203
Malicious Plugin in Pidgin (Chat Application)
(pidgin.im)
All about open source! Feel free to ask questions, and share news, and interesting stuff!
Community icon from opensource.org, but we are not affiliated with them.
Was the plugin open source?
Edit: looks like it wasn't and the incident has prompted more more transparency. Good stuff.
Unless the pidgin team are compiling the binaries themselves, this doesn't really fix much.
Ideally we need reproducible builds.
Its really not hard for them to compile themselves. This is what most package managers do