App defaulted to unencrypted HTTP traffic, and (until it was patched in December) could be exploited for phishing attacks.