Thursday, July 8, 2010

Lotus knows how to ask you to bypass security (or does it?)

Steve Riley recently pointed out some horrendous concern for customer security in a post about Priceline. Here's an example I saw today in the Lotus Sametime product. I use many collaboration tools but it's been a while since I used Sametime so it asked me run through an installation. As you can see in the screenshot below, it says "Answer YES if you receive any security warnings or Sametime will not function properly".

Highly dubious as this advice is, it actually fails because the Java Runtime identifies a problem with the signature of the Sametime application and by clicking "Yes" on the security dialog below, the Sametime meeting room client is blocked from running:



Lotus Sametime is not the only product which actively asks you to ignore security concerns. But it's the only one I've seen where the advice to bypass security actually causes the product not to install. To paraphrase Wolfgang Pauli, the advice is "So insecure it's not even wrong".