At what point in your development process do you say "I want this application, which will be distributed to unknown persons, to contain the means to control my AWS account."?
At what point in your development process do you say "I want this application, which will be distributed to unknown persons, to contain the means to control my AWS account."?
(And more often than not, they get there all by themselves -- such people usually appear on my radar asking questions showing they've figured out for themselves that it's a bad idea, they just need help turning that knowledge into practice.)
If you're using a web services API from a 3rd party that requires developer authentication keys you may be storing those keys in the code because there's not a great alternative.
It's not an "alternative", it's the correct solution.
In fact, you still have to do a lighter-weight version of it with AWS -- you need an API to generate and hand out the restricted keys to your apps.
With a few very rare exceptions, you don't use third-party APIs as a complete substitute for building your own services, you use them to make building your own services easier.
For example the push notifications SDK from Urban Airship and app analytics SDK from Flurry depend on having credentials stored in the app.
These examples are not unique to them. I don't disagree that it's wrong, but I don't know how to work around this to be candid.
This was implemented deliberately and with full knowledge of managers and developers.
Stuff like this happens....