Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.

To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.

 help



If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.

Bad actors have been social engineering passwords for years even before a single line of JS was written. Restricting the backend is a way of heavily reducing the attack surface. The expansion of hardware access to browsers is the largest scam enabler of the 21st century. The only reason it's happening in the long term is because companies like Google (DoubleClick) wish to use hardware attestation to tie people to hardware for advertisement purposes, and that requires complete vertical attestation.

We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again.

I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: