liv: cartoon of me with long plait, teapot and purple outfit (mini-me)
[personal profile] liv
So jabber.org is being DDoSed, and whatever measures they're taking to mitigate this problem mean that I can't connect via my usual IM client, Pidgin. Apparently it has something to do with DNS, but beyond that I'm in the dark. I have tried upgrading Pidgin to the latest version but no joy there. And I have tried all the reasonable web searches I can think of and not turned up any way of fixing this myself.

So, does anyone know of an IM client that successfully connects to Jabber / XMPP when they have anti-DDoS measures turned on? Basically my only requirement is that it works under Windows and handles multiple protocols, with Jabber being the most important. I would prefer something that doesn't display ads; I'm willing to pay a small amount of money to make the spam go away. If it can do IRC as well as IM that's a bonus, but not an essential feature. Visually sleek or simple is better than visually flashy and cluttered, and I don't particularly need something heavily skinnable.

Secondly, does anyone know how to retrieve IM service passwords out of Pidgin? I have several accounts that I only ever use for IM: MSN / Windows Live Messenger, Yahoo, AIM, and ICQ, and the passwords are stored in Pidgin, never getting typed in anywhere, and not in my browser where I can choose to display stored passwords. Would be a lot easier to move to a different client if I can extract them somehow.

The consequence is, until I can get this fixed or the DDoS goes away, I'm not available at my usual Jabber contact, the one I use for chatting to people who are on Google Talk. PM me if you'd like to add me on one of the other services temporarily, and I'll give you a username. It would help if you could send me a brief message with the add request because I'm getting a whole heap of IM spambots trying to persuade me to join webcam sites (especially on Yahoo and AIM), so I tend to delete add requests by default.
ETA: Fixed!

(no subject)

Date: 2012-08-28 01:03 pm (UTC)
synecdochic: torso of a man wearing jeans, hands bound with belt (Default)
From: [personal profile] synecdochic
I've had to switch to using a Jabber server lately, and after careful consideration of a bunch of clients (and throwing out the ones I'd already tried and wound up finding unusable), I picked up Psi+. It is the least worst Jabber client I've tried so far, though it only does Jabber and not IM.

(no subject)

Date: 2012-08-28 05:24 pm (UTC)
403: A rack of test tubes with the caption "If you're not part of the solution, you're part of the precipitate". (Solution or precipitate)
From: [personal profile] 403
I'm having the same problem with Trillian (v4.2 build 29), so will be watching the comments here with interest.

(no subject)

Date: 2012-08-28 07:50 pm (UTC)
vatine: Generated with some CL code and a hand-designed blackletter font (Default)
From: [personal profile] vatine
It's been a while since I poked the innards of Pidgin and I don't know if there's differences between OSes, but...

At least under Linux, there should be a .pidgin (or similar name) settings directory in your home dir. This has several files, one is a chunk of XML with all configured accounts in it (and passwords).

Under Windows, I'd expect these things to live in the registry, but I honestly have no idea.

(no subject)

Date: 2012-08-28 08:45 pm (UTC)
synecdochic: torso of a man wearing jeans, hands bound with belt (Default)
From: [personal profile] synecdochic
Alas, woe!

But yeah, it's the only Mac Jabber client I've found that doesn't do the obnoxious iChat-style grouping of messages, which I loathe with the passion of a thousand suns.

(no subject)

Date: 2012-08-28 10:36 pm (UTC)
jack: (Default)
From: [personal profile] jack
Because purple is awesome? :)

Huh. Come to think of it, it must be possible to recover saved passwords. If that's right, it's somewhat deceptive for programs to show them as asterisks without any option for displaying them, if that gives the impression they _can't_ be recovered.

(no subject)

Date: 2012-08-28 11:59 pm (UTC)
vatine: Generated with some CL code and a hand-designed blackletter font (Default)
From: [personal profile] vatine
I think it is because in some intermediate phase between being "Gaim" and "Pidgin", it was "The purple IM client".

(no subject)

Date: 2012-08-30 10:36 am (UTC)
jack: (Default)
From: [personal profile] jack
*hugs* Sorry, I meant that as an explanation, not a justification -- I agree that "it's unusable" should outweigh the reasons for purple :)

I don't honestly know if displaying the passwords from as asterisks in the user interface actually provides any security, or if it's just an illusion.

I think there's a combination of factors:

* Displaying asterisks when typing a password is a good default, because it prevents people just casually seeing your password and happening to remember it and succumbing to curiosity, even if they normally wouldn't install a keylogger on your computer even if they could.

* Stored passwords should be encrypted by the browser and/or the operating system, so you can't see them unless you're logged in. I think they probably are, but I'm not sure.

* Passwords will usually be stored as text, not as a hash or anything. There's normally no benefit to doing anything else, since whatever is stored, it will be transmitted to the website and suffice for authentication.

* I'm not sure if there's a better way of managing passwords (or private-key based authentication) if browsers and websites worked together -- I don't think so, but I'm not sure. I think things like ssh recommend something more secure.

* If someone can use your stored password to log in, they can in principle recover what the password is (even if they have to recompile firefox).

* Not displaying the password prominently has some social-hacking prevention value: it stops someone who borrows your computer for a second seeing it, even though it's not cryptographically secure.

* Probably the best compromise is to store the passwords encrypted by a browser master password, display them as asterisks by default, but have a "show password" or "show stored paswords" button which needs you to enter the master password.

Soundbite

Miscellaneous. Eclectic. Random. Perhaps markedly literate, or at least suffering from the compulsion to read any text that presents itself, including cereal boxes.

Top topics

December 2025

S M T W T F S
 123456
78910111213
14151617181920
21222324252627
282930 31   

Expand Cut Tags

No cut tags

Subscription Filters