Meanwhile:
http://security.stackexchange.com/questions/86609/this-is-20...
https://www.schneier.com/blog/archives/2015/10/sha-1_freesta...
"Freestart collisions, like the one presented here, do not directly imply a collision for SHA-1"
"this work is an important milestone towards an actual SHA-1 collision"
https://en.wikipedia.org/wiki/SHA-1
"SHA-1 is no longer considered secure against well-funded opponents".
AKA, SHA-1 may not be secure against a nation state or attacker with a ton of money, but it's secure enough against for almost every site against almost every attacker. Given the reported 5%+ of Chinese browsers not supporting newer certs, I can see why customers might want a cert that gives them a lot more than nothing, though less than best-of-breed.
It's the one-size-fits-all where someone's personal blog needs to have the same level of security as the apple app store's payment system that leaves them filling a real market need. They didn't go seeking people wanting SHA1 certs, people wanting SHA1 certs that would still work went seeking someone who would provide them.
And they went seeking because the alternative is upgrading potentially millions of dollars worth of embedded kit which doesn't support newer certs, all to secure one link in a chain in which SHA1 is nowhere near the weakest link.
So yeah, the CAB chose to inflict a ton of pain and cause still-functioning hardware to be discarded in order to push a more secure ecosystem on everybody. Which is great from some perspectives, but it's environmental vandalism from another perspective, and if it pushes people back to non-HTTPS traffic for those older pieces of equipment it could cause a short term worsening of security.
(the deprecation of sha1 that is. The lying by WoSign/StartCom was a calculated risk in a business where everything is based on trust, and they lost)