> If additional back-dating is discovered (by any means) to circumvent this control, then Mozilla will immediately and permanently revoke trust in the affected roots.
There's already evidence of this happening. It happened. Why does it have to happen again. Just revoke em.
if they removed it entirely, those would all break which would be inconvenient to the otherwise innocent customers.
Wosign/startcom are known bad actors and put the entire ecosystem at risk because browsers trust all CA's equally.
Certificates are ultimately fungible with redundant CA's globally. One certificate is essentially as good as another, from the browser perspective (and nearly all site visitors).
This interchangeability:
Reduces the risk for 'otherwise innocent customers' in terms of cost (especially now with letsencrypt) so it's "easy" (or at least possible) for customers to replace their existing certificates when they had put trust in an untrustworthy vendor, and
Increases the risk that Wosign/startcom will sign bad certificates by backdating them (especially because signing certs is, in fact, their business model and now they have no incentive to not sign bad certs by backdating, since their business is basically dead now anyway.)
The risk is too high to NOT revoke all of their certificates, unless the current certs were able to all be enumerated and pinned. Letsencrypt only issues certificates for 3 months in order to provide some semblance of control.
If they wanted to have their cake and eat it too, Mozilla could give a thirty or 60 day warning period saying 'upgrade your certs NOW' or change them to 'untrusted' (grey) for that period of time and then completely remove (red) the way Chrome has done in the past with legitimate but no-longer-secure certs.
Distrusting future certs punishes the company, distrusting all of them punishes all past customers and their users, and encourages people to just switch browsers.
In addition to the inconvenience to site owners and users, it would also lead people to blame the browser if the sites still work in other browsers, which would make it hard for any one browser to unilaterally distrust a CA.