Most people, even most developers seem to be pretty clueless with this stuff.
Please name and shame, this sounds pretty surprising!
There are several banking-related apps listed here.
Highly recommend any material on the main site as well. One of the few legit infosec professors I have ever interacted with.
> Altogether, of the 639,283 [Android] apps in our data-set, 45 implement pinning.
[1]: https://www.usenix.org/conference/usenixsecurity15/technical...
No. No application or OS should impose it's own CA on an end user without choice. I get the importance of encrypted traffic flowing over the internet, but I also have concerns about traffic leaving my own network. Neither at my home or my business do I want an encrypted stream of traffic flowing out of my network without my being able to inspect the contents and know who the recipient is.