Moderate Security Question 138 of 229

Why should you not store JWTs in localStorage?

Frontend Master · Speak this in 60–90 seconds · Faridabad & Delhi NCR

PICTURE THIS: A SENTENCE BECOMES TOKENS

The model does not read letters like humans. It reads these pieces, then predicts the next one.

Simple meaning

Any XSS on the origin can read localStorage and send the token to an attacker.

1

WHY — Security instead of guessing?

Why interviewers care about Security:

They are checking judgment

on Security.

A good answer names

the situation, the default choice, and one exception - that reads as experience.

Stay structured

Name the idea, why it exists, then one short example.

Close cleanly

End with when you use it and one common pitfall.

2

STEPS — What happens with tokens?

Before the model can read a sentence, it goes through these steps:

  1. 1
    Any XSS on the

    origin can read localStorage and send the token to an attacker.

  2. 2
    HttpOnly cookies are not

    readable by scripts.

  3. 3
    If a team still

    uses localStorage I talk about short expiry, CSP, and treating XSS as a full account compromise.

  4. 4
    Context mix

    Attention looks at nearby tokens together.

  5. 5
    Next token

    The model scores what should come next.

  6. 6
    Decode

    IDs turn back into readable text.

3

EXAMPLE — See it in action

Here's a short line you can speak, broken into clear beats:

Say this line
“HttpOnly cookies are not readable by scripts.”
Break into beats
HttpOnlycookiesarenotreadableby
Speaking order
2987408337471632900

Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.

Key takeaway

Any XSS on the origin can read localStorage and send the token to an attacker. HttpOnly cookies are not readable by scripts.

Chat with us