2.24.2008

Two passwords?

Turns out I'm stuck at McCarran Airport in Las Vegas again, so I decided to take advantage of some free wireless. It's not a pleasant idea to think that someone could be intercepting packages on unsecure networks, but whatever. I'm still confused about what I discovered about my AIM password last night.

I changed the password quite a while ago because I kept getting random overlapping connections, which I assumed were coming from other computers that had automatic log-on turned on in regular AIM. Last night I accidentally used the old password in meebo and it worked (!?). I'm pretty sure this password does not work on my current AIM client pidgin, so I tried with my new password and this also worked in meebo (!?). I tried a random password just in case - thank god that didn't also work. Then I went to aim.com and here only my old password worked.

What is going on?? My first instinct is that, assuming aim.com is "official," somehow the password change through pidgin only took place locally and somehow meebo still picks up both. Though I don't know much about encryption, I did a little research and it seems like meebo and pidgin both has its problems concerning security, since they inherently have to collect passwords for multiple protocols. And apparently, pidgin uses plain text to store passwords. But I don't think, or at least I hope, that I got my password stolen... there must be something weird about my account or one of these services/programs... I could be way off but I guess I'll keep investigating.

Articles and documentations of interest:
GMail Account Stolen - Pidgin Partly to Blame
Plain Text Passwords (Pidgin)

No comments: