> Credentials are sent BEFORE prompting the user to accept a self signed cert. So it sounds like an attacker can harvest credentials on a rogue wifi by spoofing DNS and using a self-signed cert. I don't have an iOS device so I can't test.
This does not appear to be the case (Tested on an iOS 10.3.3 device and an iOS 11 device).
This does not appear to be the case (Tested on an iOS 10.3.3 device and an iOS 11 device).