logoalt Hacker News

user43928today at 7:32 AM0 repliesview on HN

I was not talking about a backend service here.

Regarding clickable vulnerabilities in messaging apps, are you referring to the exploits that were enabled by vulnerabilities in system media parser and browser components?

This has essentially no practical relevance to app implementation.

What we are left with is not corrupting user data, particularly during migrations on app updates.

Compared to the attack surface of a backend service that handles user data, this is trivial.

We agree that the delicate work is presentation and interactions working well on device.

In my opinion this is best supported by extensive manual QA and user testing, rather than code review. This is what unlocks tremendous productivity for mobile app development with AI.