I'm testing the security of an iOS app with sslstrip running on my Kali. My iOS app is installed on several devices, on some of them, sslstrip works as expected (shows login information), on some, it doesn't (although the traffic runs over Kali for sure).
The app in question is developed via phonegap; first, it shows an HTTP-URL, after tapping on the "Login"-Button, it redirects to an HTTPS-URL. Then, after entering the login information and tapping the "submit" button, I sometimes (= on some devices) see the login data in sslstrip-log, sometimes I don't. Even if I reset the device completely and only install the app from the app store the behaviour doesn't change.
What else could determine the success of sslstrip in this case?