[JDEV] Jabber AIM transport caches passwords

kadokev at msg.net kadokev at msg.net
Fri Mar 9 00:03:24 CST 2001


I've noticed that the AIM transport for Jabberd is storing the AIM information
permanently in a file on the jabber server, including the username and
password for every AIM account used through the transport?

I can understand why the transport would need to cache the credentials for
the AIM connection, but it seems particularly dangerous to be storing this
in cleartext file, permanently. If nothing else, there should be prominent
warnings in the documentation for the transport and to all transport users.

Kevin Kadow




More information about the JDev mailing list