I would hope that somewhere at Google there is a policy that says you can't do anti-fraud and security checks in frontend only...