Two kinds of “protected”, and only one needs a password
A user password encrypts the document. Without it a reader has ciphertext and shows nothing: no pages, no text, no thumbnails. This is what most people mean by a locked PDF.
An owner password leaves the content readable and restricts what a reader is willing to do with it: printing, copying, editing, assembling pages. It’s a set of flags, and it needs no password to open the file at all.
What happens to your password
The key derivation runs here, in JavaScript, following the standard security handler in ISO 32000: MD5, RC4 and AES-CBC. The password goes into that computation in memory and isn’t stored, logged or sent anywhere. There’s no request to make, so the network panel stays empty for the whole operation and you can watch it.
- RC4-40: the 1993 scheme. Still turns up in old exports.
- RC4-128: the long-standing default through the 2000s.
- AES-128: the Acrobat 7 generation.
- AES-256: Acrobat X and later, and what most modern tools produce.
Why the file has to stay on your machine
A file you can’t open is, by definition, one you don’t fully control: a client’s invoice, a payslip, a statement, a contract someone else wrote. The password is half of the secret protecting it.
Sending that file and that password to a site you found an hour ago is the one step that turns “inconvenient” into “disclosed”. Whoever runs the service holds both halves, and you have their word for what happens next.
It won’t crack anything
There’s no guessing here and no bypass. If the document has a user password and you don’t know it, the tool tells you and stops. Ciphertext doesn’t have a shortcut.
What you get back
A new file with no encryption and no restriction flags. Pages, text layer and layout are what they were. Because nothing is protected any more, store it and send it deliberately.
