> We had an idea my friend and I to make the life harder to hackers...

However, you would still need some first point of call to get the list.
This could be found out and called by another application just as easily.
You could look at some type of public key cryptography and supply a
"certificate" of some kind that could be used in a handshake - a little
like your own style of SSL using Flash Remoting (but that may be getting a
little too complex for what you are trying to do).

You could also think about encrypting your data in some less extreme way -
but ultimately this algorithm could be worked out (and fairly quickly by
most determined hackers).

While I understand the need to control what application accesses your
webservice (for data integrity if nothing else) it is like the monthly
conversation that tends to happen on HTML/Javascript lists (about hiding
the source code).  In the end, the only "safe" way to protect your API (or
hide your intellectual property) is to just not publish it to anyone.

Your webservices/flash remoting should, however, be written in such a way
as to not assume the remote client will correctly validate the data.  It
really is no different than a HTML form submitting some data to a website.


Gary Menzel
Web Development Manager
IT Operations Brisbane -+- ABN AMRO Morgans Limited
Level 29, 123 Eagle Street BRISBANE QLD 4000
PH: 07 333 44 828  FX:  07 3834 0828


****************************************************************************
If this communication is not intended for you and you are not an authorised
recipient of this email you are prohibited by law from dealing with or
relying on the email or any file attachments. This prohibition includes
reading, printing, copying, re-transmitting, disseminating, storing or in
any other way dealing or acting in reliance on the information.  If you
have received this email in error, we request you contact ABN AMRO Morgans
Limited immediately by returning the email to [EMAIL PROTECTED]
and destroy the original. We will refund any reasonable costs associated
with notifying ABN AMRO Morgans. This email is confidential and may contain
privileged client information. ABN AMRO Morgans has taken reasonable steps
to ensure the accuracy and integrity of all its communications, including
electronic communications, but accepts no liability for materials
transmitted. Materials may also be transmitted without the knowledge of ABN
AMRO Morgans.  ABN AMRO Morgans Limited its directors and employees do not
accept liability for the results of any actions taken or not on the basis
of the information in this report. ABN AMRO Morgans Limited and its
associates hold or may hold securities in the companies/trusts mentioned
herein.  Any recommendation is made on the basis of our research of the
investment and may not suit the specific requirements of clients.
Assessments of suitability to an individual's portfolio can only be made
after an examination of the particular client's investments, financial
circumstances and requirements.
****************************************************************************

----------------------------------------------------------
You are subscribed to cfcdev. To unsubscribe, send an email
to [EMAIL PROTECTED] with the word 'unsubscribe cfcdev'
in the message of the email.

CFCDev is run by CFCZone (www.cfczone.org) and supported
by Mindtool, Corporation (www.mindtool.com).

Reply via email to