What PDF password protection really does
A protected PDF is not locked in the sense that a ZIP with a password is locked. The PDF standard defines a security handler, and the file stores the encrypted content together with the parameters needed to derive a decryption key from the password.
When a reader opens the file it applies the password, derives the key, and decrypts the pages in memory. Without the password, a reader cannot even render the first page — which is why a properly encrypted PDF is genuinely unreadable rather than merely hidden.
There are two passwords in the standard. The user password is what a reader asks for and what allows someone to open and read the document. The owner password controls permissions: it is what you would give your own software to unlock printing or editing while everyone else is restricted. If you only set one, both roles are filled by the same password, which is fine for personal documents.
Choosing an encryption strength without overthinking it
RC4-128 is the oldest of the three and the most widely supported. Every PDF reader made in the last twenty-five years handles it, including very old versions of Adobe Reader, ancient government portal viewers and specialised printing software. It is technically weaker than AES but remains far beyond practical attack for a well-chosen password.
AES-128 is the sensible modern default. It is strong, it has been supported by Adobe Reader since version 7 in 2005, and it opens in Chrome, Edge, Firefox, Safari, all mobile PDF apps and virtually every PDF library.
AES-256 is the strongest option and the current recommendation of the PDF 2.0 standard. Support is nearly universal in software released in the last decade, but some older tools and a few legacy government viewers still cannot open it.
The practical recommendation: AES-128 for anything you are sending to another person or an organisation, AES-256 for storage and archival of your own files, and RC4-128 only if you have already hit a compatibility problem.
What makes a PDF password actually strong
All three algorithms are vulnerable to the same thing: a guessable password. Encryption limits how many attempts an attacker can make per second, but it does not stop a dictionary attack against “123456” or your date of birth.
Length matters more than complexity. A five-word passphrase is far stronger than an eight-character string of symbols, and much easier to remember. “indigoTractorMorning42” is both stronger and simpler than “P@ss!23”.
Avoid: your name, your date of birth, your phone number, the document’s own subject (“salary”, “aadhaar”), the current year, and anything reused from another account. If you reuse a password that has appeared in a breach, and the attacker knows that, the encryption is irrelevant.
Store the password in a password manager, and keep a note somewhere you would find it if you needed the file in ten years. There is no recovery mechanism — a protected PDF cannot be opened without its password, by us or by anyone else. That is the point of the feature, and it is also its only real risk.
Permissions versus protection
The permission checkboxes — allow printing, allow copying, allow editing — are properties of the owner password. They are honoured by well-behaved PDF software, and ignored by software that chooses to ignore them.
Treat them as clear instructions to legitimate users rather than an unbreakable technical control. A document marked “printing not allowed” will not print from Adobe Reader, but a determined person with different tools will not be stopped by the flag.
The user password, by contrast, is real: without it the pages cannot be decrypted at all. That is the part that protects a confidential document. Use permissions to communicate intent; rely on the password and, where you need more, on simply not sharing the file.
For a layered approach: password-protect the document, watermark it with the recipient’s name, and compress it so it is small enough to transmit efficiently. All three take under a minute together, and all three run in this browser.