"Password-protected" sounds like one thing. It is actually two, and they offer very different levels of protection. Knowing which you have applied matters, because one genuinely secures a document and the other is closer to a polite request.
The two kinds of PDF password
The open password
Also called a user password. Without it, the file cannot be opened at all. The document's contents are encrypted — on disk it is unreadable noise, and the password is what derives the key to decrypt it. No password, no document.
This is real protection. Someone who obtains the file without the password has an encrypted blob and nothing else.
The permissions password
Also called an owner password. The document opens freely for anyone, but carries flags saying things like "do not allow printing" or "do not allow copying text".
Which one do you want?
Almost always the open password. If a document is sensitive enough to warrant protection, it is sensitive enough that you want it genuinely unreadable without the password rather than merely inconvenient to print.
Permissions passwords make sense for a narrow case: distributing something you want people to read but would prefer they did not casually reproduce — a sample chapter, a proof, a licensed template. Just be clear that a determined reader is not stopped.
What encryption does and does not cover
An open password protects the file's contents. It does not hide:
- The filename. Calling it redundancy-list-final.pdf tells the story before anyone opens it.
- The file's existence or size. Anyone holding it knows it is there.
- Anything after it is opened. Once a legitimate recipient decrypts it, they can screenshot, forward or print it. Encryption controls access, not what happens next.
Choosing a password, and getting it to the recipient
The encryption is only as strong as the password. A four-digit number can be brute-forced almost instantly. Use a long passphrase — several unrelated words are both stronger and easier to pass along verbally than a short string of symbols.
If you have forgotten the password
For a genuinely encrypted PDF with a strong password, there is no recovery. That is what encryption means, and any service claiming otherwise is either guessing common passwords or exploiting weak, outdated encryption.
A permissions password is different, because the content was never encrypted — the restrictions can simply be removed. Our tool includes an unlock mode for exactly this: reopening a document whose restrictions you set and no longer want.
Only remove protection from documents you have the right to access.
When a password is the wrong tool
Passwords control who can open a document. They do nothing about what is inside it. If the concern is a few specific details — a name, an account number, an address — the better answer is often to remove that information entirely and share an unprotected file. Nobody then needs a password, and nothing sensitive is present to leak.
Note that a black rectangle drawn over text does not remove it. Proper redaction deletes the underlying content; drawing a box merely covers it, and the text stays selectable underneath.
Common questions
Can a password-protected PDF be cracked?
With a strong, long password and modern encryption, not in any practical sense. With a short or obvious one, yes — brute force works quickly against weak passwords. The password is the weak point, not the encryption.
Will the password work on every device?
Yes. Password protection is part of the PDF standard, so any compliant reader on any platform will prompt for it.
Can I protect only certain pages?
No — encryption applies to the whole document. If only part is sensitive, split the file and protect that portion separately.
Does protecting a PDF change its size?
Barely. Encryption adds a little overhead but does not meaningfully change the file size.