Digital signature would prevent that (assuming scanner does a good job at verifying one). "Looking at the hexdump" section of TFA, last 64 bytes (cyan-coloured).
On top of that, online verification (e.g. by certificate ID) might be possible, too.
On top of that, online verification (e.g. by certificate ID) might be possible, too.