http://imfreedom.org/wiki/IMessage
https://github.com/meeee/pushproxy
I was curious, too. I had lunch with the guy who made the proxy (man, I love living in Berlin) and discussed his efforts to reverse engineer the iMessage protocol (which runs inside/on top of Apple's push notification system).
AFAICT, iMessage activation fetches a key from Apple that is either tied to or based on the hardware serial number. Based on Apple's history of rather excellent crypto implementations on iOS[1] I'm guessing that (on iOS) this key then gets signed by either the hardware key or somesuch to authenticate the device to the APNS. On OSX, the activation request includes the hardware serial number of the mac making the request, and the service rejects arbitrary SNs (though valid SNs are predictable so those can be used to get iMessage working on OSX inside a VM).
If I had the free time, I'd finish reversing the protocol.
I don't have proof, but preliminary observations suggest that iMessages are, indeed, end-to-end encrypted.
http://www.csoonline.com/article/731446/fbi-highlights-imess...
http://www.macobserver.com/tmo/article/apples-imessage-encry...
http://news.cnet.com/8301-13578_3-57577887-38/apples-imessag...
[1] http://images.apple.com/iphone/business/docs/iOS_Security_Oc...
I haven't seen that behavior, but it could be explained the messages being encrypted to a per-AppleID-key which is encrypted to each device's key. Time permitting I'd really like to learn more about the specific architecture.
I'd like to believe that Apple would build, at least initially, a system that's as secure as possible from snooping, waiting only until mandated by the feds to backdoor it with key escrow. Maybe I'm too idealistic. In either case I don't talk about anything sensitive on iMessage.