The client, particularly when it's enhanced by the person at the keyboard, is the greatest risk.

Certificate pinning is being deprecated because it mitigates precisely one problem and can cause an enterprise-wide outage when something goes awry. In the last decade I've experienced precisely three vendors using certificate pinning at all.It's the Betamax of TLS security.

