zzen said:I just made a widget which creates and deletes files on your hard drive. Is that damaging enough, or do you want me to do more?!!
I want more. Let's see your widget. Post a download link.
zzen said:I just made a widget which creates and deletes files on your hard drive. Is that damaging enough, or do you want me to do more?!!
Peace said:Not gonna flame ya but even windoze users know not to give out admin passwords to anyone other than the administrator.Thats why it's called administrator.Thats also why there is user switching.Each user should have their own accounts with the admin account used to administrate the puter.
.
peterjhill said:step 1. turn off automatically open "safe files" in Safari General prefs.
.
Agreed. I know this is entirely possible with dashboard's current configuration - he is not joking... (No helpful warnings either)Applespider said:Let's not have the download link. If it does exist, the fewer places it's referenced to the better to stop the script kiddies joining in
csubear said:Thats to problem! How can you be careful of things that are auto downloaded! And then auto installed!
VanNess said:So far, I haven't seen any evidence to date that shows any widget could do any sort of harm to your system, i.e., take it over, erase your hard drive, and so on. Might get one that displays adds, but its easy to get rid of it
But for the seriously neurotic, here's a permanent solution you can apply right now:
1) In the Finder, navigate to your home folder, open the Library folder, and find the folder titled "Widgets" All non-Apple widgets are installed and live in this folder.
2) Click the folder to select it.
3) Control click the folder to bring up the contextual menu.
4) Select "Enable folder actions"
5) Control click the folder again and select "attach a folder action..."
6) From the file menu that appears, choose "add - new item alert.scrpt"
That's it, your done. The next time a widget is whisked into the widget folder, you will see the following alert:
https://forums.macrumors.com/attachment.php?attachmentid=23666&stc=1
Clicking yes will take you directly to the widget folder with the nefarious widget naked and highlighted for your send to trash convenience, if you so desire.
admanimal said:I think for most of us, a simple "Do you want to install this widget" prompt from Dashboard would be good enough. Probably not for the less careful user though.
gorkonapple said:Also, Widgets are Javascript are they not?? Javascript does not even have the ability to execute outside of the sandbox. Anyway, I pass this article off as FUD.
skythefly13 said:Just download widgets from Apple.com and you'll be fine? They wouldn't post anything that could harm your computer? At least I hope not...
fatfish said:The d/l issue can be turned off in safari and I'm sure an update will soon address this issue anyway. The auto install is exactly what is supposed to happen and on it's own isn't particularly an issue. After all install in this sense means moved to one single non system folder which by now 90% of users know about anyway.
.
Sharewaredemon said:90 percent of users who know about their computers, but to the many computer illiterate mac users. They wouldn't know where the library folder is.
spakers said:Why don't you make a folder action that moves the widget out of the ~library/Widgets, library/Widgets folder until the user is prompted for permission? Thats what i did![]()
Sharewaredemon said:90 percent of users who know about their computers, but to the many computer illiterate mac users. They wouldn't know where the library folder is.
fatfish said:I'm sure they do.
The majority of widgets come as zips, unstuff to your desktop and have to be manually installed. Most users will have encountered this and know exactly where thier library folder is, even if they didn't 14 days ago.
fatfish said:I'm sure they do.
The majority of widgets come as zips, unstuff to your desktop and have to be manually installed. Most users will have encountered this and know exactly where thier library folder is, even if they didn't 14 days ago.
swissmann said:It would be nice if people who found the holes would quietly let Apple know about them instead of showing everyone else how to do it. Are they trying to help or hurt?