I disagree that using a non-local domain is a bad idea. As long as each client generates it's own key and certificate for the local webserver then a MitM isn't possible, even if they take over DNS. Using non-local DNS makes setting up DNS so much easier; and if they took over your DNS you already got some pretty serious problems.
The real problem is they embedded and distributed secrets, instead of generating them. It's funny a game company can do security better than a software firm working for a government. It's sad that I'm not surprised.
I'd bet money that people developing this software knew this was a problem, but government regulation required they use an external CA instead of a self-signed cert because "self-signed certs are always less secure", and nobody was empowered to make this issue known or do something better.