<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Pidgin may eat your password !</title>
	<atom:link href="http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/</link>
	<description></description>
	<lastBuildDate>Tue, 03 Aug 2010 10:10:43 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: kamasheto</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-189</link>
		<dc:creator>kamasheto</dc:creator>
		<pubDate>Tue, 23 Dec 2008 18:55:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-189</guid>
		<description>O, thank you.

I just need to clarify a little bit more the situation at hand. Pidgin did not rely on 3rd-party solutions to solve the problem -- they just covered it up the best way they could. They said, in honest plain words, they did not really pay any attention to securing the stored passwords.

Then they elaborated that it&#039;s plain useless, because no matter how secure they tighten things at their end the protocol itself is still unsecure -- which does make sense to be honest.

On top of all that, ALL other IM Messengers are vulnerable to having their passwords extrapolated -- just because Pidgin admitted it doesn&#039;t make it really that bad IMHO.</description>
		<content:encoded><![CDATA[<p>O, thank you.</p>
<p>I just need to clarify a little bit more the situation at hand. Pidgin did not rely on 3rd-party solutions to solve the problem &#8212; they just covered it up the best way they could. They said, in honest plain words, they did not really pay any attention to securing the stored passwords.</p>
<p>Then they elaborated that it&#8217;s plain useless, because no matter how secure they tighten things at their end the protocol itself is still unsecure &#8212; which does make sense to be honest.</p>
<p>On top of all that, ALL other IM Messengers are vulnerable to having their passwords extrapolated &#8212; just because Pidgin admitted it doesn&#8217;t make it really that bad IMHO.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed El Gamil</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-186</link>
		<dc:creator>Ahmed El Gamil</dc:creator>
		<pubDate>Mon, 22 Dec 2008 14:28:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-186</guid>
		<description>You have a good point kamasheto, thanks for mentioning it :)
the Open-source community is growing larger and larger and with very wise steps, even microsoft guys are convinced now by the concept :D
but this doesn&#039;t means that i shouldn&#039;t warn other people if i find a particular flaw in a piece of FOSS i see

Personally, i am not much in development but if i had the chance to develop something like this, i won&#039;t leave the security issue for 3rd-party software (like the UNIX permissions in our case here) to take care of it and just don&#039;t do anything about it, i know that using encryptions can sometimes be cracked and stuff like that, but at least blocked a huge amount of users from breaking it.
and remember, &lt;strong&gt;pidgin developers said that this is a situation that could change in the future&lt;/strong&gt;

I will edit the post and add your quote so that every body will see it isA :)
Thanks for passing by and for your valuable comment.</description>
		<content:encoded><![CDATA[<p>You have a good point kamasheto, thanks for mentioning it <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
the Open-source community is growing larger and larger and with very wise steps, even microsoft guys are convinced now by the concept <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /><br />
but this doesn&#8217;t means that i shouldn&#8217;t warn other people if i find a particular flaw in a piece of FOSS i see</p>
<p>Personally, i am not much in development but if i had the chance to develop something like this, i won&#8217;t leave the security issue for 3rd-party software (like the UNIX permissions in our case here) to take care of it and just don&#8217;t do anything about it, i know that using encryptions can sometimes be cracked and stuff like that, but at least blocked a huge amount of users from breaking it.<br />
and remember, <strong>pidgin developers said that this is a situation that could change in the future</strong></p>
<p>I will edit the post and add your quote so that every body will see it isA <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Thanks for passing by and for your valuable comment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kamasheto</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-184</link>
		<dc:creator>kamasheto</dc:creator>
		<pubDate>Mon, 22 Dec 2008 03:19:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-184</guid>
		<description>I&#039;m sure you don&#039;t really mean it this way, but this gives a bad impression about the open-source concept generally and this application in specific. I&#039;m sure you&#039;ve read the entire article they wrote on their wiki, but just to make sure everyone else gets the image I&#039;d like to quote them:

&lt;blockquote cite=&quot;http://developer.pidgin.im/wiki/PlainTextPasswords&quot;&gt;&quot;But other programs don&#039;t store my password in plain text!&quot;

That&#039;s true. But few of them store it in a way that&#039;s any safer. A Google search for im passwords shows a bunch of hits for getting the passwords out of other IM clients just as easily as Pidgin. &lt;/blockquote&gt;

Bottom line is, all IM clients are insecure and open to the same vulnerability. All of them.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sure you don&#8217;t really mean it this way, but this gives a bad impression about the open-source concept generally and this application in specific. I&#8217;m sure you&#8217;ve read the entire article they wrote on their wiki, but just to make sure everyone else gets the image I&#8217;d like to quote them:</p>
<blockquote cite="http://developer.pidgin.im/wiki/PlainTextPasswords"><p>&#8220;But other programs don&#8217;t store my password in plain text!&#8221;</p>
<p>That&#8217;s true. But few of them store it in a way that&#8217;s any safer. A Google search for im passwords shows a bunch of hits for getting the passwords out of other IM clients just as easily as Pidgin. </p></blockquote>
<p>Bottom line is, all IM clients are insecure and open to the same vulnerability. All of them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed El Gamil</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-165</link>
		<dc:creator>Ahmed El Gamil</dc:creator>
		<pubDate>Sun, 14 Dec 2008 23:56:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-165</guid>
		<description>@MMF:
are you using Linux now ? :)

@Mo3taz:
الموضوع و ما فيه ان المبرمجين اللى عمله بيدجين يا معتز أعتمدوا على انهم يأمنوا بيدجين عن طريق 
3rd party software
و ده طبعاً مشكلة كبيرة لأن اصلاً معظم المستخدمين بينزلوا البرنامج و اول ما يشتغل يبقا تمام كده و مبيعمولش اى حاجة تانية عشان يأمنوا النظم
 سيبك انتا أخبار الجاجا ايه معاك ؟ :)</description>
		<content:encoded><![CDATA[<p>@MMF:<br />
are you using Linux now ? <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>@Mo3taz:<br />
الموضوع و ما فيه ان المبرمجين اللى عمله بيدجين يا معتز أعتمدوا على انهم يأمنوا بيدجين عن طريق<br />
3rd party software<br />
و ده طبعاً مشكلة كبيرة لأن اصلاً معظم المستخدمين بينزلوا البرنامج و اول ما يشتغل يبقا تمام كده و مبيعمولش اى حاجة تانية عشان يأمنوا النظم<br />
 سيبك انتا أخبار الجاجا ايه معاك ؟ <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mo3taz</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-162</link>
		<dc:creator>Mo3taz</dc:creator>
		<pubDate>Sun, 14 Dec 2008 19:36:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-162</guid>
		<description>شكرا يا أحمد على المعلومة ده 
هو الأوبن سورس حلو بس مش أوبن للدرجة ده 
على اللينوكس ممكن الصلاحيات تحد من المشكلة ده لكن على الويندوز ده كارثة ما بعدها كارثة</description>
		<content:encoded><![CDATA[<p>شكرا يا أحمد على المعلومة ده<br />
هو الأوبن سورس حلو بس مش أوبن للدرجة ده<br />
على اللينوكس ممكن الصلاحيات تحد من المشكلة ده لكن على الويندوز ده كارثة ما بعدها كارثة</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MMF</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-159</link>
		<dc:creator>MMF</dc:creator>
		<pubDate>Sun, 14 Dec 2008 01:47:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-159</guid>
		<description>really thanks , AHMED :)
i will install the Password Encryption plugin 
thanks again :)</description>
		<content:encoded><![CDATA[<p>really thanks , AHMED <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
i will install the Password Encryption plugin<br />
thanks again <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bingorabbit</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-157</link>
		<dc:creator>bingorabbit</dc:creator>
		<pubDate>Sat, 13 Dec 2008 20:15:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-157</guid>
		<description>I had two comments held for moderation on my blog too, strange?</description>
		<content:encoded><![CDATA[<p>I had two comments held for moderation on my blog too, strange?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed El Gamil</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-156</link>
		<dc:creator>Ahmed El Gamil</dc:creator>
		<pubDate>Sat, 13 Dec 2008 19:25:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-156</guid>
		<description>Your are welcome ya mostafa :)
I wonder why was your comment held for moderation, do you spam yabny ?!

I really really love the new feature of commenting from the dashboard of WP :D, Thanks for BingoRabbit for fixing it ..</description>
		<content:encoded><![CDATA[<p>Your are welcome ya mostafa <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
I wonder why was your comment held for moderation, do you spam yabny ?!</p>
<p>I really really love the new feature of commenting from the dashboard of WP <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> , Thanks for BingoRabbit for fixing it ..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TeVa</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-155</link>
		<dc:creator>TeVa</dc:creator>
		<pubDate>Sat, 13 Dec 2008 19:22:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-155</guid>
		<description>Thanx alot 4 the notification.
I checked the user privileges in my Ubuntu and i was amazed.
What a stupid way!!
I consider it&#039;s a axiomatic to secure every user&#039;s files like fedora.

Finally I thanked ALLAH that my sisters don&#039;t know very much in linux otherwise my files will be in an open-air not only my passwords  :mrgreen: 
بارك الله فيك 
 :grin:</description>
		<content:encoded><![CDATA[<p>Thanx alot 4 the notification.<br />
I checked the user privileges in my Ubuntu and i was amazed.<br />
What a stupid way!!<br />
I consider it&#8217;s a axiomatic to secure every user&#8217;s files like fedora.</p>
<p>Finally I thanked ALLAH that my sisters don&#8217;t know very much in linux otherwise my files will be in an open-air not only my passwords  <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_mrgreen.gif' alt=':mrgreen:' class='wp-smiley' /><br />
بارك الله فيك<br />
 <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':grin:' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed El Gamil</title>
		<link>http://www.blog.manhag.org/2008/12/pidgin-may-eat-your-password/comment-page-1/#comment-151</link>
		<dc:creator>Ahmed El Gamil</dc:creator>
		<pubDate>Sat, 13 Dec 2008 03:19:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.blog.manhag.org/?p=275#comment-151</guid>
		<description>@Boody:
LOL @ Pidgin security :D
امن الحمام الزاجل :D

@BingoRabbit:
Yeah, I know that permissions are one approach to solve the problem, but note that &lt;strong&gt;not all the distro&#039;s out there provide such feature&lt;/strong&gt;, for example: on ubuntu systems unprivileged users are allowed to read each other&#039;s home directories :D

I will edit the post for more info on the topic after el fagr prayer isA :)
Jzakom ALLAHu kher for the nice comment</description>
		<content:encoded><![CDATA[<p>@Boody:<br />
LOL @ Pidgin security <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /><br />
امن الحمام الزاجل <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>@BingoRabbit:<br />
Yeah, I know that permissions are one approach to solve the problem, but note that <strong>not all the distro&#8217;s out there provide such feature</strong>, for example: on ubuntu systems unprivileged users are allowed to read each other&#8217;s home directories <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>I will edit the post for more info on the topic after el fagr prayer isA <img src='http://www.blog.manhag.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Jzakom ALLAHu kher for the nice comment</p>
]]></content:encoded>
	</item>
</channel>
</rss>
