Earlier quoted context omitted.
> How long before Symantec gets an NSL demanding an appliance that can mint bogus certs on the fly for dropbox.com, facebook.com, twitter.com, etc...? If the bogus certs are not logged in Certificate Transparency, they will be rejected by Chrome: https://security.googleblog.com/2015/10/sustaining-digital-c... If they are logged in Certificate Transparency, then the world will know, the offending certificates will be…
From the link you posted: > However, we were still able to find several more questionable certificates using only the Certificate Transparency logs and a few minutes of work. We shared these results with other root store operators on October 6th, to allow them to independently assess and verify our research. So finding questionable certificates is trivially easy, but nobody ever bothers to look? What good is that?
As for everyone else, give it some time. The ecosystem is still very young and we're still developing tooling.