Post

Replies

Boosts

Views

Activity

Reply to Rotating String API Key
Is there a particular reason that Apple would not want to integrate App Attest directly into CloudKit access, in particular for the public database? As far as I can tell, this would be a great way to safely distribute secrets like this to an entire app userbase, but there is definitely much I don't know. It has always surprised me that the public CloudKit database is as accessible as it is (using just the container name and record ID). With App Attest integration, it seems that Apple could make it very easy for a developer to opt in to limiting these requests to only legitimate installs of their app.
Topic: General SubTopic:
Privacy & Security Q&A
Jun ’26
Reply to Rotating String API Key
Is there a particular reason that Apple would not want to integrate App Attest directly into CloudKit access, in particular for the public database? As far as I can tell, this would be a great way to safely distribute secrets like this to an entire app userbase, but there is definitely much I don't know. It has always surprised me that the public CloudKit database is as accessible as it is (using just the container name and record ID). With App Attest integration, it seems that Apple could make it very easy for a developer to opt in to limiting these requests to only legitimate installs of their app.
Topic: General SubTopic:
Privacy & Security Q&A
Replies
Boosts
Views
Activity
Jun ’26