> You just install it on your phone and use the app.
Some people on the cybersecurity side are starting to cry....
I have been getting these comments often here, including concerns about my non existent backend's security.
Last time, when I pointed out that the attack surface for mobile apps is typically very small, some users started to talk about zero day vulnerabilities in the OS's media handling, as if it was a concern for my app implementation.
I found the concerns again wildly overblown.
They better start a proper hydration regime because they'll be crying a lot.
Why? The api has to be secure. Mobile os keeps the app safe. Where is the attack surface?
Are there cybersecurity concerns in the frontend? I would have thought you have to assume the client is untrusted and only do security work on the backend