logoalt Hacker News

nicceyesterday at 4:14 PM4 repliesview on HN

> You just install it on your phone and use the app.

Some people on the cybersecurity side are starting to cry....


Replies

user43928yesterday at 4:18 PM

I have been getting these comments often here, including concerns about my non existent backend's security.

Last time, when I pointed out that the attack surface for mobile apps is typically very small, some users started to talk about zero day vulnerabilities in the OS's media handling, as if it was a concern for my app implementation.

I found the concerns again wildly overblown.

show 1 reply
chisyesterday at 4:40 PM

Are there cybersecurity concerns in the frontend? I would have thought you have to assume the client is untrusted and only do security work on the backend

show 2 replies
Culonavirusyesterday at 4:40 PM

They better start a proper hydration regime because they'll be crying a lot.

Perz1valyesterday at 4:38 PM

Why? The api has to be secure. Mobile os keeps the app safe. Where is the attack surface?

show 1 reply