Hacker News new | ask | show | jobs
by spricket 2700 days ago
Certificate pinning. And perhaps warning your users about potential baddies if someone tries to change it.

Elsewhere in the article it mentions people were paid to screenshot their Amazon order history. Why would they do that if they could read all app traffic? My guess, Amazon is smart enough to use certificate pinning and/or not trust root certs