nus-cs2113-AY1920S2 / pe-dev-response

0 stars 0 forks source link

Security Issues for sensitive information in Hospital Management #153

Open nus-pe-bot opened 4 years ago

nus-pe-bot commented 4 years ago

As a hospital management system that deals with confidential information such as appointments date, time, and address of the patients, such data should be kept in private or at the very least encoded and not stored in plaintext so that leakage of these information should not be as simple as looking into the text file.


[original: nus-cs2113-AY1920S2/pe-interim#160]

yukilite commented 4 years ago

Team's Response

The team views this bug as a very valid one, however, as mentioned in our demo video and presentations given, this feature has been decided not to be part of current version 2.1 as it exceeds the scope of work and would require more time to implement. Furthermore, with tools like JavaSnoop, even our encrypted files would not be protected enough. https://securitycafe.ro/2014/12/19/how-to-intercept-traffic-from-java-applications/

Duplicate status (if any):

--