The well-known instant messaging services authenticate in a secure way. See "Threats to Instant Messaging"

Ron hath wroth:

Oh. All of them use a challenge-response mechanism, where the actual password is not sent. Instead a hash code derived from the combination of the password and some random rubbish is sent. It's quite safe. At one time, it was possible to crack the AIM password from a capture file because they used a really crude random number generator:

for various AIM cracking tools.

