Skip to main content
Search titles, bodies, and author names
Found 13,169 posts across 1 forum.

Widget auto-install = huge security hole? — #36

Quote: Originally Posted by Jeff Mincey At present I cannot side with those who see this as a security issue. Software executes code and it can do things for the benefit of the …
MacNN Software by Mithras

Widget auto-install = huge security hole? — #37

Quote: Originally Posted by Jeff Mincey At present I cannot side with those who see this as a security issue. (snip) But that's not what is happening here and thus I see peo…
MacNN Software by chris v

Widget auto-install = huge security hole? — #38

User interaction to invoke the widget once installed is worth zero. 99% of Windows Outlook worms require the user to open the messages, which often have subjects like "I AM A V1RUS…
MacNN Software by eevyl

Widget auto-install = huge security hole? — #39

Just curious: Widgets are, on their most basic level, CSS/XHTML/Javascript. As long as the dashboard app only runs widgets that have that criteria, it seems like it's not as big …
MacNN Software by wtmcgee

Widget auto-install = huge security hole? — #40

Quote: Originally Posted by wtmcgee To me, it doesn't seem like it's as big a deal as some are making it out to be. Yes it is, however, from what I have read, fixing it see…
MacNN Software by Pierre B.

Widget auto-install = huge security hole? — #41

Quote: Originally Posted by wtmcgee Just curious: Widgets are, on their most basic level, CSS/XHTML/Javascript. As long as the dashboard app only runs widgets that have that c…
MacNN Software by Mithras

Widget auto-install = huge security hole? — #43

Here's what else they could do, and it's far worse than either openURL or openApplication: Quote: Originally Posted by Apple Developer Documentation system Executes a command-…
MacNN Software by CharlesS

Widget auto-install = huge security hole? — #44

Quote: Originally Posted by CharlesS This is almost the exact same thing as on Windows IE when you browse to a site and it decides it will install some custom toolbar or other s…
MacNN Software by Person Man

Widget auto-install = huge security hole? — #45

Quote: Originally Posted by Person Man Well, not exactly. It's not a "bitch to get rid of" a widget... It is if you're a novice user and don't know about ~/Library/Widgets. …
MacNN Software by CharlesS

Widget auto-install = huge security hole? — #46

Quote: Originally Posted by CharlesS Here's what else they could do, and it's far worse than either openURL or openApplication: So all a widget needs to do is widget.system("r…
MacNN Software by misc

Widget auto-install = huge security hole? — #47

Quote: Originally Posted by misc Doesn't running system commands require the "Are you sure?" agreed to? And what stops the widget from not displaying this and/or automatically a…
MacNN Software by CharlesS

Widget auto-install = huge security hole? — #48

Quote: Originally Posted by CharlesS 1. It's already been shown that a site can make a widget look just like one of the default Apple ones. 2. If a user isn't intimately famili…
MacNN Software by misc

Widget auto-install = huge security hole? — #49

Quote: Originally Posted by misc Right, I understand that. But by doing a 'rm -fr' command from within a widget, Dashboard will raise the red flag and say "You sure?" Right? …
MacNN Software by Mithras

Widget auto-install = huge security hole? — #50

Nope! Your " Calculator" widget did not ask me for any kind of confirmation at all. It just ran, said its nasty little message, and displayed "EVIL" on the screen. From the looks …
MacNN Software by CharlesS
mp.ls