Sounds like it. But this isn't an architectural solution. All this does is layer an additional level of "trust" requirements onto the existing protocol. The "pinning whitelist" is isomorphic to the root CA list and can be compromised in exactly the same way.