Certificate validation
Encryption without an identity check gives you a private conversation with whoever happens to be on the other end.
This is the part that gets disabled. A certificate check fails during development, somebody turns verification off to get the work moving, and the change quietly ships. The result looks correct, the traffic is encrypted, the padlock is there, and any attacker who can get in the middle is now invited. It is a common enough mistake to be worth checking for deliberately rather than assuming nobody would.
Checked against the primary source.
