Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not super familiar with the details, but I think Pidgin has little/no support for encryption (OMEMO & OpenPGP). This probably has support for other XMPP features that Pidgin doesn't as well.

What I don't know is how this is different than gajim.



The Pidgin OTR plugin worked really well over many years, but I haven't used it in a while: https://otr.cypherpunks.ca/


Yes, OTR worked well for me years ago.

Although IIRC Pidgin also stored network credentials in plain-text file. Maybe that has been resolved in the past 10 years?


Pidgin intentionally stores them in plain text. The logic, I believe, is that "light encryption" is worse than no encryption since it gives a false sense of security.

So rather than a reversible cypher they leave it plain so that their users will freak out and /not/ share their files with folk and will properly lock down their creds file.


Every recent graphical OS has support for key management though, whether it is the key store on mac, the credential store on Windows or the key management tools that come with KDE or Gnome (I believe both share somewhat of an API).

It might be due to Pidgin's age but in modern programs storing this data in plain text should be a last resort for systems that don't do secret management for you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: