3afe0c9978
Tor hidden services are authenticated by their onion address (the public key hash), making TLS certificate verification redundant. The .onion server in TOR_ELECTRUMX_SERVERS was going through pinnedSslFactory() but its cert isn't in the pinned list (and can't be fetched without Tor). This would cause .onion connections to fail with SSLHandshakeException when Tor mode is active. Fix: .onion addresses now use a dedicated onionSslFactory() with trust-all, which is safe because: 1. Tor provides end-to-end encryption 2. The onion address IS the server identity proof 3. Samsung Knox trust-all rejection doesn't apply to proxied sockets