Skip to main content
Search titles, bodies, and author names
Found 13,982 posts across 1 forum.

Widget auto-install = huge security hole? — #29

Quote: Originally Posted by chris v At the very least, like the guy says on the page I linked to, clicking one "evil" widget could send a browser into pemanent pr0n spazms. This…
MacNN Software by Mithras

Widget auto-install = huge security hole? — #30

This is really a regrettable, inexcusable vulnerability. I know OS X is a complex project, but you would think someone in management or QA would take charge and put 2+2 together be…
MacNN Software by Big Mac

Widget auto-install = huge security hole? — #31

Just this morning I was thinking about this: would a widget that, for example, scans one's mails (using Spotlight... why not) for username/password combinations, and then occasiona…
MacNN Software by workerbee

Widget auto-install = huge security hole? — #32

I'm wondering why we all did not see this coming before. I don't mean to come off as an alarmist, but the type of scenario workerbee is describing is within the realm of possibilit…
MacNN Software by Big Mac

Widget auto-install = huge security hole? — #33

At present I cannot side with those who see this as a security issue. Software executes code and it can do things for the benefit of the user running it or it can do destructive th…
MacNN Software by Jeff Mincey

Widget auto-install = huge security hole? — #34

Quote: Originally Posted by workerbee Just this morning I was thinking about this: would a widget that, for example, scans one's mails (using Spotlight... why not) for username/…
MacNN Software by Mithras

Widget auto-install = huge security hole? — #35

As an addendum to my previous post, I will go so far as to say Safari's definition of "safe" files should exclude widgets or any other executable code -- I have no problem with tha…
MacNN Software by Jeff Mincey

Widget auto-install = huge security hole? — #36

Quote: Originally Posted by Jeff Mincey At present I cannot side with those who see this as a security issue. Software executes code and it can do things for the benefit of the …
MacNN Software by Mithras

Widget auto-install = huge security hole? — #37

Quote: Originally Posted by Jeff Mincey At present I cannot side with those who see this as a security issue. (snip) But that's not what is happening here and thus I see peo…
MacNN Software by chris v

Widget auto-install = huge security hole? — #38

User interaction to invoke the widget once installed is worth zero. 99% of Windows Outlook worms require the user to open the messages, which often have subjects like "I AM A V1RUS…
MacNN Software by eevyl

Widget auto-install = huge security hole? — #39

Just curious: Widgets are, on their most basic level, CSS/XHTML/Javascript. As long as the dashboard app only runs widgets that have that criteria, it seems like it's not as big …
MacNN Software by wtmcgee

Widget auto-install = huge security hole? — #40

Quote: Originally Posted by wtmcgee To me, it doesn't seem like it's as big a deal as some are making it out to be. Yes it is, however, from what I have read, fixing it see…
MacNN Software by Pierre B.

Widget auto-install = huge security hole? — #41

Quote: Originally Posted by wtmcgee Just curious: Widgets are, on their most basic level, CSS/XHTML/Javascript. As long as the dashboard app only runs widgets that have that c…
MacNN Software by Mithras

Widget auto-install = huge security hole? — #43

Here's what else they could do, and it's far worse than either openURL or openApplication: Quote: Originally Posted by Apple Developer Documentation system Executes a command-…
MacNN Software by CharlesS

Widget auto-install = huge security hole? — #44

Quote: Originally Posted by CharlesS This is almost the exact same thing as on Windows IE when you browse to a site and it decides it will install some custom toolbar or other s…
MacNN Software by Person Man

Widget auto-install = huge security hole? — #45

Quote: Originally Posted by Person Man Well, not exactly. It's not a "bitch to get rid of" a widget... It is if you're a novice user and don't know about ~/Library/Widgets. …
MacNN Software by CharlesS

Widget auto-install = huge security hole? — #46

Quote: Originally Posted by CharlesS Here's what else they could do, and it's far worse than either openURL or openApplication: So all a widget needs to do is widget.system("r…
MacNN Software by misc

Widget auto-install = huge security hole? — #47

Quote: Originally Posted by misc Doesn't running system commands require the "Are you sure?" agreed to? And what stops the widget from not displaying this and/or automatically a…
MacNN Software by CharlesS

Widget auto-install = huge security hole? — #48

Quote: Originally Posted by CharlesS 1. It's already been shown that a site can make a widget look just like one of the default Apple ones. 2. If a user isn't intimately famili…
MacNN Software by misc

Widget auto-install = huge security hole? — #49

Quote: Originally Posted by misc Right, I understand that. But by doing a 'rm -fr' command from within a widget, Dashboard will raise the red flag and say "You sure?" Right? …
MacNN Software by Mithras

Widget auto-install = huge security hole? — #50

Nope! Your " Calculator" widget did not ask me for any kind of confirmation at all. It just ran, said its nasty little message, and displayed "EVIL" on the screen. From the looks …
MacNN Software by CharlesS
mp.ls