nus-cs2103-AY2425S1 / pe-dev-response

0 stars 0 forks source link

Mistakenly changing/corrupting the password.txt file will mean that you can no longer enter the application #961

Open nus-pe-bot opened 2 weeks ago

nus-pe-bot commented 2 weeks ago

Screenshot 2024-11-15 at 4.41.22 PM.png

Screenshot 2024-11-15 at 4.43.17 PM.png

Accidentally corrupting/editing the password.txt file unintentionally would be disastrous as now the user need to reset all the data inside VBook. This means that the user will lose all his/her data.


[original: nus-cs2103-AY2425S1/pe-interim#1339] [original labels: severity.Medium type.FeatureFlaw]

anselmlong commented 2 weeks ago

Team's Response

Hi, thank you for your feedback and for raising this concern!

While it might initially seem like a flaw, this behaviour is a deliberate part of our security features and aligns with best practices for applications prioritising user data privacy.

1. The Security-User Experience Trade-Off

2. Risk Mitigation: User Warnings

Screenshot 2024-11-18 at 4.06.31 PM.png

3. The Realistic Likelihood of Tampering

4. Conclusion: Security Takes Priority

We hope this clarifies why this behaviour is a feature and not a bug. Thank you!

Duplicate status (if any):

--