Earlier quoted context omitted.
The people saying this is "generous" are making largely irrational arguments. What Mozilla is proposing is the worst case for incumbent CAs.
> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…
Insta-revocation therefore wouldn't really make this notably more painful for them -- they're walking dead at this point either way and there's a good chance they may even close shop before the deadline. All it would do is immediately put a bunch of their innocent customers in immediate pain, for essentially no gain. It might also send the message to, say, Symantec, that they can get away with anything, because no browser would risk revoking 30+% of the web instantly. Establishing a procedure that allows for executing a CA of any size puts everyone on notice.