> These secrets belonged to a lot of different 3rd party services, for example Uber’s secret which can be used to send in-app notification via the uber app.
In every Apple application - aren't these keys a one off, created by the client?
"The device token included in each request represents the identity of the device receiving the notification. APNs uses device tokens to identify each unique app and device combination. It also uses them to authenticate the routing of remote notifications sent to a device. Each time your app runs on a device, it fetches this token from APNs and forwards it to your provider. Your provider stores the token and uses it when sending notifications to that particular app and device. The token itself is opaque and persistent, changing only when a device’s data and settings are erased. Only APNs can decode and read a device token."
Source: https://developer.apple.com/library/content/documentation/Ne...
If it is only your own token/secret you are seeing, that does not seem so bad, right?
In addition - let's say these apps DO leak secrets, what is the alternative solution here?