That being said, type systems aren’t the magic solution to reliable code, nor is throwing static types away the magic solution to easier human-compiler relations. Forethought must be applied in all cases to end up with a mess, and Lang choice should match domain & org needs.
As im sure you are aware, using twitter is not a good way for a PUBLIC DOMAIN org to handle images. Find a better way. You are making history, document it properly, and make the image available to all mankind, forever.
No, whilst I think certificate vendors should exhibit exemplary practice on web security the bit that matters for issuing is linking private key info in CSR to domain/org. That said most take credit card data so should meet PCI rules.
In my experience, this works better than a whiteboard. Let them invent the color coding and symbols, put someone in charge of keeping a legend, and keep adding tech/arch/domain/org/political/... information and move it around until something emerges. pic.twitter.com/eijssipNBp