I think we have pretty decent examples where browsers remove malicious root certificates if they have been so proven. Do you think the matters will be different if those belong to a country level root?