Is there someone in another part of the world that would like hacking you only if you’re not using httpOnly cookies, happy to know that you used localstorage?
What's the best way to do authentication in modern applications
11–20 of 22 posts
Re: What's the best way to do authentication in modern applications
#12I struggle to underdress why this slop content gets to the front page. It’s likely close to 100% ai made. I really want this era of AI generated writing that reads so poorly to end. Or at least society should be ashamed of publishing this content.
Re: What's the best way to do authentication in modern applications
#13Re: What's the best way to do authentication in modern applications
#14I struggle to underdress why this slop content gets to the front page. It’s likely close to 100% ai made. I really want this era of AI generated writing that reads so poorly to end. Or at least society should be ashamed of publishing this content.
Re: What's the best way to do authentication in modern applications
#15I struggle to underdress why this slop content gets to the front page. It’s likely close to 100% ai made. I really want this era of AI generated writing that reads so poorly to end. Or at least society should be ashamed of publishing this content.
Re: What's the best way to do authentication in modern applications
#16localStorage is very much fine and arguably superior to cookies for authentication tokens. First of all, once you have achieved JS execution on a target origin, you can send requests, open up malicious "login" prompts and generally control everything the user sees and does. The article mentions this, but plays it down with no good arguments. Much more importantly however, is that the cookie standards are a mess! The…
But they're still the superior choice for authN on the web, because if you want to, you CAN configure cookies to be secure. Yes, attackers can ride the session, but it's dependent on the user being on the tab and you being able to consistently execute JS. Client-side compromise (ie attacker controls the entire browser) is not feasible to defend against anyway.
The main issue with JWT+localStorage is you can actually execute one-off JS, exfiltrate the token and come back later. I've _never_ seen a well-executed JWT+localStorage implementation in 10 or so years, because teams inevitably realise they can't reliably revoke sessions (another advantage of cookies) and then start giving out long-lived access tokens but adding them to the database. Or some variation of that.
Re: What's the best way to do authentication in modern applications
#17smells a bit like AI, or AI helped article. Still, some points are explained quite clearly. Knew most of it, but still, some parts where a good reminder. I would always try to use bullet prooven framworks and NOT reinvent the wheel. Best way to go in 2026. There is simply too much angles of attack and knowing myself I would miss something.
My experience with "AI" is that if you ask the right questions in the right way (and give it access to accurate information to build it's answers from) it's actually really good at explaining things "quite clearly".
Re: What's the best way to do authentication in modern applications
#18localStorage is very much fine and arguably superior to cookies for authentication tokens. First of all, once you have achieved JS execution on a target origin, you can send requests, open up malicious "login" prompts and generally control everything the user sees and does. The article mentions this, but plays it down with no good arguments. Much more importantly however, is that the cookie standards are a mess! The…
Re: What's the best way to do authentication in modern applications
#19localStorage is very much fine and arguably superior to cookies for authentication tokens. First of all, once you have achieved JS execution on a target origin, you can send requests, open up malicious "login" prompts and generally control everything the user sees and does. The article mentions this, but plays it down with no good arguments. Much more importantly however, is that the cookie standards are a mess! The…
localStorage is not sent to the server when you request a document. So now you threw out the ability to do server-side rendering. This is only fine if you've got a application that always requires authentication, otherwise you risk server vs client mismatch, needless roundtrips, and DOM rewrites.
Re: What's the best way to do authentication in modern applications
#20smells a bit like AI, or AI helped article. Still, some points are explained quite clearly. Knew most of it, but still, some parts where a good reminder. I would always try to use bullet prooven framworks and NOT reinvent the wheel. Best way to go in 2026. There is simply too much angles of attack and knowing myself I would miss something.
> "Still, some points are explained quite clearly." My experience with "AI" is that if you ask the right questions in the right way (and give it access to accurate information to build it's answers from) it's actually really good at explaining things "quite clearly".