# SD IM Tutorial Please

**URL:** <https://boards.straightdope.com/t/sd-im-tutorial-please/313869>\
**Category:** Factual Questions\
**Created:** [July 24, 2005, 12:14am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869 "2005-07-24T00:14:30Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [July 24, 2005, 12:14am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/1 "2005-07-24T00:14:30Z")

</div>

I suddenly have a use for an IM program. I concerned about security. I’ve been directed to Miranda and Trillian. I don’t care about audio/video conferencing etc.

Also, do I need to have an account somewheres with somebody? If so, who’s got the best re security and privacy?

I already have the usual assortent of security precautions and protocols in place (AV, anti-spyware, turned off unused services, firewalls, etc). Is there anything else that I’ll need to have or do to be reasonably safe?

thx

---

<div class="post-metadata">

**Author:** ![jnglmassiv](https://avatars.discourse-cdn.com/v4/letter/j/f07891/32.png) [@jnglmassiv](https://boards.straightdope.com/u/jnglmassiv)\
**Post date:** [July 24, 2005, 12:20am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/2 "2005-07-24T00:20:19Z")

</div>

Both parties need an account with a particular IM service (AIM, MSmessenger, Yahoo, etc). Trillian can combine all these and more into a single, slick (and encrypted) program. I’ve been using it for quite a while now, even though I use AIM exclusivly.

---

<div class="post-metadata">

**Author:** ![Lobsang](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lobsang/32/4067_2.png) [@Lobsang](https://boards.straightdope.com/u/Lobsang)\
**Post date:** [July 24, 2005, 12:22am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/3 "2005-07-24T00:22:14Z")

</div>

We use trillian at work because so many of our contacts used different services (AIM, MSN, Yahoo etc…) I can’t fault it so far. And I assume reducing four programs into one frees up some resources for the computer.

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [July 24, 2005, 1:04am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/4 "2005-07-24T01:04:51Z")

</div>

> [@jnglmassiv](#):
>
> Both parties need an account with a particular IM service (AIM, MSmessenger, Yahoo, etc). Trillian can combine all these and more into a single, slick ( **and encrypted** ) program. I’ve been using it for quite a while now, even though I use AIM exclusivly.

Are you saying that communication on Trillian is encrypted?

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [July 24, 2005, 1:06am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/5 "2005-07-24T01:06:02Z")

</div>

> [@Lobsang](#):
>
> We use trillian at work because so many of our contacts used different services (AIM, MSN, Yahoo etc…) I can’t fault it so far. And I assume reducing four programs into one frees up some resources for the computer.

Do you know what kinds of security steps do you guys take for IM use?

---

<div class="post-metadata">

**Author:** ![jnglmassiv](https://avatars.discourse-cdn.com/v4/letter/j/f07891/32.png) [@jnglmassiv](https://boards.straightdope.com/u/jnglmassiv)\
**Post date:** [July 24, 2005, 2:05am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/6 "2005-07-24T02:05:31Z")

</div>

> [@](#):
>
> Are you saying that communication on Trillian is encrypted?

Yes it can be. It’s a box you check in the configuration setup. Both users need ti be using Trillian. It’s kind of neat…when an incoming crypto message approaches, the window pops up and says something like ‘establishing secure tunnel’ and then ‘Secure IM session established with xxuserxx’.

---

<div class="post-metadata">

**Author:** ![snailboy](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@snailboy](https://boards.straightdope.com/u/snailboy)\
**Post date:** [July 24, 2005, 6:13am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/7 "2005-07-24T06:13:01Z")

</div>

You might consider using Jabber. You’ll be able to run your own server and can use transports to connect to other services, like Yahoo and AIM, through it. I’m not sure, but I believe it has encryption too.

---

<div class="post-metadata">

**Author:** ![snailboy](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@snailboy](https://boards.straightdope.com/u/snailboy)\
**Post date:** [July 24, 2005, 6:27am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/8 "2005-07-24T06:27:03Z")

</div>

I should have searched a little before posting. Jabber does support SSL encryption of messages, passwords, log files, and more. However, it’s only available with the enterprise version, and I’m not sure how much that costs. I doubt it’s much since the regular version is free.

[http://security.itworld.com/4361/IDG010419jabber/page\_1.html](http://security.itworld.com/4361/IDG010419jabber/page_1.html)

More information at:

[http://www.jabber.com/](http://www.jabber.com/)  
[http://www.jabber.org/](http://www.jabber.org/)

---

<div class="post-metadata">

**Author:** ![hightechburrito](https://avatars.discourse-cdn.com/v4/letter/h/f6c823/32.png) [@hightechburrito](https://boards.straightdope.com/u/hightechburrito)\
**Post date:** [July 24, 2005, 6:38am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/9 "2005-07-24T06:38:56Z")

</div>

I use gaim, which can also connect to AIM, Yahoo, MSN, ICQ, and all other services that I can think of.

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [July 24, 2005, 3:13pm UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/10 "2005-07-24T15:13:39Z")

</div>

> [@hightechburrito](#):
>
> I use gaim, which can also connect to AIM, Yahoo, MSN, ICQ, and all other services that I can think of.

What are the security issues re IM esp w/ gaim?

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [July 24, 2005, 3:16pm UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/11 "2005-07-24T15:16:26Z")

</div>

> [@snailboy](#):
>
> You’ll be able to run your own server and can use transports to connect to other services…

This is beyond my needs.

I don’t even really anticipate needing encryption. I saw that it was mentioned by **jnglmassiv** and wondered. I mean, it’s cool and all, but I’m saying anything really worth eavesdropping on.

Mostly I"m interested in security concerns

---

<div class="post-metadata">

**Author:** ![hightechburrito](https://avatars.discourse-cdn.com/v4/letter/h/f6c823/32.png) [@hightechburrito](https://boards.straightdope.com/u/hightechburrito)\
**Post date:** [July 24, 2005, 8:18pm UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/12 "2005-07-24T20:18:57Z")

</div>

> [@PatriotX](#):
>
> What are the security issues re IM esp w/ gaim?

[http://gaim.sourceforge.net/security/](http://gaim.sourceforge.net/security/)

Here’s the page describing the various security issues that gaim has.

I’m a fan of it because it is very minimalistic in its UI, and also open-source, if you like that kind of thing.

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [July 24, 2005, 8:33pm UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/13 "2005-07-24T20:33:20Z")

</div>

> [@hightechburrito](#):
>
> [http://gaim.sourceforge.net/security/](http://gaim.sourceforge.net/security/)
> 
> Here’s the page describing the various security issues that gaim has.
> 
> I’m a fan of it because it is very minimalistic in its UI, and also open-source, if you like that kind of thing.

Is this sort of intercourse with the outside world protected the same way that web browsing is?

---

<div class="post-metadata">

**Author:** ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)\
**Post date:** [July 24, 2005, 8:50pm UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/14 "2005-07-24T20:50:50Z")

</div>

> [@hightechburrito](#):
>
> [http://gaim.sourceforge.net/security/](http://gaim.sourceforge.net/security/)
> 
> Here’s the page describing the various security issues that gaim has.
> 
> I’m a fan of it because it is very minimalistic in its UI, and also open-source, if you like that kind of thing.

The issues on that page don’t seem to be about the security issue the OP is concerned about, which is the privacy of the connection.

I like GAIM too, but I have no idea if it can encrypt a connection.

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [July 24, 2005, 11:58pm UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/15 "2005-07-24T23:58:59Z")

</div>

I just want to know if I’m opening up a door for crackers and script kiddies.  
And, if I am, how do I secure my machine so that I won’t get pwned by some fourteen year old.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [July 25, 2005, 1:47am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/16 "2005-07-25T01:47:28Z")

</div>

You will not get pwned by instant messaging. The worst that could happen is that you have a conversation with someone who uses words like “pwned.”

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [July 25, 2005, 2:49am UTC](https://boards.straightdope.com/t/sd-im-tutorial-please/313869/17 "2005-07-25T02:49:32Z")

</div>

> [@friedo](#):
>
> You will not get pwned by instant messaging. The worst that could happen is that you have a conversation with someone who uses words like  
> “pwned.”

I’ve taken the ususal, regular, reasonable precautions to secure my system (two firewalls- soft and hard, AV, anti-spyware, turned off unused services, activeX & java whitelists, intrusion prevention software). I’d hate to render that effort moot by creating an opening that I don’t know how to secure.

Are there any other security steps beyond the regular ones I should take?
