<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Flash is secure.</title>
	<atom:link href="http://aralbalkan.com/61/feed" rel="self" type="application/rss+xml" />
	<link>http://aralbalkan.com/61</link>
	<description>Aral on Flash, SWX, Flex, ActionScript, and life.</description>
	<pubDate>Tue, 07 Oct 2008 17:14:09 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Aral</title>
		<link>http://aralbalkan.com/61#comment-69930</link>
		<dc:creator>Aral</dc:creator>
		<pubDate>Wed, 05 Sep 2007 10:19:38 +0000</pubDate>
		<guid isPermaLink="false">#comment-69930</guid>
		<description>Hi David,

That's not what we're talking about when we talk about security. There is no obfuscation or DRM in Flash at the moment, that's a given. By security, we're talking about exploitable security holes within the player. You can reverse-engineer any SWF file and find the paths to used MP3s, FLVs or any other assets. This is not a revelation, it's just the way it's always been. Nothing in a SWF is any more hidden than anything in an HTML page. It's just a little harder to get to it as you need to decompile the SWF bytecode. Many tools (like Burak's excellent &lt;a href="http://buraks.com/asv/" rel="nofollow"&gt;ASV&lt;/a&gt;) exist that can do this.  

Hope that clears things up.</description>
		<content:encoded><![CDATA[<p>Hi David,</p>
<p>That&#8217;s not what we&#8217;re talking about when we talk about security. There is no obfuscation or DRM in Flash at the moment, that&#8217;s a given. By security, we&#8217;re talking about exploitable security holes within the player. You can reverse-engineer any SWF file and find the paths to used MP3s, FLVs or any other assets. This is not a revelation, it&#8217;s just the way it&#8217;s always been. Nothing in a SWF is any more hidden than anything in an HTML page. It&#8217;s just a little harder to get to it as you need to decompile the SWF bytecode. Many tools (like Burak&#8217;s excellent <a href="http://buraks.com/asv/" rel="nofollow">ASV</a>) exist that can do this.  </p>
<p>Hope that clears things up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david roma</title>
		<link>http://aralbalkan.com/61#comment-69900</link>
		<dc:creator>david roma</dc:creator>
		<pubDate>Wed, 05 Sep 2007 07:32:34 +0000</pubDate>
		<guid isPermaLink="false">#comment-69900</guid>
		<description>security of flash player can no long be guarenteed.
a friend of mine recently discovered a way around it, try me, put any mp3 or video (that is impossible for me to download for free anywhere else) in a secure flashplayer and il email it back to you as it is.
regards</description>
		<content:encoded><![CDATA[<p>security of flash player can no long be guarenteed.<br />
a friend of mine recently discovered a way around it, try me, put any mp3 or video (that is impossible for me to download for free anywhere else) in a secure flashplayer and il email it back to you as it is.<br />
regards</p>
]]></content:encoded>
	</item>
</channel>
</rss>
