start.com, live.com and security?
In the last few days I started to explore start.com and live.com, the two quite new WEB 2.0 sites of Microsoft. As usual Microsoft is not the first, but tries to get the most out of new ideas, in this case the WEB 2.0 movement (unification of desktop and the web). Of course there are some earlier developments (YAHOO gadgets, google desktop). But my impression is that Microsoft wants to get the highest degree of integration of the into their operating system (Windows Vista).
After having some success developing my first small sample gadgets I got the irresistible feeling that again security issues a the big point against live.com. Don’t missunderstnd myself, I like the great variety of possibilities, the richness of the bindings an the simple integration into the well known and (in)famous world of DHTML, but let’s see:
One of the first thing you have to do if ou want to develop something is to weaken the client side security levels for connection to live.com and start.com (see for example the explanations on the developer pages for start.com). Both must be added as trusted sites in the configurations for the IE6 and even worse the unsaint Access data sources across domains feature should be enabled. I wait for the first gadget attacks using this security flaw !!
Am I to pessimistic? I hope so, because I would enjoy to support WEB 2.0 and I am sure Microsoft, Yahoo and Google are the key player in this new game. But please don’t make the same mistakes as in the first DHTML era….





