So you're assuming there are compromised CA keys in the hands of governments & corrupt corporations?
Even if this is true, isn't it mitigated by certificate pinning?
Even if this is true, isn't it mitigated by certificate pinning?
With regard to corporations, most large ones configure employee browsers to trust corporate proxies which can see their traffic in plaintext. That's not unusual at all.
Certificate pinning very partially mitigates these issues. It should be done, but pinning certificates (as fragile as that process is to begin with) isn't enough when you can't trust what you're pinning to begin with.
In short it's a good idea to use certificate pinning but in no way should be thought of as a fix for fundamental problems that exist in PKI.
I might add Moxie's concept of "trust-mobility" to the list of things in the list up the comment stack.