What's the best way to do authentication in modern applications
freediver
44 points
15 comments
July 11, 2026
Related Discussions
Found 5 related stories in 52.7ms across 5,215 title embeddings via pgvector HNSW
- Show HN: Anonymous age verification with passkey-powered encryption mikeysight · 13 pts · August 19, 2026 · 48% similar
- Logging in Was Never Supposed to Be This Complicated bookofjoe · 14 pts · August 26, 2026 · 45% similar
- I used AWS cognito for a startup. I wouldn't do it again speckx · 173 pts · August 28, 2026 · 44% similar
- Show HN: Sesame - a local-first, open-source password manager d0mkaaa · 49 pts · August 28, 2026 · 43% similar
- Show HN: macOS data protection keychain for Electron apps biwills · 23 pts · August 18, 2026 · 43% similar
Discussion Highlights (7 comments)
padjo
> So the boring 2005 design wins. As an old guy reading this I had a lot of wtf moments during the setup. Then I laughed pretty hard when we eventually got to this line. Like there's a reason we invented cookies and all mature web frameworks use them for auth.
haburka
I struggle to underdress why this slop content gets to the front page. It’s likely close to 100% ai made. I really want this era of AI generated writing that reads so poorly to end. Or at least society should be ashamed of publishing this content.
stavros
Don't use JWTs for session auth, and don't outsource your articles to Claude.
homebrewer
Cookies can be encrypted and signed and contain whatever information you want, not just some random token that has to be looked up in the database to be actually useful. This is what aspnet core does by default if you enable cookie-based authentication. Gives you the best of both worlds.
StrauXX
localStorage is very much fine and arguably superior to cookies for authentication tokens. First of all, once you have achieved JS execution on a target origin, you can send requests, open up malicious "login" prompts and generally control everything the user sees and does. The article mentions this, but plays it down with no good arguments. Much more importantly however, is that the cookie standards are a mess! The complexity of cookie default behaviour, their flags, scopes, differences in their SOP (cookies ignore ports for example, so https://example.com:443 and https://example.com:8443 share their cookies) are huge. Research papers have been written in this. And don't even get started on differentials between browsing engines. This huge complexity of cookies opens up a whole class of authentication attacks where bad (or just weirdly) configured cookies can be stolen cross origin. localStorage on the other hand is practically impossible to get wrong.
Lucasoato
If I use short-lived JWTs and localstorage, am I such a bad person? Are you truly increasing the blast radius? Is there someone in another part of the world that would like hacking you only if you’re not using httpOnly cookies, happy to know that you used localstorage?
yako21000
smells a bit like AI, or AI helped article. Still, some points are explained quite clearly. Knew most of it, but still, some parts where a good reminder. I would always try to use bullet prooven framworks and NOT reinvent the wheel. Best way to go in 2026. There is simply too much angles of attack and knowing myself I would miss something.