It’s 11:30 p.m. Do you know what your widget is doing?

April 16th, 2008

by Al Merkrebs, April 16, 2008 @ 11:37 a.m. PDT

widget In SightWidget security is a topic that seems to lurk in the background, not getting much attention. One example of this is the huge RSA Security Conference held last week in San Francisco. It did not have ANY panels on widget security.

MacWorld article on widget security said,
“Widgets are owned by the user, and can do anything that a user can do. For instance, they can remove files from your home directory without asking permission. They can run anything from the command line that a user can. They can call any AppleScript that a user can.”

Yesterday, one of the W3C drafts on widgets stated that, “When compared to Web browsers, some market-leading widget user agents have a comparatively relaxed security model that allows an instantiated widget to read, write, modify, and/or delete files, automatically upload files, automatically download files, execute local applications, and even perform cross-domain request to “mash-up” data from multiple different sources. All without the end-user having any indication that their privacy and security might be at risk.” (Bold formatting is mine.)

So how does a typical user address this problem? Most of us look the other way and just click the “Install Widget” button. We are often told to only download software from sources that we trust. Well, who ARE you supposed to trust, and WHY?

I would very much like to hear your comments on and experiences with this issue. I’ll be writing more on this subject.

Entry Filed under: widget in sight

Leave a Comment

Required

Required, hidden

Some HTML allowed:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Trackback this post  |  Subscribe to the comments via RSS Feed



 RSS    Email 

Android This Week: Froyo for EVO; Top 5 Widgets - GigaOm (blog)

BlackBerry 6 Changes App Development Too - Softpedia

Widgets Odyssey II Launching Next Week, Exclusively for the PlayStation Mini ... - IGN

Apple updates Safari 5 - Telegraph.co.uk

Web 2.0 Security Means Fighting Malicious Third-Party Content - eWeek

Droid Incredible gets Android 2.2 Froyo leak, too - IntoMobile (blog)

Wolfram Alpha rolls out widget platform - V3.co.uk

INGEAR Instrumentation Widgets for PDA Enhances User Interface - The Open Press (press release)

Wolfram Alpha Launches Widget Builder Beta - PC Magazine

Wolfram does widgets - Inquirer

Battlefield Heroes PTE - NEW Widgets, Outfits and Emotes

Introducing HTC Desire

Beautiful Widgets 3.0 on Droid Eris

Mytouch slide psx4droid gameplay and multimedia

How to add a banner ad to your widget sidebar in Wordpress

Nexus One Transparent Widgets Review.wmv

Battlefield Heroes - New Savage Sly Outfits and Widgets

Battlefiedl Heroes New outfits, widgets and emotes on PTE.

BFHeroes PTE: New Items Testing! (Nationals)

Battlefield Heroes PTE New Things #1

BFHeroes PTE: New Items Testing! (Royals)

Samsung Galaxy S - The Carphone Warehouse - eye openers

Samsung UN55C8000 55-Inch 1080p 240 Hz 3D LED HDTV

Comment ajouter des Widgets sur Mac.

iPod Touch Nexus One Theme Tutorial and More

Making the Case for a Microsoft Phone - PC World

HTC EVO 4G Android 2.2 Update Details, Download Now - Android Community (blog)

Apple updates Safari 5 - Telegraph.co.uk

Big File Desktop Send Widget Released by Ricoh Visual Online Storage Service ... - MarketWatch (press release)

App-makers fully geared up for Boris's cycle scheme - The Guardian

Web 2.0 Security Means Fighting Malicious Third-Party Content - eWeek

Wolfram Alpha rolls out widget platform - V3.co.uk

Droid Incredible gets Android 2.2 Froyo leak, too - IntoMobile (blog)

Metastorm M3 Demonstration - Enterprise Irregulars (blog)

Wolfram Alpha Launches Widget Builder Beta - PC Magazine


Widget-related Events
July 2010
M T W T F S S
28 29 30 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31 1
2 3 4 5 6 7 8

Search for jobs with this widget:

Get this widget!
Job search





widgetBeat™ is dedicated to bringing you timely widget news and widget reviews, written by industry professionals. Think of us as
THE place for all things widget.

Your comments are most welcome.

View Al Merkrebs' profile on LinkedIn

Follow Al Merkrebs' on Twitter

Internet Blogs - BlogCatalog Blog Directory


Loading...

Calling all widgets...

If you would like widgetBeat™ to consider reviewing your widget, please e-mail us at tips@widgetbeat.net