Gadgets and Personal Data

User-generated gadgets made personalized homepages a better place because users can choose from a wider variety of content and even create their own gadget if they have programming skills. But just because you see a gadget in Google's directory or elsewhere doesn't mean you have to trust it and handover personal information or credentials.

Jason wrote a popular gadget that showed your MySpace alerts. Of course, the gadget required you to enter your MySpace username and password (ideally, MySpace should have an API for authentication and data).

"A few months back, a flaw was discovered whereby usernames were being passed in clear-text as a querystring parameter when using the gadget. As a result of Google's mechanism that caches web-content, a list of usernames on a phishing watchlist website was cached in Google's search index, thus making them publicly accessible. Once Google was alerted of the issue, they contacted me immediately. Google took action and removed the cached content from their search index, and I took numerous steps to strengthen the security of the gadget - and to mitigate any future risks. Google even went as far as to work with the operators of the phishing watchlist to remove my name and IP addresses from the suspected phishers list."

But people thought that the flaw was intentional and accused him of phishing. "Due to a common misconception that the Gadget was actually being used to facilitate phishing activity, I have decided to remove it permanently. This is a particularly difficult decision because of the large number of users and the popularity of this gadget."

Google shows a warning everytime you add third-party gadgets, so you should be careful when you add gadgets from unknown sources. You should be even more careful when you enter personal data.

Labels

Web Search Gmail Google Docs Mobile YouTube Google Maps Google Chrome User interface Tips iGoogle Social Google Reader Traffic Making Devices cpp programming Ads Image Search Google Calendar tips dan trik Google Video Google Translate web programming Picasa Web Albums Blogger Google News Google Earth Yahoo Android Google Talk Google Plus Greasemonkey Security software download info Firefox extensions Google Toolbar Software OneBox Google Apps Google Suggest SEO Traffic tips Book Search API Acquisitions InOut Visualization Web Design Method for Getting Ultimate Traffic Webmasters Google Desktop How to Blogging Music Nostalgia orkut Google Chrome OS Google Contacts Google Notebook SQL programming Google Local Make Money Windows Live GDrive Google Gears April Fools Day Google Analytics Google Co-op visual basic Knowledge java programming Google Checkout Google Instant Google Bookmarks Google Phone Google Trends Web History mp3 download Easter Egg Google Profiles Blog Search Google Buzz Google Services Site Map for Ur Site game download games trick Google Pack Spam cerita hidup Picasa Product's Marketing Universal Search FeedBurner Google Groups Month in review Twitter Traffic AJAX Search Google Dictionary Google Sites Google Update Page Creator Game Google Finance Google Goggles Google Music file download Annoyances Froogle Google Base Google Latitude Google Voice Google Wave Google Health Google Scholar PlusBox SearchMash teknologi unik video download windows Facebook Traffic Social Media Marketing Yahoo Pipes Google Play Google Promos Google TV SketchUp WEB Domain WWW World Wide Service chord Improve Adsence Earning jurnalistik sistem operasi AdWords Traffic App Designing Tips and Tricks WEB Hosting linux How to Get Hosting Linux Kernel WEB Errors Writing Content award business communication ubuntu unik