<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Wesabe&#039;s Mac Dashboard Widget</title>
	<atom:link href="http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/</link>
	<description>The Wesabe blog</description>
	<lastBuildDate>Sat, 31 Jul 2010 18:27:05 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Sam Quigley</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4218</link>
		<dc:creator>Sam Quigley</dc:creator>
		<pubDate>Tue, 05 Feb 2008 01:26:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4218</guid>
		<description>Nat--

I work in the Security group here at Wesabe, and I just thought I&#039;d point out
that the fact that the login keychain is often unlocked does *not* mean that
any application has access to its contents. The Mac Keychain only allows
&quot;trusted applications&quot; to access individual keychain entries: unless users
specifically grant access to the &quot;Wesabe Widget&quot; keychain item to other
programs, the only application that can read it will be the &quot;DashboardClient&quot;.[1]

The result of this is that I&#039;m not sure moving the Wesabe widget password to a
different keychain is going to do much. If a user gives a malicious program
access to the Widget keychain item, then it doesn&#039;t matter which keychain the
Widget uses. (Note that this can&#039;t happen accidentally -- the user would have
to explicitly grant such access.)

That said, your comment about setting keychains to lock brings up a good
point. By default, the login keychain on OS X is *not* set to lock
automatically, even if the computer goes to sleep. Apple set these defaults in
the interests of usability -- most users don&#039;t want to be prompted for their
password all the time, no matter what the marginal benefit -- but more
paranoid (or just plain curious) users may want to change them.[2] This will
limit the amount of time passwords are stored in memory, and will protect your
passwords even from someone who steals your computer while it&#039;s running...

Of course, if you have any other questions about Wesabe security, or ideas
about how to improve things, please don&#039;t hesitate to send a note to
support@wesabe.com. We take these things really seriously here, and we&#039;re
always happy to hear what people think...

-sq

[1] You can check this yourself by opening Keychain Access
(/Applications/Utilities/Keychain Access.app), double-clicking the &quot;Wesabe
Widget&quot; item, and looking in the &quot;Access Control&quot; tab.

[2] You can change the settings by opening Keychain Access, as described in
[1], ctrl-clicking the keychain marked &quot;login&quot;, and selecting the &quot;Change
settings&quot; option. I set mine to lock when sleeping and after 5 minutes of
inactivity, and I don&#039;t find it too annoying. (But then again, I probably have
a higher tolerance for this than the average user...)</description>
		<content:encoded><![CDATA[<p>Nat&#8211;</p>
<p>I work in the Security group here at Wesabe, and I just thought I&#8217;d point out<br />
that the fact that the login keychain is often unlocked does *not* mean that<br />
any application has access to its contents. The Mac Keychain only allows<br />
&#8220;trusted applications&#8221; to access individual keychain entries: unless users<br />
specifically grant access to the &#8220;Wesabe Widget&#8221; keychain item to other<br />
programs, the only application that can read it will be the &#8220;DashboardClient&#8221;.[1]</p>
<p>The result of this is that I&#8217;m not sure moving the Wesabe widget password to a<br />
different keychain is going to do much. If a user gives a malicious program<br />
access to the Widget keychain item, then it doesn&#8217;t matter which keychain the<br />
Widget uses. (Note that this can&#8217;t happen accidentally &#8212; the user would have<br />
to explicitly grant such access.)</p>
<p>That said, your comment about setting keychains to lock brings up a good<br />
point. By default, the login keychain on OS X is *not* set to lock<br />
automatically, even if the computer goes to sleep. Apple set these defaults in<br />
the interests of usability &#8212; most users don&#8217;t want to be prompted for their<br />
password all the time, no matter what the marginal benefit &#8212; but more<br />
paranoid (or just plain curious) users may want to change them.[2] This will<br />
limit the amount of time passwords are stored in memory, and will protect your<br />
passwords even from someone who steals your computer while it&#8217;s running&#8230;</p>
<p>Of course, if you have any other questions about Wesabe security, or ideas<br />
about how to improve things, please don&#8217;t hesitate to send a note to<br />
<a href="mailto:support@wesabe.com">support@wesabe.com</a>. We take these things really seriously here, and we&#8217;re<br />
always happy to hear what people think&#8230;</p>
<p>-sq</p>
<p>[1] You can check this yourself by opening Keychain Access<br />
(/Applications/Utilities/Keychain Access.app), double-clicking the &#8220;Wesabe<br />
Widget&#8221; item, and looking in the &#8220;Access Control&#8221; tab.</p>
<p>[2] You can change the settings by opening Keychain Access, as described in<br />
[1], ctrl-clicking the keychain marked &#8220;login&#8221;, and selecting the &#8220;Change<br />
settings&#8221; option. I set mine to lock when sleeping and after 5 minutes of<br />
inactivity, and I don&#8217;t find it too annoying. (But then again, I probably have<br />
a higher tolerance for this than the average user&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nat Irons</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4217</link>
		<dc:creator>Nat Irons</dc:creator>
		<pubDate>Mon, 04 Feb 2008 07:25:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4217</guid>
		<description>It&#039;s not terribly safe, unless you remove the Wesabe password from your default keychain (where the Wesabe password is born, and which is probably unlocked most of the time), and put it in its own dedicated keychain. Then assign the new keychain file a unique password, which you&#039;ll be prompted to enter when the Dashboard widget tries to collect new data. (For bonus points, open the new keychain&#039;s settings and set it to lock after one minute.)

You could re-use your Wesabe account password for this new keychain, if it already strong and unique -- if a bad actor ever compromised the password to your Wesabe keychain, they could by definition learn the password it&#039;s protecting. Fortunately, Keychain&#039;s encryption has a good track record.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not terribly safe, unless you remove the Wesabe password from your default keychain (where the Wesabe password is born, and which is probably unlocked most of the time), and put it in its own dedicated keychain. Then assign the new keychain file a unique password, which you&#8217;ll be prompted to enter when the Dashboard widget tries to collect new data. (For bonus points, open the new keychain&#8217;s settings and set it to lock after one minute.)</p>
<p>You could re-use your Wesabe account password for this new keychain, if it already strong and unique &#8212; if a bad actor ever compromised the password to your Wesabe keychain, they could by definition learn the password it&#8217;s protecting. Fortunately, Keychain&#8217;s encryption has a good track record.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Explore2Learn</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4216</link>
		<dc:creator>Explore2Learn</dc:creator>
		<pubDate>Mon, 03 Dec 2007 00:24:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4216</guid>
		<description>How do they get all that secure info, yet not have any access to it? I guess I am not sure how safe it is.</description>
		<content:encoded><![CDATA[<p>How do they get all that secure info, yet not have any access to it? I guess I am not sure how safe it is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manage Your Money with Wesabe Dashboard Widget [Featured Mac Download] at SoftSaurus</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4215</link>
		<dc:creator>Manage Your Money with Wesabe Dashboard Widget [Featured Mac Download] at SoftSaurus</dc:creator>
		<pubDate>Mon, 03 Dec 2007 00:21:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4215</guid>
		<description>[...] Mac OS X only: Previously introduced money management web app, Wesabe, makes it even easier to manage your money with a free dashboard widget. The widget has two views: transactions and accounts. The accounts view (shown above) displays the balance of each account. The transactions view (not shown) displays the most recent 10 transactions. The dashboard widget makes it very easy and convenient to manage your finances at-a-glance. The Wesabe dashboard widget is a free download for Mac OS X only. Wesabe&#8217;s Mac Dashboard Widget [Wheaties for your Wallet] [...]</description>
		<content:encoded><![CDATA[<p>[...] Mac OS X only: Previously introduced money management web app, Wesabe, makes it even easier to manage your money with a free dashboard widget. The widget has two views: transactions and accounts. The accounts view (shown above) displays the balance of each account. The transactions view (not shown) displays the most recent 10 transactions. The dashboard widget makes it very easy and convenient to manage your finances at-a-glance. The Wesabe dashboard widget is a free download for Mac OS X only. Wesabe&#8217;s Mac Dashboard Widget [Wheaties for your Wallet] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manage Your Money with Wesabe Dashboard Widget [Featured Mac Download] &#183; TechBlogger</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4214</link>
		<dc:creator>Manage Your Money with Wesabe Dashboard Widget [Featured Mac Download] &#183; TechBlogger</dc:creator>
		<pubDate>Sun, 02 Dec 2007 23:20:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4214</guid>
		<description>[...] Mac OS X only: Previously introduced money management web app, Wesabe, makes it even easier to manage your money with a free dashboard widget. The widget has two views: transactions and accounts. The accounts view (shown above) displays the balance of each account. The transactions view (not shown) displays the most recent 10 transactions. The dashboard widget makes it very easy and convenient to manage your finances at-a-glance. The Wesabe dashboard widget is a free download for Mac OS X only. Wesabe&#8217;s Mac Dashboard Widget [Wheaties for your Wallet] [...]</description>
		<content:encoded><![CDATA[<p>[...] Mac OS X only: Previously introduced money management web app, Wesabe, makes it even easier to manage your money with a free dashboard widget. The widget has two views: transactions and accounts. The accounts view (shown above) displays the balance of each account. The transactions view (not shown) displays the most recent 10 transactions. The dashboard widget makes it very easy and convenient to manage your finances at-a-glance. The Wesabe dashboard widget is a free download for Mac OS X only. Wesabe&#8217;s Mac Dashboard Widget [Wheaties for your Wallet] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Briskar</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4213</link>
		<dc:creator>Briskar</dc:creator>
		<pubDate>Thu, 22 Nov 2007 21:38:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4213</guid>
		<description>Great widget. It&#039;s a huge timesaver.</description>
		<content:encoded><![CDATA[<p>Great widget. It&#8217;s a huge timesaver.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: metarand &#187; What&#8217;s the KeyPoint of a Facebook Application?</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4212</link>
		<dc:creator>metarand &#187; What&#8217;s the KeyPoint of a Facebook Application?</dc:creator>
		<pubDate>Thu, 15 Nov 2007 22:26:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4212</guid>
		<description>[...] Checking out your balance on the site you most frequent is useful, but it&#8217;s not a gobsmackingly good experience you want to evangelize to all your Facebook friends, nor is it an engaging utility you cannot do with out. Widgets are great - for example, Wesabe has launched an account balance Mac widget which streams real time balance updates. [...]</description>
		<content:encoded><![CDATA[<p>[...] Checking out your balance on the site you most frequent is useful, but it&#8217;s not a gobsmackingly good experience you want to evangelize to all your Facebook friends, nor is it an engaging utility you cannot do with out. Widgets are great &#8211; for example, Wesabe has launched an account balance Mac widget which streams real time balance updates. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kristof</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4211</link>
		<dc:creator>kristof</dc:creator>
		<pubDate>Tue, 13 Nov 2007 15:45:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4211</guid>
		<description>You plan to develope it to windows?</description>
		<content:encoded><![CDATA[<p>You plan to develope it to windows?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kyle P.</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4210</link>
		<dc:creator>Kyle P.</dc:creator>
		<pubDate>Mon, 12 Nov 2007 10:37:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4210</guid>
		<description>Thank you. Downloaded it this morning. Love it.</description>
		<content:encoded><![CDATA[<p>Thank you. Downloaded it this morning. Love it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wesabe’s Mac Dashboard Widget &#171; The Bankwatch</title>
		<link>http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4209</link>
		<dc:creator>Wesabe’s Mac Dashboard Widget &#171; The Bankwatch</dc:creator>
		<pubDate>Wed, 07 Nov 2007 01:31:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.wesabe.com/2007/11/06/wesabes-mac-dashboard-widget/#comment-4209</guid>
		<description>[...] Wheaties for Your Wallet » Blog Archive » Wesabe’s Mac Dashboard Widget   The Dashboard Widget gives you one-button access to your bank balances and recent transactions. This turns out to be hugely convenient — instead of having to log into all of your bank sites or even to Wesabe to check your balances, you just have to be logged into your Mac. [...]</description>
		<content:encoded><![CDATA[<p>[...] Wheaties for Your Wallet » Blog Archive » Wesabe’s Mac Dashboard Widget   The Dashboard Widget gives you one-button access to your bank balances and recent transactions. This turns out to be hugely convenient — instead of having to log into all of your bank sites or even to Wesabe to check your balances, you just have to be logged into your Mac. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
