MSN Messenger Exposes Contact List via Registry?
While checking out some MSN Messenger registry entries, I found out this:
The entries in HKEY_CURRENT_USER\Software\Microsoft\MessengerService\ListCache\MSN Messenger Service are mostly of the form Allownn, Contactnn, Reversenn and a few other entries (including a rather ominous MsgPrivacy entry with a value of 00 00 00 00 on my machine :-)).
The problem is, contact info for every messenger login made by that Windows username seems to be stored over here. While much of the data is obscured (or seems to be (haven’t checked yet)), the email address of each contact is stored in the clear . Interesting thing to remember the next time you use MSN Messenger at a public computer, or on someone else’s machine — your contact list may just have become public knowledge.
Is this a known issue, by any chance? Can anyone else comment on this? I’ve checked this out on MSN Messenger 3.6.0025 on Windows 2000 SP1.

