guess who doesn't verify the root CA. Think of all the fun to be had with a Siri man-in-the-middle
The trick here was that Siri was asking for an HTTPS connection to a named server, and you can't MitM that without having a signed cert for that server. So they added a new CA to their local (jailbroken) iPhone platform data and signed a cert for the Siri server.