logoalt Hacker News

freeplayyesterday at 6:03 PM2 repliesview on HN

Nailed it. Assume your client is compromised and/or malicious regardless of how it was built.


Replies

Matumiotoday at 6:42 AM

If your clients are compromised then what's even the point of backend security. Users will login and do legitimate actions while their compromised client does whatever behind their back, while still looking normal. And the backend can't tell the difference.

asdfsa32today at 1:37 AM

This is the most naive take on security ever. For the backend, you assume your client is compromised, but you still don't want to allow your client to be compromised.