Forums
New posts
Articles
Product Reviews
Policies
FAQ
Log in
Register
What's new
Search
Search
Search titles only
By:
New posts
Menu
Log in
Register
Install the app
Install
Forums
General Discussions
Switcher Hangout (Windows to Mac)
WARNING: Widgets can hijack your dashboard
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Reply to thread
Message
<blockquote data-quote="Thud" data-source="post: 109893"><p>This is not good....</p><p></p><p><a href="http://www.tuaw.com/2005/05/07/the-problem-with-widgets/" target="_blank">http://www.tuaw.com/2005/05/07/the-problem-with-widgets/</a></p><p></p><p></p><p>I haven't installed the "demo" widget. But here's the summary:</p><p></p><p>1) Widgets cannot be removed from the widget bar once they are installed (according to Apple's help files), unless you edit an XML file and reboot.</p><p></p><p>2) By default, widgets will auto-install automatically through safari, WITHOUT PROMPTING or asking for a password. The article shows how to disable this "feature."</p><p></p><p>3) Widgets can be made to use an obscene image as its icon, which will then take permanent residence in your widget bar, until you do some XML file editing (see #1)</p><p></p><p>4) A widget can be programmed to load a particular web page in the browser (which also closes the dashboard). This means that you effectively cannot open the dashboard (because it closes immediately) and thus you can't remove the offending widget from the dashboard, after the widget was installed automatically without your permission!</p><p></p><p></p><p>Well, as both a windows and mac user, I would like to welcome mac users to the wonderful world of spyware, and something that doesn't exist in the windows world -- <strong>Dashboard Hijackers</strong>.</p><p>The question is, will Apple fix this gaping security hole before somebody exploits it?</p></blockquote><p></p>
[QUOTE="Thud, post: 109893"] This is not good.... [url]http://www.tuaw.com/2005/05/07/the-problem-with-widgets/[/url] I haven't installed the "demo" widget. But here's the summary: 1) Widgets cannot be removed from the widget bar once they are installed (according to Apple's help files), unless you edit an XML file and reboot. 2) By default, widgets will auto-install automatically through safari, WITHOUT PROMPTING or asking for a password. The article shows how to disable this "feature." 3) Widgets can be made to use an obscene image as its icon, which will then take permanent residence in your widget bar, until you do some XML file editing (see #1) 4) A widget can be programmed to load a particular web page in the browser (which also closes the dashboard). This means that you effectively cannot open the dashboard (because it closes immediately) and thus you can't remove the offending widget from the dashboard, after the widget was installed automatically without your permission! Well, as both a windows and mac user, I would like to welcome mac users to the wonderful world of spyware, and something that doesn't exist in the windows world -- [b]Dashboard Hijackers[/b]. The question is, will Apple fix this gaping security hole before somebody exploits it? [/QUOTE]
Verification
Post reply
Forums
General Discussions
Switcher Hangout (Windows to Mac)
WARNING: Widgets can hijack your dashboard
Top