3 ms·
Disclaimer: I work for Uber. These questions/opinions are entirely my own as a curious engineer. > These secrets belonged to a lot of different 3rd party servi
by michaelvoz 10y ago
Disclaimer: I work for Uber. These questions/opinions are entirely my own as a curious engineer.
> These secrets belonged to a lot of different 3rd party services, for example Uber’s secret which can be used to send in-app notification via the uber app.
In every Apple application - aren't these keys a one off, created by the client?
"The device token included in each request represents the identity of the device receiving the notification. APNs uses device tokens to identify each unique app and device combination. It also uses them to authenticate the routing of remote notifications sent to a device. Each time your app runs on a device, it fetches this token from APNs and forwards it to your provider. Your provider stores the token and uses it when sending notifications to that particular app and device. The token itself is opaque and persistent, changing only when a device’s data and settings are erased. Only APNs can decode and read a device token."
Source: https://developer.apple.com/library/content/documentation/NetworkingInternet/Conceptual/RemoteNotificationsPG/APNSOverview.html#//apple_ref/doc/uid/TP40008194-CH8-SW1 https://developer.apple.com/library/content/documentation/Ne...
If it is only your own token/secret you are seeing, that does not seem so bad, right?
In addition - let's say these apps DO leak secrets, what is the alternative solution here?
- mkagenius 10y ago> In every Apple application - aren't these keys a one off, created by the client? You just need the server token, and a phone number to send the notification. (The gsm token already in possession with Uber can be used to send notification to anyone at will) Here is the uber documentation regarding reminders: https://developer.uber.com/docs/riders/references/api/v1.2/reminders-post https://developer.uber.com/docs/riders/references/api/v1.2/r...
- dalore 10y agoYou proxy the request through your own server using their user credentials.