A certificate validation callback is overridden to always return true, disabling TLS trust checks.
Perform proper certificate chain and hostname validation instead of returning true unconditionally.