[Pidgin] #16223: passwords stored in CLEAR TEXT in accounts.xml

Pidgin trac at pidgin.im
Mon May 5 12:42:10 EDT 2014


#16223: passwords stored in CLEAR TEXT in accounts.xml
---------------------+-------------------------------
 Reporter:  cparris  |      Owner:  EionRobb
     Type:  defect   |     Status:  new
Milestone:           |  Component:  unclassified
  Version:  2.10.9   |   Keywords:  password security
---------------------+-------------------------------
 Pidgin user passwords are stored in clear text on user desktops.
 Exact location is:
 C:\Users\<username>\AppData\Roaming

 This is generally, and usually, considered very bad practice.
 At a minimum this should be hashed.

-- 
Ticket URL: <https://developer.pidgin.im/ticket/16223>
Pidgin <https://pidgin.im>
Pidgin


More information about the Tracker mailing list