Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Back end-for-Front end: The most secure architecture for browser-based apps (fusionauth.io)
5 points by mooreds 8 days ago | hide | past | favorite | 1 comment
 help



the npm supply chain attacks were a massive wakeup call. the fact that we normalized storing sensitive tokens in localstorage for the last decade is wild.

moving to a bff pattern isnt just about hiding tokens, its about reducing the client attack surface entirely. shifting api orchestration and sanitization to edge proxies makes so much more sense. the browser should just be a dumb terminal rendering ui, not a secure vault managing state and credentials




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: