Last week I received the shameful message "Your confirmation of the ssl certificate of your application is unsafe" [link] warning for our application.
Since we are not using a custom TrustManager, I looked at the apk application for the appearance of "checkServerTrusted". The only class that came up is related to Fabric / Crashlytics (most likely io.fabric.sdk.android.services.network.PinningTrustManager ).
Does anyone know if there is a problem with the implementation of Fabient TrustManager? Does anyone using Fabric (and not a custom TrustManager implementation) also get this warning?
I did not find the source code of the SDK, so I could not test myself, however, if you see similar results, in the next step I will contact their support.
Update:
android google-play crashlytics fabric-twitter
Florian barth
source share