<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Kommentare zu: Palringo has severe security issues</title>
	<atom:link href="http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/</link>
	<description>Herzlich willkommen an Bord!</description>
	<lastBuildDate>Fri, 05 Mar 2010 18:05:58 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Von: bigstyle</title>
		<link>http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/comment-page-1/#comment-206944</link>
		<dc:creator>bigstyle</dc:creator>
		<pubDate>Fri, 26 Feb 2010 19:03:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kaputtendorf.de/?p=620#comment-206944</guid>
		<description>I have seen exactly the same problem with ebuddy.

So... is there any WLM/MSN Client secured ?

Thanks</description>
		<content:encoded><![CDATA[<p>I have seen exactly the same problem with ebuddy.</p>
<p>So&#8230; is there any WLM/MSN Client secured ?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: anon</title>
		<link>http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/comment-page-1/#comment-98887</link>
		<dc:creator>anon</dc:creator>
		<pubDate>Thu, 15 Jan 2009 04:27:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kaputtendorf.de/?p=620#comment-98887</guid>
		<description>Do you know if Nimbuzz has the same problem?</description>
		<content:encoded><![CDATA[<p>Do you know if Nimbuzz has the same problem?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Sveenie</title>
		<link>http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/comment-page-1/#comment-36720</link>
		<dc:creator>Sveenie</dc:creator>
		<pubDate>Fri, 15 Aug 2008 14:08:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kaputtendorf.de/?p=620#comment-36720</guid>
		<description>BTW: Google (Gtalk) states in the Terms of Service:
&lt;cite&gt;6.1	You agree and understand that you are responsible for maintaining the confidentiality of passwords associated with any account you use to access the Services.&lt;/cite&gt;
How can a Palringo user do that, if he doesn&#039;t even know, that he/she gives the password to a third party?</description>
		<content:encoded><![CDATA[<p>BTW: Google (Gtalk) states in the Terms of Service:<br />
<cite>6.1	You agree and understand that you are responsible for maintaining the confidentiality of passwords associated with any account you use to access the Services.</cite><br />
How can a Palringo user do that, if he doesn&#8217;t even know, that he/she gives the password to a third party?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Sveenie</title>
		<link>http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/comment-page-1/#comment-36708</link>
		<dc:creator>Sveenie</dc:creator>
		<pubDate>Fri, 15 Aug 2008 13:35:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kaputtendorf.de/?p=620#comment-36708</guid>
		<description>@Martin: that&#039;s not true. For XMPP/Jabber/Gtalk, what I&#039;m mainly using, full encryption IS standard. So for me this would be clearly a step back.
Of course you are free to convince your potential users that your intentions are good, but first you have to give them the choice by clearly stating how it works. But you don&#039;t, since you fear that users will have doubts if it is such a good idea to give all their passwords to a third party. And instead of addressing these doubts you just don&#039;t mention it.
To be fair: MobileChat is relaying over their proxy as well, but I don&#039;t know about encryption. I cannot check it out, since I don&#039;t want to pay money for it.</description>
		<content:encoded><![CDATA[<p>@Martin: that&#8217;s not true. For XMPP/Jabber/Gtalk, what I&#8217;m mainly using, full encryption IS standard. So for me this would be clearly a step back.<br />
Of course you are free to convince your potential users that your intentions are good, but first you have to give them the choice by clearly stating how it works. But you don&#8217;t, since you fear that users will have doubts if it is such a good idea to give all their passwords to a third party. And instead of addressing these doubts you just don&#8217;t mention it.<br />
To be fair: MobileChat is relaying over their proxy as well, but I don&#8217;t know about encryption. I cannot check it out, since I don&#8217;t want to pay money for it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Martin</title>
		<link>http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/comment-page-1/#comment-36218</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Wed, 13 Aug 2008 20:18:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kaputtendorf.de/?p=620#comment-36218</guid>
		<description>@Sveenie: Users face the same issues when using official MSN/ICQ/AIM clients - it is not industry standard practice to encrypt data other than passwords.

Palringo&#039;s servers act as a proxy/gateway to other services, which provides better resilience to intermittent connectivity problems and will allow us to implement push notifications in the near future. We do not log traffic data we relay, and the sole design rationale behind our architecture has been to provide a better user experience.</description>
		<content:encoded><![CDATA[<p>@Sveenie: Users face the same issues when using official MSN/ICQ/AIM clients &#8211; it is not industry standard practice to encrypt data other than passwords.</p>
<p>Palringo&#8217;s servers act as a proxy/gateway to other services, which provides better resilience to intermittent connectivity problems and will allow us to implement push notifications in the near future. We do not log traffic data we relay, and the sole design rationale behind our architecture has been to provide a better user experience.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Sveenie</title>
		<link>http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/comment-page-1/#comment-36173</link>
		<dc:creator>Sveenie</dc:creator>
		<pubDate>Wed, 13 Aug 2008 13:35:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kaputtendorf.de/?p=620#comment-36173</guid>
		<description>@Martin: Ok, so what do we still have in the new version: Everybody can see our conversation and Palringo knows all our passwords. That&#039;s a bit better, but far from being good.

Your privacy policy just tells what you do with the information, not what information you will gather. The users just don&#039;t expect, that all their passwords are disclosed to Palringo.

If you want to offer a fair and acceptable product, you should use a full SSL tunnel to your server and explicitly clarify to the users, that all the IM traffic and all passwords will be forwarded to your server.</description>
		<content:encoded><![CDATA[<p>@Martin: Ok, so what do we still have in the new version: Everybody can see our conversation and Palringo knows all our passwords. That&#8217;s a bit better, but far from being good.</p>
<p>Your privacy policy just tells what you do with the information, not what information you will gather. The users just don&#8217;t expect, that all their passwords are disclosed to Palringo.</p>
<p>If you want to offer a fair and acceptable product, you should use a full SSL tunnel to your server and explicitly clarify to the users, that all the IM traffic and all passwords will be forwarded to your server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Martin</title>
		<link>http://blog.kaputtendorf.de/2008/08/12/palringo-has-severe-security-issues/comment-page-1/#comment-36029</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Tue, 12 Aug 2008 21:00:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kaputtendorf.de/?p=620#comment-36029</guid>
		<description>As of 20 minutes ago, Apple have finally approved the 1.1 update to Palringo. This enables full encryption for sensitive user details such as passwords.

Palringo&#039;s servers do not store unencrypted versions of passwords, and do not store messages which are relayed to MSN/ICQ/AIM/etc.

Our privacy policy is available on our website and details our use of details provided to us by our users - it&#039;s not as alarming as this post makes it out to be.</description>
		<content:encoded><![CDATA[<p>As of 20 minutes ago, Apple have finally approved the 1.1 update to Palringo. This enables full encryption for sensitive user details such as passwords.</p>
<p>Palringo&#8217;s servers do not store unencrypted versions of passwords, and do not store messages which are relayed to MSN/ICQ/AIM/etc.</p>
<p>Our privacy policy is available on our website and details our use of details provided to us by our users &#8211; it&#8217;s not as alarming as this post makes it out to be.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
