Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Password protection seems to be weak #6012

Open
nus-se-script opened this issue Nov 17, 2023 · 1 comment
Open

Password protection seems to be weak #6012

nus-se-script opened this issue Nov 17, 2023 · 1 comment

Comments

@nus-se-script
Copy link

nus-se-script commented Nov 17, 2023

Unhashed passwords can be easily retrieved and data is not encrypted either. It appears that the feature may need further polishment.


[original: nus-cs2103-AY2324S1/pe-interim#5997] [original labels: severity.Low type.FeatureFlaw]
@aarontxz
Copy link

aarontxz commented Nov 18, 2023

Team's Response

The purpose of the password acts as a layer of extra protection from entering InsuraHub, it is rare but admittingly
not impossible for other users to know where to look for the password. However, If the hacker is able to actually find the folder for the password then they would be able to find the JSON file for the information stored in InsuraHub anyways and be able to look at the content. In order to really fully protect the content of the information of the clients stored in InsuraHub is beyond the scope of just implementing password protection. Will need to find a way to hide the addressbook.json file as well.

Duplicate status (if any):

--

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants