An interesting point on the article is how we are dependant to centralized CA. If the notion of CA was also linked to Web-of-trust, it will make it less prone to governmental intervention. Because of the actual legal system, it is possible for court to obtain by secret warrant a copy of the main key of a website. Why they don't request a copy of the main CA key and fake a new upgraded key after an event like heartbleed?