Mozilla admits to mishandling Comodo disclosure
blog.mozilla.com
blog.mozilla.com
If you've been following the story closely, that's the most significant portion of the blog post. There has been substantial criticism of the browser vendors acting to protect CAs instead of users, and this is an admission by Mozilla that they agree, at least to some extent.
If you read through the entry given a title of "Comodo Certificate Issue – Follow Up" it would be pretty easy to miss, as it is rather buried. Much of the rest of it is a rehash of previously available information.
I think Mozilla tried to protect their own browser, by tacitly releasing updates for blacklisting those certificates, with the rationale being that this way Mozilla updates wouldn't also get blocked.
As the article says, those certificates have value in a tightly controlled network, because otherwise the browser would get a revocation status for that certificate using the OCSP protocol. In such a network it would also be feasible to also block Mozilla updates, and making the issue public wouldn't have helped (from this perspective).
Not saying that what they did was OK, but the issue is not so cut and dry.
https://bugzilla.mozilla.org/show_bug.cgi?id=643056#c20
It seems to me that there is a bit of a question (at least in a few people's minds) if there was going to be any kind of disclosure if Jacob didn't come along.