Mozilla piles on China's SSL cert overlord: We don't trust you either

The solution is for anyone who wants to prove their identity to make their own certificate and get it signed by several CAs. That way the certificate remains valid until all of the counter-signatories have mis-behaved.

It's also more expensive (ie, a money-spinner for the CAs) so I'm surprised the CAs themselves aren't pushing this approach.

