All tools run in your browser — your files never leave your device.
All tools154

PDF

Real encryption, fake locks, and forgotten passwords

A PDF can carry two entirely different passwords. One is genuine encryption; the other is a note asking software to behave.

The short answer. A PDF user password encrypts the file and is required to open it — with modern AES-256 that is real cryptography, and a forgotten one is not recoverable. An owner password only sets permission flags on an otherwise unencrypted file, so any tool that ignores them can, which is why some PDFs appear to unlock instantly. Word uses AES encryption, and a forgotten Word password is likewise unrecoverable.

The two PDF passwords

The two PDF passwords
User passwordOwner password
Also calledOpen passwordPermissions password
What it doesEncrypts the fileSets restriction flags
Needed to openYesNo
Real encryptionYes, AES-256 in modern PDFsThe file is not encrypted
Enforced byMathematicsReaders that choose to comply
If forgottenEffectively unrecoverableIrrelevant — it opens anyway

This table explains the whole subject. A file with only an owner password opens in any reader without a password; the restrictions on printing or copying are flags that cooperating software honours voluntarily. A file with a user password cannot be read at all without it.

Why some PDFs "unlock in seconds"

Because there was nothing to break. Removing an owner password is not cryptanalysis — the file was never encrypted, and the restriction is a boolean the software agreed to respect.

That is worth understanding rather than relying on. If you set an owner password expecting it to stop copying or printing, it will stop an honest user in Acrobat and nobody else.

A user password is a different matter entirely. Modern PDFs use AES-256, and with a reasonable password there is no shortcut — recovery means guessing, which for anything other than a short or common password is not a realistic prospect. Services promising to remove any PDF password are describing the owner-password case, whether or not they say so.

When you have forgotten your own

This is the situation the question usually comes from, and the honest answer is that the options are limited and none of them is a tool.

Work through the possibilities in order rather than reaching for software.

  1. Check where the file came from. Bank and government PDFs commonly use a formulaic password — a date of birth, a postcode, the last digits of an account. The covering email usually says.
  2. Ask the sender to re-issue it, unencrypted or with a password you know. Almost always the fastest route.
  3. Check your password manager and any note attached to the file.
  4. If you created it, look for the source document and re-export.
  5. If it is only an owner password, the file opens already — you are looking at a permissions restriction, not a lock.

If none of those applies and the file has a genuine user password, it is gone. That is not a limitation of the available tools; it is what encryption is for, and a format where a forgotten password could be recovered would be a format where the encryption did nothing.

Protecting a Word document

Word offers several things under the heading of protection, and only one of them is encryption.

Encrypt with Password — File → Info → Protect Document → Encrypt with Password — applies AES encryption to the file. Modern versions use AES-256. This is real, and a forgotten password means the document is unrecoverable.

  • Restrict Editing — permission flags, not encryption. Comparable to a PDF owner password.
  • Mark as Final — a status flag and nothing more. Dismissible with one click.
  • Read-only recommended — a suggestion the user can decline.
  • Encrypt with Password — the only option here that is actual security.

The distinction matters when a document is being sent outside the organisation. Restrict Editing prevents accidental changes by colleagues acting in good faith, which is a real and useful thing. It does not protect a confidential document from anyone who wants to read or alter it.

Sending the password

An encrypted file emailed with its password in the same message is not protected. Both are in the same inbox, the same mail server logs and the same backup.

Use a different channel — text the password, or say it on the phone. This is the single most common way document encryption is undone, and it takes ten seconds to avoid.

Generate the password rather than inventing it, since the encryption is only as strong as what you chose. Password Generator produces one locally in the browser, which is the appropriate place for something that will never be transmitted.

Handling other people's documents

Some occupations receive highly sensitive documents as a matter of routine. Estate agency is a clear example: a single transaction can involve identity documents, bank statements, proof of funds, mortgage paperwork and financial details for several parties at once.

Professional duties of confidentiality in these fields typically continue after the transaction ends and after the relationship ends. Data protection obligations apply independently and in parallel — under GDPR and equivalent regimes, holding this material makes you responsible for it regardless of any professional code.

  • Do not email unencrypted identity or financial documents. Use a secure portal, or encrypt and send the password separately.
  • Collect only what is needed, and delete it when the purpose is served. Retained data is retained risk.
  • Redact properly. A white box over an account number removes nothing — the text is still in the file.
  • Check metadata before forwarding a document someone else prepared.
  • Use tools that work locally for compressing or splitting client files, so they are not uploaded to a third party.
  • Know your breach obligations before you need them. GDPR sets a 72-hour notification window.

The redaction point recurs because it keeps causing real disclosures. Covering text with a shape leaves it fully recoverable by copy and paste, and it has exposed bank details and identity documents in exactly this kind of transaction.

Frequently asked questions

What is the difference between a user and an owner password on a PDF?

A user password encrypts the file and is required to open it — real cryptography, AES-256 in modern PDFs. An owner password only sets permission flags on an unencrypted file, restricting printing or copying for readers that choose to comply. The file opens without it.

Why can some PDF passwords be removed instantly?

Because those files were never encrypted. Removing an owner password is not breaking anything — the restriction is a flag that software honours voluntarily. Services offering to remove any PDF password are describing this case.

I have forgotten the password to my own PDF. What can I do?

Check whether the sender uses a formulaic password, as banks and government bodies often do, and ask them to re-issue the file — that is usually fastest. Check your password manager, and look for the source document if you created it. If it has a genuine user password and none of that helps, it is not recoverable.

How do I password protect a Word document?

File → Info → Protect Document → Encrypt with Password, which applies AES encryption. Restrict Editing and Mark as Final are permission flags rather than encryption and offer no protection against anyone determined to read or change the document.

Is Word's Restrict Editing secure?

No. It prevents accidental changes by colleagues acting in good faith, which is genuinely useful, but it is not encryption and does not protect a confidential document. Only Encrypt with Password does that.

How should I send someone an encrypted file?

Send the password by a different channel — text or phone. A file and its password in the same email share an inbox, a mail server log and a backup, which undoes the encryption entirely.

What should professionals handling client documents do differently?

Avoid emailing identity and financial documents unencrypted, collect only what is needed and delete it afterwards, redact by removing content rather than covering it, check metadata before forwarding, use locally-processing tools for client files, and know your breach notification obligations in advance.

Stop reading, start doing

Every tool in this guide is free.

154 browser-based utilities. No account, no upload, and no file size limit — your files are processed on your own device and never sent anywhere.

Browse all 154 tools