> This is a controversial opinion, but I am actually of the view that SSL is structurally unworkable against nation-state-level adversaries.
Seems like a pretty sensible opinion to me. The entire CA system is full of flaws that can be exploited by anyone with enough money, power or influence.