3 ms·
Shoot me down if I'm missing something obvious here, but: One solution would be for Apple and Android to have an "environment" section for applications. You'd
by HarrietJones 12y ago
Shoot me down if I'm missing something obvious here, but:
One solution would be for Apple and Android to have an "environment" section for applications. You'd be able to set these environment keys when publishing the app.
Apple and Android could provide an API to these environment keys, and they'd be published in an encrypted form as part of the application manifest.
Bonus Points: It would be relatively simple to provide the facility from the AppStore provider for changing / cancelling these keys.
- jaegerpicker 12y agoWhile not an API as such both OS's provide a User defaults/App default storage area. It's not that hard to encrypt your key in an outside process and then have your app write it to that location in encrypted format. Then make a request to the server to supply the key to decrypt the api key. Then again you are making it a little harder to break in but not much. The better tactic is to just limit the API access to as little as possible and make the API as secure as possible.