Air Flex Flash Developments

 

Compare Life Insurance   We search 300 life insurance plans
Get our cheapest quote online now!

www.protected.co.uk

Matched.co.uk

I have been doing research on creating FB applications but have been hindered by FB developer forum comments stating that’s its a unsecured environment to develop for in regards to Flash/Flex development. So is it a warn off or are there real security gap implications to these roomers.

Well taking into account that any so and so can decompile a swf therefore crack down into the code namely where your AS3 is connecting to the developer api key. This would mean that any decompilation savvy individual could get a hold of your api key and deconstruct or de-anything your application/s.

Now that just ruined my morning let me know your thoughts

PROTECT YOUR FAMILY GET QUOTE
Car Insurance
Mortgages
Life Insurance
UK Quotes

11 Responses to “Dont write Facebook apps with Flex or Flash?”

  1. judah

    Don’t listen to the player haters (Flash Player haters that is). There isnt a decompiler for AS3 at the time of this comment. There is one for Flash AS2 that shows you stripped down variable renamed code fragments. If you can understand it then you can write the code in the first place. Your app is as secure as you make it. It is more secure by default than HTML which is available by “View Source”. There are also system checks and balances all along the way.

    BTW I’m not sure what site you would use to put an API key on the page. Maybe flicker? If that is the case that key is available in View Source on html. If you need it more secure you need to setup a login that does not compile any sensitive information in the swf.

  2. admin

    Thanks for the reply judah very informative

  3. Menzoic

    I’m not sure what an api key is but its my understanding that flash has a sandbox that prevents other programs on different servers from communicating with the swf. Wouldn’t the person need access to the server to do something?

  4. admin

    No the api key is instilled within the swf itself in the actionscript and because swfs can be decompiled there is s risk of the api key that facebooks seal of application security can be used to copy or even destroy the app. How ever theres no such known swf decompiler for flash player 9 so we are safe as for now

  5. joeboxer

    I have a flash app on facebook. I use SWF Encrypt 4.0 to lock down the .swf and use Flash remoting for the communication… thats about as secure as you can get it.

  6. john b

    acctually there is a decompiler that partially supports as3. it’s called flash decompiler 3 trillix.

  7. admin

    Nice one Joeboxer any chance we can take a look at your app?

  8. Carmella Bing

    I read your blog in a regular manner and just love it
    hope there will be more postings from you, keep on going
    greetz, carmella

  9. Hamed Aliloo

    How use facebook as3 api with flash cs3

  10. Darren

    I imagine you could just load up the api key from a php script or other programming language, into the swf application. You could protect the script by POST’ing a big random variable to it just to check that it’s coming from the right person and not a hacker, then return the api key to the swf if the var checks out. Not sure though as I haven’t looked into FB developers applications before.

  11. David

    Darren has the right idea. Keeping all sensitive info external from the swf is the only way to go, AS 3 Decomplilers or not.

Leave a Reply

Proudly powered by WordPress. Theme developed with WordPress Theme Generator.
Copyright © Air Flex Flash Developments. All rights reserved.
Secured Loans

Compare 100s of secured loans with Accepted.co.uk.

www.accepted.co.uk

Matched.co.uk
UK Life Insurance Quotes
Life Insurance
UK Insurance
Buildings and Contents
Mortgage Insurance