View this article at: http://dev.macnn.com/articles/07/09/17/firm.issues.widget.warning
Monday, Sep 17, 2007 1:25pm
Security firm issues widget...
Web security firm Finjan today warned users that "widgets" and "gadgets" are posing serious security risks to computer, and that the small software add-ons should be treated just like full-sized applications. Finjan points to several security vulnerabilities which were repaired by various widget vendors after the firm discreetly offered information about those issues. While Apple is listed as one of the larger platforms supporting widgets, none of the listed security vulnerabilities reported so far afflict the Cupertino-based company's Mac OS X operating system. Finjan recommends refraining from using non-trusted third-party widgets or gadgets, and suggests exercising caution when using interactive widgets that rely on external sources like RSS feeds. Recent vulnerabilities were discovered in Windows Vista Contacts Widget, Live.com RSS reader, and Yahoo! Widgets Contacts. Finjan is actively warning users to expect an increase in attacks through unsecured widgets in the near future.