Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can't upvote this enough. If you want to protect content, make the checks server-side. Security must be server-side first, no exceptions. Doing anything else is asking for tech savy people with debuggers (or "view source" in this case) working around it.

You can get into a race with your users renaming javascript variables or changing CSS classes, or implementing the most advanced javascript obfuscator that exists today, but this is a waste of time.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: