Why client-side verification is bad
blog.dryft.net
blog.dryft.net
But think about it for a moment. Assuming the ideal product would have both client + server verification, it's clearly less work to only do client-side verification. The product can be released quicker.
Maybe they intentionally forgo the server-side verification code until they actually get cheaters. Then they implement it before it begins to hurt their bottom line.
Because what if the game was an utter failure, and never got any users? How glad would you be that you spent all that time writing the server checks for every game action?
Client-side verification is Good, it saves bandwidth and reduces annoyance to the user. Client-side verification without also checking on the server is bad.
Given the example of a word game to be played on a phone. I would argue that client-side verification of valid words is vital.
"Why client-side verification is bad.."
(rather than the title you suggest)
"to my surprise discovered that it did client-side verification of the words"
(rather than "...that it didn't do server side verification")
However, in support of your position; in his opening paragraph, he does say "you can't rely on it to do authentication", rather than "you shouldn't use it to do authentication".
"It's not wrong to use client-side methods to do initial validation, but it's wrong to trust that validation on the server side."
"I probably wasn't very clear on my feelings though."
In more competitive games like Starcraft you can't trust the client (maphack for example).
A friend of mine (a student) asked me if it was possible to create macros in a browser to help go faster, and since I was bored and lack morals in this area... just took a look through the JS, and fifteen minutes later and an injection for him to paste into the URL bar and skip through each stage, making the game think he had completed it, as fast or slow as he wanted. So he got a free iPhone.
are there any frameworks that let you re-use the same verification code on both client and server? i'm imagining some way to decouple the validation from the presentation and then run the validation part on both sides - i don't see why this wouldn't be possible with something like Node.js.
related, i guess that some frameworks (particularly ajax) support duplicating validation on client and server by automatically generating (different) client (javascript) and server-side code (python/ruby/java/...) from simple specifications (eg regexps). does anyone have good experiences with any of these?
I'm more curious as to how you go about circumventing this. I would imagine that it probably IS very hard.