password." PDF password protection, even with AES-256, is only as strong as the password chosen. A common short password can be found with a dictionary attack in seconds. A 12-character random password from the full ASCII printable character set is effectively unbreakable by brute force against a correctly implemented AES-256 scheme. The cryptography is not the vulnerability. The passwords humans choose are.
PDF encryption also comes in two flavors: user password, which controls opening the document, and owner password, which controls permissions like printing, copying, and editing without restricting opening. An owner password alone does not prevent the document from being opened. It only sets permission flags that compliant readers respect. Tools that ignore permission flags, including many open-source PDF libraries, bypass owner passwords entirely. Owner passwords are essentially a gentleman's agreement, not a security control.
What Modern PDF Password Protection Actually Provides
The version of PDF encryption you get when you password-protect a document today depends on which software creates it. Software that implements PDF 2.0, including Acrobat Reader versions from 2017 onward, will use AES-256. Older software may default to older algorithms. When you receive a password-protected PDF, the encryption header in the file identifies which algorithm was used, and PDF inspection tools can report this.
Browser-based PDF password protection tools create the encryption using JavaScript cryptography libraries that implement AES-256. The cryptographic operations happen in your browser on your device. The unencrypted PDF never leaves your machine before encryption is applied. This matters for confidential documents: a server-based tool that receives your PDF, encrypts it, and returns the encrypted version has access to the decrypted content during processing.
The practical guidance for PDF password protection is straightforward. Use it for documents that contain sensitive information and must be sent electronically. Choose a password that is long, random, and stored in a password manager rather than a word you will remember. Understand that password protection controls access to the document content; it does not hide that the document exists or that it is encrypted. And for documents where the information is truly sensitive, consider whether email attachment is the appropriate delivery mechanism at all, rather than relying solely on password protection.
Conclusion
PDF password protection has evolved from 40-bit encryption restricted by export laws to AES-256 standardized by a global cryptographic competition. The standard is strong. The passwords people choose often are not.
The PDF Password Protect tool at ToolHQ applies AES encryption in your browser. Your document is encrypted before anything leaves your device, and the unencrypted content is never sent to any server.
Frequently Asked Questions
What encryption does PDF password protection use today?
PDF 2.0 (2017) standardized AES-256. Older software may use AES-128 or RC4. AES-256 with a strong password is cryptographically secure by current standards.
Can PDF passwords be cracked?
The cipher itself cannot be brute-forced practically. Weak passwords can be found via dictionary attacks in seconds. The password strength determines the real-world security level.
What is the difference between user and owner passwords in PDF?
User passwords control opening. Owner passwords control permissions like printing and copying. Owner passwords alone don't prevent opening and are bypassed by most PDF tools.
Is it safe to use an online tool to password-protect a PDF?
Only if the encryption happens in your browser before the file is sent anywhere. Browser-based tools encrypt locally; server-based tools see your unencrypted content.
Try These Free Tools
PDF Merger
Merge multiple PDF files into a single document online. Reorder pages and combine PDFs easily.
PDF Splitter
Split a PDF into individual pages or extract specific page ranges. Free online PDF splitter.
PDF to Word Converter
Convert PDF files to editable Word documents (DOCX) online for free. Preserve formatting and layout.