I have two issues and follow up questions…
I tend to be quite wordy, I will try not to be and aplogize in advance if I am.
I have researched quite a bit (this forum, security redbooks on R5 and R6) and cannot find a couple answers. Your help would be appreciated.
We have been a notes shop since R3. We are just testing our understanding of security (currenly on R6.0.1 - previously on R4.6, skipped over R5).
ISSUE #1: It used to be in 4.6 that a laptop user, opening there local client, could eventially open up client without entering the userid password, by "esc"ing past error messages. This was a potential security problem in the case the laptop was stolen - some data could be accessed (depending on ACL, etc)
Now in R6 with the new password entry box, I have tried every which way to open the client without a password and I cannot.
QUESTION #1: Is this a true statement, did a change occur to make the client more secure, and if so, can you point me to any documentation specifying this change?
ISSUE #2: In database properties, under encryption settins, if you select “Do not locally encrypt…” the help text in that window states: “This database can be opened without a user ID if someone gains physical access to this computer… if the database is on a laptop that is lost, anyone who finds the computer can open the database without the password to your user ID” - I have found similar statments in User Security, on R6 Technical Papers, etc…
If my ISSUE #1 is TRUE, then the Lotus statement in ISSUE #2 is FALSE.
It seems to me the statement should actually state that ‘anyone finding the laptop, who can gain access to ANY notes ID and password, can open the client, thus gaining access to local databases that are not encrypted AND ACL is not enforced’
QUESTION #2: How can a user without an ID or password, get to data, encrypted or not? Please help in clarifying this.
Thank you all for your input.