Skip to content

Comment on Security on an untrusted client - locking down a javascript libraryparent

Comments

You can never trust a client you don't have absolute control of. Unless you have such control, you can only assume the client is compromised.

I understand that your scenario calls for trust where none is warranted†. That's risk. And your mitigation is to be clear how you handle a compromise (likelyhood).

† As does probably 99.9% of sites on the Internet.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.