Maybe consolidating ~60% of the web's certificates on to a single provider was a mistake.
Before this, they were all unencrypted and you had to pay to get a cert. I guess we could go back to that - now knowing that every unencrypted connection is being MITMed (the world is so much more hostile now)...
Well good thing everyone using the provider is using an open protocol and it's stupid easy to switch