We don't know that they didn't get a forged certificate for ssl.google-analytics.com.
Diginotar haven't (AFAIK) released even a partial list of affected domains, other than admitting that there were quite a lot of them.
Diginotar haven't (AFAIK) released even a partial list of affected domains, other than admitting that there were quite a lot of them.