The only reason why my mum won't be tricked into adding a rogue CA root is because it's too complicated to do for her, even if she wanted to.
* If it was as easy as installing a fake Flash plugin Trojan, she'd have installed plenty of rogue CAs already; * If it remains hard to do, she'll stick to the default config, which is what she does already.
So, the main change wrt the current PKI system is that by default, her browser would probably check a certificate validity against a couple of top authorities, rather than a single one. I guess it would make getting a certificate a couple of times more complicated, hence a couple of times more expensive (if the process of trust propagation is fully automated, then I'm no safer than with a single CA signature).
To sum up, I don't see how this would improve the situation for average Joes and Janes. Since Paypal, Amazon, Google etc. primarily care about average Joes, I don't see why they would adopt that kind of cyberpunk technology.