# Detecting a Spoof Client

**URL:** <https://forum.kirupa.com/t/detecting-a-spoof-client/280670>\
**Category:** flash\
**Created:** [January 30, 2009, 6:06am UTC](https://forum.kirupa.com/t/detecting-a-spoof-client/280670 "2009-01-30T06:06:24Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![anonp](https://avatars.discourse-cdn.com/v4/letter/a/50afbb/32.png) [@anonp](https://forum.kirupa.com/u/anonp)\
**Post date:** [January 30, 2009, 6:06am UTC](https://forum.kirupa.com/t/detecting-a-spoof-client/280670/1 "2009-01-30T06:06:24Z")

</div>

We have a client / server setup and the client is a Flex application. We are afraid that hackers can eavesdrop the client / server exchange and connect to the server with a spoof client.

How do we make sure a client that is connecting to the server is not a spoof client? We can put a private key inside the client for authentication but that can easily be defeated by a de-compiler.

What do you suggest?

Thanks.
