Pidgin: The Universal Chat Client
pidgin.im
pidgin.im
There were add-ons for message styles, contact list styles, dock icons, sounds, and more.
It's really sad that we've lost the ability to connect to so many of the services we use with third party clients. Instead, I now have FB Messenger, WhatsApp, iMessage, Discord, and Signal all running and taking up space in my dock.
Instead, the "interoperability" we get today is the result of multibillion dollar corporations making partnerships with each other, while independent developers are locked out.
As an example, Google gets access to streaming services APIs and catalogs in order to fill their Chromecast and AndroidTV products' menus with movies and shows. Meanwhile, Kodi has to rely on hacks to do something similar, it doesn't work with all streaming services, and there might not be feature parity.
There is no way to regulate an equivalent level of service and features be provided on a platform you don't control.
So between modded iChat and Adium, on Mac OS you had the choice between minimal and kitchen-sink style IM clients, both of which were free and had no ads. OS X had also hit peak refinement around that time, between 10.2 and 10.6. It was a brief but golden age for Mac users with a lot of IM friends.
At least we don’t have IE6 any more, so it’s a fair trade.
You know it was thinking about that the other day, and i came to the conclusion that we're back in 1970, our powerful computers are mostly used as Terminals aka Browser connected to powerful monolithic service providers aka Mainframe.
That means Ken Olsen was right and yes even Larry Ellison.
It looks like MSN Messenger didn't require a plugin, it worked because it was XMPP which iChat/Messages supported out of the box, up until High Sierra I think.
[0]: https://web.archive.org/web/20121118061309/http://cocoon.dri...
Then I had to run "killall imagent" in Terminal for it to work properly. Logged right into OFTC in Messages on OS X 10.9 Mavericks.
So... plugins were supported, but it may well be that the only plugin ever made was literally the example Apple released? :(
That said, I've switched back to terminal-based IRC clients, so I haven't run either Pidgin or Adium in probably 10 years. It's sad. Both were really good tools.
"Old-school" IM networks like AIM were simple to work with from a client perspective -- you connect to the network, you send and receive messages, and that's it. There was no real support for server-side message history, multiple clients, mobile clients, or offline messaging, so third-party clients often just implemented their own local history instead.
Newer IM networks like Telegram are usually designed from a mobile-first perspective -- the Telegram client protocol is designed around the concept that the server has a definitive view of history across all chats, and the client synchronizes portions of that history to local storage to display it. It certainly isn't impossible to adapt this to a design like libpurple/Adium/etc, but it's an awkward fit and is likely to fail to support features which don't fit into that model, like chat messages being edited or deleted by the other party in the conversation.
https://www.adium.im/screenshots/images/overview.jpg
The area inside the chat window is HTML rendered via WebKit and you can change the theme easily. The Contacts list is also HTML in the middle so that's all theme-able too.
https://images.six.betanews.com/screenshots/1110403338-1.jpg
Here's a Contacts list that's more compact and a chat window without the top toolbar.
https://adium.im/screenshots/images/overvieworange.jpg
Here's a more radical theming where they've gotten rid of the window around the contact list so it's floating.
If you go through the Adium Xtras, you can see all sorts of chat (https://www.adiumxtras.com/index.php?a=search&cat_id=5&sort=...), contact list (https://www.adiumxtras.com/index.php?a=cats&cat_id=4&sort=do...), and other ways of styling Adium.
KDE's Kopete (and after that, the now defunct KDE Telepathy) could that too. Maybe GNOME's Empathy client could that too. I agree all of that was really cool.
I sorely miss those all-in-one messengers completely integrated to the desktop.
(I started that project decades ago and still grateful to it, as it was the start of my career in tech)
On top of that, Adium is/was also incredibly themable. You could use independent Adium Xtra addons for both your contact list and your chats. I had a theme so that all messages just appeared sequentially like so:
[Hello][Hello][What's Up?][Etc.]
where mine were red and the person I was talking to was in blue (or vice versa, it's been awhile). You could see so many messages at once.
Adium is the application I miss most from MacOS, although I imagine I'd still miss it even if I were still using a Mac. With the exception of the addition of multi-device continuous chat history, we've really regressed in the category of instant messaging since the days of multi-chat clients.
I still have it installed. It was very useful in the PowerPC era.
Pidgin still is useful: it talks to a whole bunch of services that are still alive... IRC, Telegram, Skype, Google Hangouts, Slack, Rocket.chat, XMPP, ICQ, etc.
Sadly Adium can't use Pidgin or Libpurple plugins directly. This severely reduces its usefulness today.
https://en.wikipedia.org/wiki/Pidgin_(software)#Naming_dispu...
But naim was such a nice client before finch was really a thing.
(No, I never did anything more exciting than have private conversations with individuals that might provoke this, and it tended to happen to swathes of people using third-party clients at once.)
Weird, I used Trillian on Windows and Adium on Mac exclusively for years, from 2004 through some time in the mid 2010s when all of my old AIM and ICQ contacts had moved on to Steam and then later Discord. Never had any issues other than the usual stuff where file transfers and the like weren't reliable with third party clients.
They did eventually seem to back off though, as the sibling commenter said, because after a certain point I stopped randomly getting banned ever again from then until the end of AIM as a service.
Why don’t you use a matrix client with bridges? I use telegram, WhatsApp and signal over Element. The bridges are not as great as the individual clients, but it’s definitely miles ahead of using five messaging apps.
It seems like a puppeted bridge requires me to send the messages to the Matrix server who then has a login to my FB Messenger to read/write messages there. I'm not going to run my own Matrix server so that requires me to trust a Matrix server with access to my Facebook.
Yes, downloaded apps can be malware, but it's a lot more easily discoverable. One can use tools like Wireshark to confirm where data is going. If apps are open source, one can see the source code and even compile one's self. Even if you don't trust the maintainer who is compiling, you still have a good idea that they're not sending all your messages to them because someone is more likely to notice the binary doing that (via tools like Wireshark). When software is just run on a server that the public doesn't have access to, who knows what is happening. Yes, running on your machine doesn't mean everything is safe, but there's some level of inspection you can do of what is going on.
I don't want to sound too down on Matrix, but it feels a bit off to me. It feels like people who want a decentralized future...where everyone is centralized into a small number of servers who can run a dozen or so Docker containers and such. Maybe that's the way the world needs to be given where we're at, but I just miss having a client that could login to multiple chat services.
If these puppeted bridges can exist, why can't my client just puppet directly? Why send the message to the matrix server for the matrix server to then call the Facebook API? I remember the days of AIM breaking the OSCAR protocol and libpurple/libgaim needing to catch up so I understand that pushing out an update to client software might mean some extra hiccups in the connectivity. Still, it feels like the servers might not be able to update their software much faster than I am able to. Maybe App Store approvals holding up updates is the issue? Is the issue that app stores could block a Matrix + bridges client since it's clearly trying to access services that don't want third-party access, but a Matrix client that's just talking to a Metrix server is fine - and then the "infraction" is on a server that the App Store doesn't get a say over? (I'm not saying that I think it should be disallowed, but I could see companies disliking it)
Is the issue that people want to write these bridges in JavaScript, Python, and other languages which are all fine if you're running a bunch of Docker containers on a server, but might not work so well if you're trying to create a desktop or mobile app?
Why can Matrix bridge these things, but we can't have a libpurple that works as well as these bridges? Or maybe I just haven't used libpurple in a long time and it's actually still good and I should re-try it.
It feels like Matrix wants to be a decentralizing force, but then the bridges force me to centralize my messaging through one of their servers. Again, maybe that's the way it needs to be for reasons, but it just doesn't feel like what I've been looking for.
I'd be very curious to know if the work on P2P Matrix servers is going to include some level of support for client-side bridges?
I know the P2P work and bridging aren't quite the same thing, but it seems like the two are vaguely related: if you've got a bridge running, I suspect that would have a lot of the same concerns as running a Matrix server locally. And I get that for some clients like iMessage, your bridge has to be running on a Mac, but that isn't the case for most other messaging platforms, is it?
You do need your own homeserver, but for me I run a homeserver just for the bridges, and have my main account on a third-party homeserver. This way at least my native matrix chats (which are far more important to me) don't depend on my home server being online.
I would subscribe to hosted bridges fairly quickly if they were a reasonable price. Maybe $1/month per service? Obviously there is risk here because you are trusting someone with access to your account but to me it is probably worth it. There is https://www.beeper.com/ but you need to move your primary account to their service, which is just too much disruption and lock-in for me.
TL;DR I agree, self-hosting is a bit much. I'd love to be able to pay for it though.
I thought about hosting that service myself but I wouldn't want to run a service that is both against the dependencies' ToS and is playing cat-and-mouse with their attempts to shake you off. Too much excitement for too little reward.
This is kind of how it's done today but also not exactly. The bridge (which is what has access to your account and messages) is its own process and could in principle be run on a separate host (like your own device for a single-user bridge). However, most (all?) public homeservers access for connecting puppeting bridges (meaning "virtual" Matrix identities for each identity on the bridged network, rather than just having a single "botuser" for all conversations through the bridge) and the API for access is rather coarse.
Also, last time I checked most bridges do not implement E2EE and signing properly, which means that the homeserver it connects to both gets read-access to bridged messages and can impersonate. This is mostly a matter of implementation not being prioritized highly in bridge projects. Currently that can be worked around to get E2EE even for cleartext bridges by running a protocol-specific proxy called pantalaimon which sits between the bridge and the homeserver and terminates encryption.
There are tradeoffs that can be made, which can be seen in the different alternatives for IRC bridges. For example, matterbridge is more of a typical bot (supporting loads of protocols!) and can be run towards a remote homeserver as a normal user.
https://github.com/hifi/heisenbridge#comparison
https://github.com/42wim/matterbridge/wiki/Section-Matrix-%2...
I am certain we will see better interfaces to allow people to run local personal IM bridges without the requirements and overhead involved today. Thinking out loud here, I could imagine a minimal per-user homeserver baked into a client, that only does bridging for that user and only federates with the homeserver of that users' accounts. That could tick all the boxes even before P2P matrix I think.
The benefit of this approach over pidgin or a purely local single-user homeserver (which are viable and it sounds like you kind of want) would be all the conveniences people have gotten used to with centralized platforms... E.g. if you have the bridged rooms on a remote homeserver, seamless retention of histories across all your devices, without needing to be simultaneously online. But you'd also only need to keep credentials local, and message content in cleartext would only ever be acessible on your client(s).
Matrix and WhatsApp are both durable with regards to users so this issue probably isn't relevant.
Personally I find the biggest problem with puppeting is the impedance mismatches. For example if reactions aren't bridged it can be easy to miss stuff. This depends on the bridge used.
I ask because I’d like to set up Matrix bridges like that locally, but if I have to create a Discord bot account or fish out an API key then that’s asking a bit much.
EDIT: If you can do without Discord DMs, you don't even need to run the bridge yourself or supply discord credentials - just invite a bot to a discord server if it isn't already
(Obviously if you're concerned of privacy you wouldn't be having those conversations on Discord in the first place)
I used to use Pidgin with OTR[0] for e2e encrypted chat over google & facebook. It was pretty fantastic, messages were inaccessible to facebook and google even with a court order so I didn't need to trust them.
Also used Finch for a bit[1]. For a time I had a pretty great setup on a local VM (running the PHP app I was working on): one tmux tab with work, another with a pane for finch (for chatting on FB & google), a pane for IRC, and a third pane for ttytter[2], the amazing twitter CLI. If someone nontechnical walked by they'd see a terminal and it looked exactly like I was working, not chatting on IRC & facebook, and looking at twitter :D
0: https://otr.cypherpunks.ca/ 1: https://www.systutorials.com/docs/linux/man/1-finch/ 2: https://www.floodgap.com/software/ttytter/
BTW, OTRv3 has pretty poor security these days, there is OTRv4 but it isn't ready for users yet.
There's github issue[1] for it and no resolution, except a weird python script hack to do 2 factor which may or may not be reliable.
1. IRC
2. IRC, Yahoo messenger, Aol Instant Messenger, MSN Messenger (mostly based on your ISP in the early days)
3. All + Skype (video!! wow!) + Google messenger. *This was when pidgin was invaluable* (there was also some Duck app for macOS?)
4. Skype started charging and since everyone was on Facebook, everyone moved to Facebook messenger. Text messages also became free, so for instant comms you just texted people.
5. Slowly FB Messenger took precedence over even text messages as data plans became better
6. A decade passes...
7. The exodus off of Facebook begins and Discord takes over as a way to talk to your group of friends.
The webcam features on MSN messenger landed at the same time as broadband internet became widespread in my country, when I was at school, so everyone was in on the novelty.
Some of it is certainly the cynicism of age and work life, but I'm certain something has been lost since then. The UI, the nudges, the winks, the games, the chaotic friend lists were all magic in a way that FB, WA, Slack, Teams, Discord, et al aren't.
Getting home and seeing a few friends on discord and joining in has always been a magic experience for me.
You are thinking of Adium (https://adium.im). I believe it was a port of pidgin/libpurple to cocoa/aqua (or whatever the macOS gui framework was back then).
1. IRC
2. ICQ
3. MSN
4. IRC (again)
5. Skype and Facebook
6. WhatsApp
7. Facebook again
8. Still Facebook (very sticky)
9. IRC + Slack (some communities) + Discord (some communities) + Facebook/Whatsapp + Signal + Telegram + Matrix + Zulip
Yeah, I think we need a new libpurple.
I used to be a dev on the team, and we had our accounts banned all the time. Some of the IM services didn't mind us being there (MSN seemed more than fine with it, and we reportedly had fans within the team there, though future protocol versions made it harder for us to figure out).
Yahoo wanted us off and did everything they could to keep us from connecting. Changing auth schemes to increasingly-elaborate obfuscated methods, at one point throwing pages of what looked like equations at us.
AIM would have been fine with us if we had used TOC (their open source protocol), but OSCAR is where all the features were at. They didn't outright ban clients, but my understanding is that their lawyers were involved at one point (though I think mainly due to the name "GAIM").
But you're right, they are removing third-party clients more. And fewer protocols are unencrypted plain text, which makes it harder as well. Still, work continues.
I remember using talk about the same time, but telnet ones had more edge in UX side.
Before that I used first Trillian, then Pidgin. Then seeking persistence across clients I started using bitlbee to access everything through IRC, but that really sucked for media-heavy things like Telegram. My current setup of my own Matrix homeserver + bridges has been working great and feels way more liberating than using 6 different apps.
I don't use Discord all that much and I just bridge a few specific rooms I'm interested in, but I think you can bridge entire servers at once as well.
Also, I use this for personal messages as well as group chats. The people I interact with don't even know I am not using the native client.
libpurple still exists and even has plugins for a lot of the protocols you mention, so no need to move away from it.
1. IRC
Today: IRC + Matrix.
I believe you're referring to Adium [1].
It's funny. Having a similar trajectory of chat clients, I'd say my migration in my teens was dictated by "which service were the girls I wanted to talk to using?" In my 20s it was "what preserved my session as I ran around town and logged into various dumb terminals" until finally "what worked best on mobile."
Now that I'm married in my 40s, it's "which service are the guys I want to talk to using?"
My journey was:
1. ICQ, because my gamer friends used it.
2. Added IRC, while it felt already outdated, somehow a bunch of my Japan-nerd friends used it.
3. Added AIM, YIM, MSN, because girls and my parents used them.
4. Switched to Trillian, because it wasn't managable otherwise.
5. Everyone moved to Facebook Messenger.
6. Everyone moved to WhatsApp
7. Now and then some friends switch to Signal, Telegram, or another "secure," alternative to WhatsApp.
8. Started working remote and everything is Slack and Zoom.
9. Dabbled in Web3/crypto and everything is Discord
2. ICQ
3. Trillian & QIP, mostly to connect to ICQ
4. Facebook chat
5. Google Hangouts, Allo, gmail chat
6. Back to Facebook Messenger because all my contacts use it, Slack for work
1. Yahoo messenger (2001/2 - First internet experience)
2. Yahoo messenger + Text (2003/4)
3. Text + Skype (2006/7)
4. Whatsapp + FB Messenger + Skype (2010)
5. Whatsapp/iMessage + Instagram (2016/17)
For work it was Slack and then MS Teams (again sigh).
Interestingly, some actors are willing to buy exploits against Pidgin users for sums higher than what the authors have made out of it.[0]
[0] https://therecord.media/zerodium-acquiring-zero-days-in-pidg...
If someone want to help them :
Thanks to Pidgin Portable, simply copied the zipped folder to the USB flashdisk, visit any computer lab then I can YM'ed my friends. Good old days :)
It would be great to see an integrated chat app.
For me Telegram is the king of today's UI, hence, it would be amazing to see them integrating Skype (still using it) and whatsapp. Line and wechat integration would also be super.
This new European law that is about being passed gives me hope.
P.S. I have even written a plugin for - quickpurple
I also used the similarly named but jabber only Gajim.
Good times :)
Internally at least, we called it "Gaim's An Instant Messenger". I'm not sure if we formalized that or not. It's been too long.
And then to fully move away from that branding situation, it was renamed to Pidgin. This was mid-2000s, after I moved away from the project, so I don't have any insight into the name change beyond the history.
Good times for sure!
Nowadays I use Zukitre, Tango and Go fonts to make something close-ish.
>OTR uses a combination of AES symmetric-key algorithm with 128 bits key length, the Diffie–Hellman key exchange with 1536 bits group size, and the SHA-1 hash function.
What specifically is wrong with any of that?
0: https://crypto.stackexchange.com/questions/75880/what-is-a-m...
1: https://csrc.nist.gov/publications/detail/sp/800-57-part-1/r...
2: https://weberblog.net/site-to-site-vpns-with-diffie-hellman-...
1. Does that not mean that NIST considers AES-128 secure?
2. Who exactly thinks that 1536 bit DH is breakable by nation states? The closest I have heard is 1024 bit DH. Note that we are talking messaging here where a break gets you one users messages.
3. Exactly what sort of attack would be possible against OTR using a practical SHA-1 collision?
https://pidgin.im/plugins/ https://github.com/EionRobb/purple-discord
Its about the same as any other Pidgin protocol (no audio AFAICT), with some support for some of the features of Discord like reactions. It gets updates for new features sometimes. The author has written a lot of different libpurple plugins and is quite busy though.
Note I've heard you can get banned from Discord for not using the official client.
Though, honestly, now that most people I know are on Signal, the only other messenger platform I care about is Slack, and given that's just for work, I'm not sure I care anymore...
Thanks for what you did, no thanks for repeat business.
I don't think I said anything untrue; only hurtful.