Is it safe to accept self-signed certificates?
问题 I have an Android app, and I keep getting javax.net.ssl.SSLException: Not trusted server certificate when I try to use it with my own server with my own self-signed certificate. I am thinking of configuring the Android TrustManager to accept self-signed certificates, or to accept all certificates, so I can debug my app. I've read a bunch of resources on this site about how to do that. Is this safe to do? 回答1: No, this is not safe. It destroys most of the security benefits of SSL/TLS. It