Security has always been an issue with IoT devices. Off the shelf devices ... The normal ways to do HTTPS with an ESP8266 is to either use Fingerprints, or to use client.setInsecure().
The first flaw is the simplest, and only effects ESP8266s. While connecting to an access point, the access point sends the ESP8266 an “AKM suite count” field that contains the number of ...