QuickTime 7.0.1: Security enhancements
This sucks. QT 7.0.1 no longer lets you access remote web locations from within a Quartz Composition when played using Quicktime Player. No more playing such compositions from the Quicktime Plugin in a web page either. This means no RSS feeds unless you run the composition in Quartz Composer itself or in a custom app.
This is the direction I’m heading anyway (making custom apps) but it means you can no longer distribute a .qtz file or a composition in a .mov which accesses network data and expect it to work on machine running Tiger unless the user has Quartz Composer installed.
These were some of the coolest features of Quartz which I was only just starting to explore before the plug was pulled. Hopefully these features will return some time soon.
Update 18/7/05
I don’t think I made this clear enough but the change was made in response to the potential security issue whereby network access from within a composition wrapped in a .mov file to be used to leak information to a malicious third party when used in combination with Quartz Composer’s ability to access sensitive information about the host computer (computer name, local ip address, current username, results of spotlight searches etc). See the original security report from David Remahl here:
Full-Disclosure: [Full-disclosure] [DR018] Quartz Composer / QuickTime 7 information leakage
Regular (non Quartz Composer) wired Quicktime movies have had the potential to expose some information about the host computer via network access for many years, however it was never to this level and I guess never seen as a security issue. As much as I hope to see things like RSS access return to Quartz Compositions when wrapped in .movs I don’t think it is likely.
It would be virtually impossible to modify Quicktime’s handling of QCs to differentiate between allowing nice, friendly information to be sent (get me links to all the recent images of “x” from flickr.com) and preventing nasty information such as (here is my username and ip address, please start trying to hack into my machine).
Using Quartz Compositions as screen savers expose the same potential risks but I guess in this case you are making a conscious decision to install a piece of software, as opposed to playing a .mov file unaware of its hidden code.
Technorati Tags: Quartz Composer, Quicktime








