Actually pretty decent tech reporting if true. This is a non trivial task that can take some time to setup and analyze. If the app is secure and uses certificate pinning it would require reverse engineering it to patch over the pinning before you could MiTM the traffic and actually see it decrypted.