republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Tech and Talk » OS and Software » All Things Macintosh » Widget Security
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[X] Freeware DVD audio extractor / ripper for OS X? »
« Networking  
AuthorAll Replies


JJ
Beat It, Bill
Premium,MVM
join:2000-02-18
Madison, WI

reply to shavano
Re: Widget Security

The widget has to ask the user for permission to run the first time if it wants access to the system:

»developer.apple.com/documentatio···n_1.html


jDyno
Premium
join:2001-02-20
Washington, DC
clubs:

But it doesn't really tell you that it may be a security risk or that it accesses private system stuff. It just asks permission to run for the first time.

Also, no such warning exists when a widget needs Net access.

Yes, apps exist to monitor net traffic, and of course one is SUPPOSED to scan everything you put on your computer, but that's just not a practical security paradigm.

Even if everyone did have the discipline to check for security risks in every Widget (or any other thing they put on their machine), you can't expect everyone to have the knowledge to know what to look for. Hell, I'm a developer and I wouldn't be able to spot everything - probably even if I knew it was there.

And no, these do no more than any other Applescript could do, but Widgets and Automator actions will be used and downloaded many hundreds of thousand of more times than Applescript just by the very fact in how they are now more built-in adn accessible by the everyday user.

I am of the opinion that the security of Dashboard Widgets (and Automator actions) needs to be addressed by Apple ASAP.
--
Smart Marketing


shavano
Even in America -- I long for America

join:2003-06-08
Dallas, TX

said by jDyno See Profile:

But it doesn't really tell you that it may be a security risk

that's just not a practical security paradigm.

Even if everyone did have the discipline ... you can't expect everyone to have the knowledge to know what to look for.

I am of the opinion that the security of Dashboard Widgets (and Automator actions) needs to be addressed by Apple ASAP.
Exactly!

I just took a few minutes this morning to see what it might take for me to write my own. I saw the note on the Apple page about system commands and looked inside a couple of widgets.

My immediate reaction was "holy sh*t!!!!!".

Though not a professional developer, I'm reasonably competent at the Unix command line and have done some HTML and C programs. And I immediately knew they will easily be so complex there is no chance I would be able to tell if a widget was going to do something malicious.
--
Seek truth, not validation of existing beliefs.
Forums » Tech and Talk » OS and Software » All Things Macintosh[X] Freeware DVD audio extractor / ripper for OS X? »
« Networking  


Monday, 09-Nov 03:43:44 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [156] Cable Uncapper Faces Criminal Charges
· [140] AT&T Sues Verizon Over 3G Ads
· [112] Why Run Fiber When You Can Run Ads That Pretend You Do?
· [109] Comcast Is Simply Getting Huge
· [93] Apple Cooking Up New $30 A Month TV Service?
· [83] Bits Of ACTA Agreement Leaking Out
· [80] Will 'Three Strikes' Come To The United States?
· [78] Verizon To Double Smartphone ETFs?
· [77] Verizon: Droid Tethering Will Cost $30 Extra
· [73] Comcast, NBC Deal Almost Complete
Most people now reading
· Lots of problems lately? [Rogers]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [Rant] Brand New 'Jasper' Xbox360 - RRoD Hardware Failure [Rants, Raves, and Praise]
· [WIN7] Which Services in Win 7 Have You Turned Off? [Microsoft Help]
· Divorce advice... [General Questions]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· Security Software Updates - 09 Nov 2009 [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· [ Classes] ATTN Death Knights - Post your spec for critique! [World of Warcraft]