namely, I can pin your domain certificate to something broken and now user's browsers will refuse to load your domain until the HSTS timeout