I'll accept that it's hard, but why do you think Google didn't do it right?
Google also has an internal PKI CA - I think they meet and exceed that security baseline for rigor.
The threat models targeting anti-Google malicious actions obviously worked since they have traces of the Otto guy's activities. What I am asserting is that these forensics logs they use as evidence can be attacked in court as not being sufficiently protected from tampering by an internal Google party interested in fabricating evidence.