SSL certificate verification disabled in openframeworks/openframeworks
Mar 10th 2022
This report is strange, partially because the existence of this code has been acknowledged without any alarm about its security implication(s), and also because a pull request that would fix the vulnerability (opened as a bug patch) has been open for over two years! Having SSL certificate verification disabled is usually a bad idea because it opens users (in this case, developers' projects) to the availability of man-in-the-middle attacks that utilize self-signed SSL certificates as a way to 'spoof' a secure connection.
This vulnerability is capable of allowing attackers to intercept data sent over HTTPS connections that are handled by the