@Scott_Helme IMO, no. The complaints mentioned in that article conflate authenticating a connection with verifying that the destination you've gone to is the one you wanted to visit.
The cert authenticates that endpoint may speak for https://example.com/. That's all it should do.