← Back to context

Comment by freeplay

20 hours ago

Nailed it. Assume your client is compromised and/or malicious regardless of how it was built.

If your clients are compromised then what's even the point of backend security. Users will login and do legitimate actions while their compromised client does whatever behind their back, while still looking normal. And the backend can't tell the difference.

This is the most naive take on security ever. For the backend, you assume your client is compromised, but you still don't want to allow your client to be compromised.