It most definitely does. You can authenticate using a token that only allows access via that url for a set period of time and also from a set range of IPs.
edit for link: http://docs.amazonwebservices.com/AmazonCloudFront/latest/De...
edit for link: http://docs.amazonwebservices.com/AmazonCloudFront/latest/De...
The ACL is for the S3 and not the CloudFront.
Don't take my word for it:
http://developer.amazonwebservices.com/connect/thread.jspa?t...
http://developer.amazonwebservices.com/connect/thread.jspa?t...
http://developer.amazonwebservices.com/connect/thread.jspa?t...
Edit: The signed URL protects the "copy and paste" but not the "easy" ripping.