So the article title could be changed to "Peach API has replay vulnerability"? I haven't actually tried this yet but can someone confirm the app has pinning? If so, thoughts on how he sniffed the original traffic and ran the replay?
[0] https://github.com/nabla-c0d3/ssl-kill-switch2 [1] http://mitmproxy.org/