2 ms·
A self signed cert is a a real cert, its just not provided by an CA authority. I guarantee you this http just redirects to an https location, (just tested it on
by restingrobot 6y ago
A self signed cert is a a real cert, its just not provided by an CA authority. I guarantee you this http just redirects to an https location, (just tested it on my own device), so there is no plain text transfer. In the mobile industry this happens all the time as backend endpoints grow and change.
- nicholashead 6y agoThe bottom line is, there's no reason to request the non-HTTPS connection in the first place. And there's apparently no checks in the app to make sure it's connected to their real server.
- restingrobot 6y ago>The bottom line is, there's no reason to request the non-HTTPS connection in the first place. The example I gave wasn't to excuse the issue, it was to maybe explain why the fix is taking so long. > And there's apparently no checks in the app to make sure it's connected to their real server. I don't think you can make that statement. The description of the issue only attempts to hi-jack the session, he didn't actually try to do anything with it. There may very well be checks in place.