So, how much of my internet will break if I distrust the Symantec cert on my machine?
If your threat model contains nation-states, you shouldn't be trusting any CAs in the first place. With a nation-state adversary, you really need to be manually verifying certificate hashes that have been securely communicated to you out of band.
https://theintercept.com/2014/03/20/inside-nsa-secret-effort...