in windows too Pidgin stores the plain text password in
%userprofile%\../.purple/   folder in plain text with all email of
your conacts and when uninstalled doesnt clear the folder and password
file.

IM contacts stored locally can be used by mailware to SPAM is a long known issue

but as the password is stored under your home directory the FS
permission should take cair of security, though in corporate
environment this might be a little problem. other apps that has option
to store password also store passowrd in encoded form anyways.

in windows you could use the default encrypted file system feature and
transperently encrypt the folder same goes with *nix system....
encrypt your home directory.

better option is to remember your IM password instead of storing it as
it could float around in unallocated space of your hdd even long after
deleted!

On Jan 18, 2008 12:30 AM, Prasanna Gautam <[EMAIL PROTECTED]> wrote:
> Did you guys know that pidgin saves all your passwords in plaintext? :) good
> stuff,eh?
> http://developer.pidgin.im/wiki/PlainTextPasswords
> Here's the reason why.
> If you want to look at it...  it's at $HOME/.purple/accounts.xml
> I'd also like to give a solution to this that I came across.
> http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html
>
> Have a nice day,
> Prasanna Gautam
>
> >
>



-- 
X-No-Archive:

--~--~---------~--~----~------------~-------~--~----~
FOSS Nepal mailing list: [email protected]
http://groups.google.com/group/foss-nepal
To unsubscribe, e-mail: [EMAIL PROTECTED]

Community website: http://www.fossnepal.org/
-~----------~----~----~----~------~----~------~--~---

Reply via email to