We Just Can’t Help It
Wow, what an awesome article. http://www.joemcnally.com/blog/2010/02/15/we-just-cant-help-it/
Posted via web from posterous for Kevin Williams | Comment »
I am a developer of a free iphone
XMPP client called Monal. I was really excited to hear that Facebook
finally opened up their network to XMPP clients after promising it for
years. I raced home to try it out and discovered that they had done
probably one of the worst implementations ever. The chat does not use
SSL encryption unlike almost every other server. Better yet, they
decided to use an authentication scheme called Digest-MD5, which aside
from having varying implementations and compatibility problems was
DEPRECATED by the IETF in January 2009 ( https://tools.ietf.org/html/draft-ietf-sasl-digest-to-historic
) because it can be cracked. Facebook has just opened up a gaping
hole in their security. Someone at facebook needs to be fired.
