Password-protected PDFs and their limits
My PDF is protected and the tool says it cannot edit it. Why, and what are my options?
There are two different passwords
PDF encryption, defined in ISO 32000, distinguishes a user password from an owner password. The user password — often called the open password — is required to decrypt the document at all. Without it the content streams are ciphertext and no software can read a single page. The owner password is different: the document opens without it, but the encryption dictionary carries permission flags that say what a conforming viewer should refuse to allow, such as printing, copying text or modifying the file.
That distinction explains most of the confusion. A document that opens instantly but refuses to let you copy a paragraph is not "unlocked" — it is encrypted with an empty user password and a set of restrictions.
What the encryption actually protects
| Password | Needed to open? | What it protects | How strong is it |
|---|---|---|---|
| User (open) password | Yes | The content itself; streams and strings are encrypted | As strong as the cipher and the password chosen |
| Owner (permissions) password | No | Nothing cryptographically; it sets flags a viewer is asked to honour | Advisory only |
Permission flags are a request to well-behaved software, not an enforcement mechanism. The bytes are decrypted the moment the document opens, so any program that chooses to ignore the flags can do so. Treat them as a statement of intent — useful for signalling how a document should be used, useless as a security control.
Why an editor refuses the file
To restructure a PDF — to merge it, split it, rotate its pages, drop unused objects — a library has to parse the object graph. In an encrypted document, the strings and streams that make up that graph are ciphertext until the correct key is derived. There is nothing to parse. This is not a policy decision by the tool; there is genuinely no document there yet.
So FileSlimmer's structural PDF tools are disabled for an encrypted document, and say so, rather than failing halfway through with a corrupted output. That is the correct behaviour even though it is the less convenient one.
What happens to a password you type in
Where a password-assisted path is offered, the password is used to derive the decryption key in memory, in this browser tab, for as long as the task runs. It is not written to local storage, not written to the service-worker cache, not put in a URL, and not transmitted — there is no server in this application to transmit it to. When the tab closes, it is gone.
It is still worth being deliberate about where you type any password. A browser extension can read the contents of a page, and that is true of every website, including this one. If a document is sensitive enough that this matters, unlock it in offline desktop software you trust instead.
What this tool will not do
- It will not attempt to recover or brute-force a password you do not have.
- It will not strip an owner password to bypass permission flags on a document you have no rights to.
- It will not silently produce a decrypted copy of a document you opened with a password; removing protection is a separate, explicit action.
- It will not pretend a permission flag is a security boundary.
Removing protection from a document you are not entitled to modify may also breach a contract or a law where you live. That is a question for you and, if it matters, a lawyer — not for a compression tool.
Realistic options when you are stuck
- Ask whoever produced the document for an unprotected copy. This is by far the most common solution and it takes one message.
- If you have the open password, use it: with the document decrypted, every ordinary operation becomes available again.
- If you only need the pages to look at, print to PDF or export a rasterised copy. You lose the text layer, the links and the accessibility structure, and you keep the appearance.
- If the document is signed as well as encrypted, stop and reconsider. Any modification invalidates the signature, and a signed document usually exists precisely because someone needs to verify it later.
One more limitation
Older PDF encryption revisions used weak key derivation and short keys, and are considered broken. Newer revisions use AES with a proper derivation function. You cannot tell which one a document uses by looking at it, and a tool that opens an old file quickly is not evidence that a new file will behave the same way. If you are choosing protection for a document you are producing, choose current software and a long password rather than relying on the format's history.
Tools for this
Sources
- ISO 32000-2 — Document management, Portable Document Format
- Adobe — PDF 32000-1:2008, clause 7.6 on encryption and permissions
- NIST FIPS 197 — the Advanced Encryption Standard