This presentation reviews the most common client-side security issues and how to avoid them. Taking lessons learned from building a web-based OS and app ecosystem, we’ll look at the underlying causes of front-end security issues. We’ll examine strengths and weakness of common application frameworks and introduce tools and techniques for detecting, correcting and avoiding security issues in the first place.