Hacker News new | past | comments | ask | show | jobs | submit login

Jabber support for FB Chat is nice, but failing to support SSL/TLS is not really acceptable...



When would you use FB chat and care about the privacy of the communication?


When I am using a real Jabber client.


At work, probably.


This includes the login I guess...


can someone confirm that login info is sent in the clear? that's pretty terrible.


They claim they're using DIGEST-MD5, so not quite plaintext, but a broken hash algorithm

http://www.facebook.com/help/?faq=16742

http://www.facebook.com/help/?faq=16741


yep. they could have at least supported SASL to have the login info encrypted and then transport the rest of the stream unencrypted, but they did not.


Where does it say SSL/TLS is not supported?


When you try to connect with "Require SSL/TLS" enabled.


Just check the instructions for iChat it clearly says to uncheck SSL.


Has the AJAX-based chat built into the web application ever been encrypted?




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: