3 ms·
The title should probably read "Why relying only on client-side verification is bad". I don't think the author is suggesting that doing client-side verification
by mopoke 15y ago
The title should probably read "Why relying only on client-side verification is bad".
I don't think the author is suggesting that doing client-side verification is a bad thing in itself.
- frobozz 15y agoThat's probably what's in the authors mind, but not what's in the article. The author is not just suggesting that client side verification is bad in itself, but stating that position quite precisely. "Why client-side verification is bad.." (rather than the title you suggest) "to my surprise discovered that it did client-side verification of the words" (rather than "...that it didn't do server side verification") However, in support of your position; in his opening paragraph, he does say "you can't rely on it to do authentication", rather than "you shouldn't use it to do authentication".
- nhebb 15y agoThe author wrote "A common mistake is the web site that relies on javascript". I think the key word is "rely". You either rely on something or you don't. It's not a partial measure.
- mopoke 15y agoAuthor's comment on his site: "It's not wrong to use client-side methods to do initial validation, but it's wrong to trust that validation on the server side."
- frobozz 15y agoThe comment you cite (which is new since my comment above) confirms my point that it might be what he thinks, but not what he says. The comment continues: "I probably wasn't very clear on my feelings though."