CERT Tapioca screenshot listing some HTTPS traffic that was let through, despite being intercepted.
https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/783/164/193/162/381/original/352d83a4c3f58319.png
About 10 years ago, I set up an automated system to test whether Android apps choose to bypass HTTPS security or not. Almost 24000 vulnerabilities later, I was... not impressed.
Just for lulz, I decided to test some iOS apps using a telephone and my fingers. Yes, the situation is much better than it was back then. No, I should not have been able to find over a dozen vulnerable apps by hand this easily.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.