in the dropbox app. Feel free to extract the certificate and MITM connections to your local machine.
Then I'm not entirely sure I understand the point of having an SSL certificate in place to begin with?
You cannot talk to non SSL connections from an SSL page.
It's there to enable a connection from an https web app. Otherwise it would be blocked as mixed content (e.g. if you just used ws). Because everyone has access to the localhost key in the Dropbox app, Dropbox uses additional mutual authentication after establishing the wss (this is actually also because other websites may try to access the local daemon). The wss is only there to indicate to the browser that Dropbox really wants to establish a connection between their web app and the local daemon. It's a lot of hoops to jump through to make it work, but it's the best way of doing it.
> It's there to enable a connection from an https web app
Oh! Thanks. Forgot about that.
We'll be changing the mixed-content detection soon to treat localhost as a secure transport (because it is from the network perspective), which will address the mixed content issue.