<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fix for Master password expose for Pidgin</title>
	<atom:link href="http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html</link>
	<description>Ubuntu Linux Tutorials,Howtos,Tips &#38; News &#124; Oneiric,Natty,Maverick</description>
	<lastBuildDate>Mon, 06 Feb 2012 15:40:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: simon</title>
		<link>http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html/comment-page-1#comment-31285</link>
		<dc:creator>simon</dc:creator>
		<pubDate>Sat, 29 May 2010 12:27:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html#comment-31285</guid>
		<description>Attila - actually the passwords are not necessarily sent in plaintext.  My GTalk account uses SSL/TLS.  I would very much prefer that my password was *not* stored in plaintext on my filesystem.

The Pidgin developers&#039; argument is basically that unless the security is 100%, a little security is not better than no security.  I don&#039;t agree.

*frustrated*</description>
		<content:encoded><![CDATA[<p>Attila - actually the passwords are not necessarily sent in plaintext.  My GTalk account uses SSL/TLS.  I would very much prefer that my password was *not* stored in plaintext on my filesystem.</p>
<p>The Pidgin developers&#8217; argument is basically that unless the security is 100%, a little security is not better than no security.  I don&#8217;t agree.</p>
<p>*frustrated*</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Attila</title>
		<link>http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html/comment-page-1#comment-2301</link>
		<dc:creator>Attila</dc:creator>
		<pubDate>Tue, 07 Oct 2008 11:31:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html#comment-2301</guid>
		<description>Hi guys!
I actually read at the pidgin website why they decided not to encode the passwords on your hard drive.
Since you probably did not read it here it is in short:
The passwords are sent through the internet without encryption. Therefore if your password is encoded on your box it gives you a false feeling of security.
By the way when your passwords are stolen from your machine it is the same as if your keys were stolen from your desk. Do not leave your machine unattended and unlocked.
Attila</description>
		<content:encoded><![CDATA[<p>Hi guys!<br />
I actually read at the pidgin website why they decided not to encode the passwords on your hard drive.<br />
Since you probably did not read it here it is in short:<br />
The passwords are sent through the internet without encryption. Therefore if your password is encoded on your box it gives you a false feeling of security.<br />
By the way when your passwords are stolen from your machine it is the same as if your keys were stolen from your desk. Do not leave your machine unattended and unlocked.<br />
Attila</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TSM</title>
		<link>http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html/comment-page-1#comment-2300</link>
		<dc:creator>TSM</dc:creator>
		<pubDate>Fri, 06 Jun 2008 08:14:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html#comment-2300</guid>
		<description>Nice catch. I noticed this a few days ago myself and was highly confused that anyone would store passwords in such a way.. I really hope the pidgin development team fixes this in the not too distant future.</description>
		<content:encoded><![CDATA[<p>Nice catch. I noticed this a few days ago myself and was highly confused that anyone would store passwords in such a way.. I really hope the pidgin development team fixes this in the not too distant future.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html/comment-page-1#comment-2299</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Wed, 30 Apr 2008 17:19:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html#comment-2299</guid>
		<description>yes you can use and you can use ubuntugeek.com name for this</description>
		<content:encoded><![CDATA[<p>yes you can use and you can use ubuntugeek.com name for this</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ConnorBehan</title>
		<link>http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html/comment-page-1#comment-2298</link>
		<dc:creator>ConnorBehan</dc:creator>
		<pubDate>Wed, 30 Apr 2008 16:45:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html#comment-2298</guid>
		<description>I would really like to include that patch in my &quot;Funpidgin&quot; package which aims to give users the features they ask for without being preachy or political. Is that ok? I will give you credit for writing it on the site if you tell me what name I should use. Thanks!</description>
		<content:encoded><![CDATA[<p>I would really like to include that patch in my &#8220;Funpidgin&#8221; package which aims to give users the features they ask for without being preachy or political. Is that ok? I will give you credit for writing it on the site if you tell me what name I should use. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scv5</title>
		<link>http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html/comment-page-1#comment-2297</link>
		<dc:creator>scv5</dc:creator>
		<pubDate>Wed, 09 Apr 2008 12:54:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html#comment-2297</guid>
		<description>If you wrote that patch, you need to contact the pidgin developers team to push this upstream.</description>
		<content:encoded><![CDATA[<p>If you wrote that patch, you need to contact the pidgin developers team to push this upstream.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alvin Brinson</title>
		<link>http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html/comment-page-1#comment-2296</link>
		<dc:creator>Alvin Brinson</dc:creator>
		<pubDate>Fri, 22 Feb 2008 10:29:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.ubuntugeek.com/fix-for-master-password-expose-for-pidgin.html#comment-2296</guid>
		<description>I wish I had known this before!!

My GMail account was stolen today, and in the course of tracking down how it happened I hit upon Pidgin as one other password that was stolen (the only other one) was my ICQ account which I almost never use. The password for ICQ *only* exists in Accounts.XML so that is certainly how the hacker got my GMail password as well.

I&#039;m rather upset that anyone considers it acceptable to store plaintext passwords. I use a password manager on my system that requires a Master Password to unlock, and yet one of my most important passwords is compromised by a bad programming decision. How they got the Accounts.XML file is almost irrelevant (not quite sure, but I&#039;ve wiped the system just in case the exploit was still around), just that it apparently is a juicy target that IS BEING TARGETTED.

I will never again use Pidgin until this is changed.</description>
		<content:encoded><![CDATA[<p>I wish I had known this before!!</p>
<p>My GMail account was stolen today, and in the course of tracking down how it happened I hit upon Pidgin as one other password that was stolen (the only other one) was my ICQ account which I almost never use. The password for ICQ *only* exists in Accounts.XML so that is certainly how the hacker got my GMail password as well.</p>
<p>I&#8217;m rather upset that anyone considers it acceptable to store plaintext passwords. I use a password manager on my system that requires a Master Password to unlock, and yet one of my most important passwords is compromised by a bad programming decision. How they got the Accounts.XML file is almost irrelevant (not quite sure, but I&#8217;ve wiped the system just in case the exploit was still around), just that it apparently is a juicy target that IS BEING TARGETTED.</p>
<p>I will never again use Pidgin until this is changed.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

