# Runtime encapsulation with AS2

**URL:** <https://forum.kirupa.com/t/runtime-encapsulation-with-as2/223197>\
**Category:** flash\
**Created:** [April 20, 2007, 8:01am UTC](https://forum.kirupa.com/t/runtime-encapsulation-with-as2/223197 "2007-04-20T08:01:19Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcusjw](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@marcusjw](https://forum.kirupa.com/u/marcusjw)\
**Post date:** [April 20, 2007, 8:01am UTC](https://forum.kirupa.com/t/runtime-encapsulation-with-as2/223197/1 "2007-04-20T08:01:19Z")

</div>

Hi,

I’m needing to secure a flash app which is currently in AS2. It is ‘encrypted’ with SWF Encrypt prior to deployment, but this doesn’t seem to be a whole lot of use…

Turns out that if you create an empty Flash movie, and load in _any_ other existing flash app, you can inspect, instantiate, and override all classes, methods, and properties (private or otherwise), but simply running a for/in loop over \_global._packagename_

Try it for yourself… doesn’t matter if your target clip is ‘encrypted’ (using the term loosely) or not.

So… does anyone have any suggestions for how to protect an AS2 movie in any way? Would moving to AS3 overcome this massive security whole?? Do any pre-compile-time code obfuscators exist so my classes/methods/properties will be less obvious as to their usage?

Any suggestions will be greatly appreciated!

thanks  
Marcus.
