So, how does the Flash application tell the server that the puzzle is solved? Using TamperData , an attacker can intercept / modify / play this request, even if it exceeds HTTPS. If you try to inject a secret, you can get it by decompiling a flash application or even a debug flash drive while your application is running and finding the secret in memory.
, , , . - . ? , , . , , Message Authentication Code, .
, - . , . , , , . , . - , , , , - . , . sha256, md5 , -, .
, , , . , , - . , , . Mac, , - , .