logoalt Hacker News

Perz1valyesterday at 4:38 PM1 replyview on HN

Why? The api has to be secure. Mobile os keeps the app safe. Where is the attack surface?


Replies

nicceyesterday at 4:43 PM

You don’t believe how often people leave secrets in the app or use webviews and iframes badly, misconfigure OAuth in client side and so on. There are many issues where secure API does not help.