That only works in some areas of the world, where a, there is a somewhat free market; b, the free market idea exists in the first place.
As always, like in Perl, there are other ways of doing things; free market is not a universal law.
Chrome does not perform pin validation when the
certificate chain chains up to a private trust anchor.
A key result of this policy is that private trust
anchors can be used to proxy (or MITM) connections,
even to pinned sites.
-- https://www.chromium.org/Home/chromium-security/security-faq...Also we are talking about apps implementing certificate pinning. Not reading from the OS store etc., and therefore, I don't see Kazakhstan reverse engineering and patching executables.
The fact that Chrome ships with a broken implementation does not imply the concept is broken.
I don't really agree with that, but it's IMO more useful to acknowledge the confusion, than having an argument about whether Chrome really does pinning or even gets to de facto define pinning or not, since this isn't even about Chrome :)
But still, I would have much preferred if the GP would have started their comment with "yes, but" instead of "sorry, no". That would have made the distinction much clearer.
https://www.owasp.org/index.php/Certificate_and_Public_Key_P...
The fact is that pinning as implemented in Chrome exempts installed CA's from pinning checks because they want to allow administrator-mandated MITM - apparently "market requirement" because it's a common practice in schools and workplaces in some countries that lack reasonable communications privacy legislation.
You may argue that this is is broken behaviour, but that's what pinning currently is in browsers. Seems it's this way in Firefox too ("pinning not enforced if the trust anchor is a user inserted CA, default" - https://wiki.mozilla.org/SecurityEngineering/Public_Key_Pinn...)
The other option is to examine and pin the signing certificate. This is more code and more prone to error, but makes your connection slighty more robus in the face of a compromised certificate.
And yes, both techniques work even if a cert in your root store has another certificate. Applications can simply refuse to function, but this has to be done on an ad hoc basis.