حماية PDF
شفّر ملف PDF بكلمة مرور وحدّد ما يُسمح للقارئات بفعله.
تعمل هذه الأداة داخل متصفحك بالكامل. لا يُرفع ملفك أبدًا، ويمكنك التحقق من ذلك في تبويب الشبكة بمتصفحك. تحقّق بنفسك: افتح تبويب الشبكة في متصفحك وراقب. سترى طلبًا صغيرًا واحدًا يسأل إن كان لديك مهام متبقية — اسم أداة وبصمة تجزئة، وليس الملف أبدًا.
ماذا تفعل هذه الأداة
Two different things are called protection, and a PDF offers both. A user password encrypts the file: without it the document cannot be opened by anyone, and that is real cryptography rather than a preference. The permission flags are not encryption at all - they record a request, such as do not print, that a well-behaved reader honours and any other reader may ignore.
Use the password before a document travels somewhere you do not control: a payslip going to a personal address, a contract sent to a counterparty, tax papers going to an adviser. Reach for the permission flags in the softer case, where a request is all you need and all you will get.
كيف تعمل
- Drop the PDF onto this page. A document that is already encrypted is refused rather than encrypted twice, because a doubly encrypted file is one no reader can open.
- Type the password people will need in order to open it. This is the field that actually encrypts; everything below it is weaker.
- Set a separate permissions password if opening the file and controlling it should be different privileges. Leave it empty and the open password is used for both.
- Choose the encryption strength, then set the toggles for printing, copying, editing, annotating and form filling.
- Press Protect PDF. The password is the only way back in, so keep it somewhere you will still have it next year.
The encryption is done by qpdf compiled to WebAssembly, running in a worker inside your browser. The password you type is used there to derive the file's key and is never transmitted - open the network tab, protect a document, and the one request you will find asks whether you have tasks left, carrying a tool name and a hash.
The two passwords do different jobs. The open password decrypts the file; the permissions password is what lets somebody lift the restrictions afterwards. qpdf needs a permissions password to set any restriction at all, so when only one box is filled in that password is used for both - one password that opens and fully controls the file.
Take the permission flags for what they are. Acrobat and most commercial readers honour them; plenty of free readers do not, and stripping them takes one pass through Unlock PDF and no password whatsoever. If a document genuinely must not be printed, the answer is not to send it.
AES 256-bit is the default because it is the strongest thing the format offers and every reader since roughly Acrobat 9 understands it. The 128-bit settings are compatibility choices for older software and are meaningfully weaker, RC4 especially. Whichever you pick, the length of your password matters more than the cipher, because the password is what gets guessed.
ما لا تستطيع هذه الأداة فعله
- The permission flags are advisory. The encryption is real, but do not print and do not copy are requests, and any reader is free to ignore them.
- A lost open password cannot be recovered, here or anywhere else. Nothing in the file remembers it.
- An already-encrypted PDF is refused rather than encrypted a second time. Remove the existing protection with Unlock PDF first.
- The 128-bit options exist for readers too old to understand AES and are not a serious defence. AES 256-bit is the only setting worth relying on.
أسئلة يطرحها الناس
- ما الفرق بين كلمة مرور الفتح وكلمة مرور الأذونات؟
- كلمة مرور الفتح تشفّر المستند: بدونها لا يمكن قراءة شيء. أما كلمة مرور الأذونات فلا تشفّر شيئًا - وهي ما يتيح لأحدهم رفع القيود لاحقًا. املأ كلمة مرور الفتح وحدها فتُستخدم للاثنتين؛ واملأهما معًا حين لا ينبغي أن يكون من يجوز له قراءة الملف هو نفسه من يجوز له رفع قيوده.
- هل يستطيع أحد طباعة ملف PDF أو نسخه رغم أنني منعت ذلك؟
- نعم، إن أراد. القيود رايات داخل الملف، واحترامها عُرف. فـ Acrobat ومعظم القارئات المدفوعة تلتزم؛ وعدة قارئات مجانية لا تلتزم، وأي أداة تزيل كلمة مرور المالك تجرّدها في ثانية.
- أي قوة تشفير ينبغي أن أختار؟
- AES 256 بت، إلا إذا كنت تعرف أن قارئًا قديمًا بعينه يجب أن يفتح الملف. وكل شيء من Acrobat 9 تقريبًا فصاعدًا يتعامل معه. أما خيارات 128 بت فهي لبرمجيات أقدم من ذلك، وRC4 له نقاط ضعف معروفة. وفي الحالتين كلمة مرور قصيرة تُبطل كل ذلك.
- نسيت كلمة المرور. هل يمكنكم استعادتها؟
- لا، وذلك عن قصد. لا يوجد باب خلفي في الصيغة، وCekPDF لا يخمّن كلمات المرور - فبناء أداة كسر داخل أداة خصوصية سيغيّر الغرض من هذا الموقع. وإن كان المستند يُفتح بلا كلمة مرور ويرفض الطباعة فحسب، فأداة فتح قفل PDF تصلح ذلك بدلًا من هذا.
- هل تُرسل كلمة المرور إلى أي مكان؟
- لا. يجري التشفير داخل متصفحك في Web Worker، وتُستخدم كلمة المرور هناك ثم تُطرح مع انتهاء المهمة. يمكنك التأكد بفتح تبويب الشبكة قبل الضغط على الزر. وبعد تحميل الصفحة مرة واحدة، تعمل الأداة والاتصال مقطوع.
- ماذا يفعل إذن قارئ الشاشة؟
- يتحكّم في ما إذا كان يجوز للبرمجيات المساعِدة استخراج النص لقراءته بصوت عالٍ، فإيقافه يجعل المستند غير صالح لأي شخص يعتمد على قارئ شاشة. وهو مفعّل افتراضيًا. وعند تشفير AES 256 بت لا تُحمَل هذه الراية إطلاقًا، لذا لا ينطبق الإعداد إلا عند قوة 128 بت.