1. For certificates, when copying a member of a container, one shouldn't read beyond the enclosing context.