Does anyone know why Apple uses certificates instead of API keys (a la GCM) for authorization?
Does anyone know why Apple uses certificates instead of API keys (a la GCM) for authorization?
Apple's model uses a public/private key pair: the private key never leaves your server and Apple doesn't know it. Apple only knows the public key, in the form of a cert. Apple actually writes about the trust model in the docs: https://developer.apple.com/library/ios/documentation/Networ....
Google's model uses a shared secret (the API key) that both the client and server know.
Having worked with both systems, I prefer the ease of the shared secret model, but each system uses a fundamentally different security model.
[1] https://developer.apple.com/library/ios/documentation/IDEs/C...
Also, having the certificate helps in signing and encrypting the notification packets triggered from the server.