Popular proxy software Xray-core covered up a certification verification bypass vulnerability for half a year
Disclaimer: I am the reporter of the vulnerability.
Xray-core maintainers look down on "skip certificate verification" feature (i.e. the allowInsecure option in Xray-core) or similar options in proxy software, arguing that this is equivalent to having no security measures at all and leaves users "streaking", exposing them to the risk of man-in-the-middle attacks. However, if a vulnerability in Xray-core itself causes users to be "streaking" and fall victim to man-in-the-middle attacks, Xray-core...
Read more at github.com