Is the default Android app actively maintained at the moment?

How exactly was TLS preventing an app starting on the same port and getting the API key before?

There was no certificate validation, so this change does not make the security any worse.