Hacker News new | ask | show | jobs
by aaronblohowiak 5977 days ago
When would you use FB chat and care about the privacy of the communication?
3 comments

When I am using a real Jabber client.
At work, probably.
This includes the login I guess...
can someone confirm that login info is sent in the clear? that's pretty terrible.
They claim they're using DIGEST-MD5, so not quite plaintext, but a broken hash algorithm

http://www.facebook.com/help/?faq=16742

http://www.facebook.com/help/?faq=16741

yep. they could have at least supported SASL to have the login info encrypted and then transport the rest of the stream unencrypted, but they did not.