Earlier quoted context omitted.
Who do you imagine they verified was Person X? More on the malware cert issuance: https://blogs.msmvps.com/donna/2009/05/18/microsoft-mvp-mike... For malware concerns there's also Comodo's relationship with PrivDog. I'm not clear on whether PrivDog is deliberate malware or just incompetent insecure software.
That is ridiculous, to expect a CA to google every cert request domain and check what they are doing? That is a ridiculous requirement - cert issuance is automatic. Do you think we should stop allowing Let's Encrypt to issue certs? You know they don't google each domain to see what they are doing.
In my opinion, it would be worse if they denied certs to certain people.