Hacker News new | ask | show | jobs
by 3np 768 days ago
Why need a login/account at all? What core functionality actually requires a server to be involved, from your point of view?

What we've seen again and again is apparently well-intended founders who say something like this.

Fast-forward a few years and for whatever reasons, the company transitions ownership, and the founder and original team are out of the decision-making loop. After which the already-gathered data gets increasingly exploited and the gathering of data from users expands, contrary to promises and intents of the founder.

By being stricter in your original implementation and application architecture as can be observed externally and from the point of view of the client, you make it harder to for silently break user trust without a way for users to detect it.