Earlier quoted context omitted.
Banks can just switch to better SSL services...
Any large organization lacks the ability to "just switch" from one thing to another.
However, there's no point in pretending these certs are good if we can't trust the issuer to not put out BAD certs. Painful or not, if the banks are user the certs to show they are trustworthy, then they need to switch when the issuer ISN'T trustworthy.