Re: its all bs
I agree with you.
If you want security, you must only trust your CA, and nobody else. This, of course, presents it's own problems if you are connecting to somebody else's servers, because by default they do trust at least the root CAs. And the issue is they can't be fully trusted.
You also have the blackbox inside the OS and processor/enclave, that you also can't fully trust.
Do basically you can have reasonable security, but bad actors with access to dodgy certs will be able to do MiTm attack, and depending on your paranoia it will be more or less difficult.
Of course the common attack won't work against you if diligent.
I am happy not to be the one responsible for security at a high stakes company because IMHO it is getting more and more difficult to manage.
As for the point of this article.. I think that if security worries you that much, just use your own servers.
That, of course, also has issues and a price to pay