Is this a concern over protecting actionscript code or a concern over protecting sensitive information (like passwords) If it's the former then I agree with Bob, you are powerless to stop people getting their hands on your code *eventually*, and the whole excercise is meaningless. If it's the latter, then this is just sticking to the principle of 'no sensitive information in the swf' allowing access to an X ray debugger could be considered a security risk, so the whole thing makes sense.
 
John, is there any example you can think of of someone could use X ray for 'evil' ends? By which i mean ends that affect the website database or whatever else a swf could access? If we're following bob's rule (which i think this should be christened as, btw) then in theory there shouldn't be any risk at all... what your then left with is a security risk that involves hacks snooping round your classes going 'ooo, he's used a multidimensional array to iterate the properties etc...' which i think i for one could live with. Maybe i'm missing something.
 
Rob

 
On 1/7/06, John Grden <[EMAIL PROTECTED]> wrote:
"Actually, you can only guarantee security if you don't publish the SWF"

I think some are missing what I've been saying becuase, this is EXACTLY what I've been saying:  no URL / Password/ Username /IP would be published with any SWF at all.

You have a dumb connector and you have an interface.  They talk via localConnection.

If you tell your application to load the connector SWF, and the file DOES exist, it loads.  Otherwise, if fails silently.

How does the app know where to get the connector SWF?  YOU tell it through the interface (Xray interface where you take snapshots - physically type it in), which tells your application the URL for the connector.

So, there's no information that's published in any swf at all.  If someone caches your SWF's and views them with ASV, they get nada/nothing.  The developer has to know the URL of the connector or it's all over.

So, no proprietary information is ever in any of the SWF's.

Have I missed something in this scenario?  thoughts?

_______________________________________________
osflash mailing list
[email protected]
http://osflash.org/mailman/listinfo/osflash_osflash.org





--
~~~~~~~~~~~~~~~~~~~~~~~~
Rob Bateman - Flash Product Manager
BBC News Interactive

Tel: 0208 6248692
Mob: 07714 329073

[EMAIL PROTECTED]
~~~~~~~~~~~~~~~~~~~~~~~~
_______________________________________________
osflash mailing list
[email protected]
http://osflash.org/mailman/listinfo/osflash_osflash.org

Reply via email to