

It’s the “change your password often odyssey” 2.0. If it is safe, it is safe, it doesn’t become unsafe after an arbitrary period of time (if the admin takes care and revokes compromised certs). If it is unsafe by design, the design flaw should be fixed, no?
Or am I missing the point?


Moot point!
You could still get certificates for other people’s domains from Honest Ahmed 's used cars and totally trustworthy CA or so. But that’s another story. (there are A LOT of trusted CAs in everybody OS and browser. Do you know and trust them all?)