Being able to partially distrust a Certificate Authority is good
utcc.utoronto.ca
utcc.utoronto.ca
I'm guessing that for some TLDs it would make even more sense like for .gov or .google or similar.
It would be useful for internal CAs too, because they could be trusted for only a specific subdomain, eg *.intranet.acme.com.
https://news.ycombinator.com/item?id=33876949 (> 100 comments)
It would be possible to require certs be included in logs before some cutoff time but no browsers do that today.
It does provide a mechanism that cert backdating can be detected, if new never before seen certs keep showing up from a partially distrusted CA.
He did propose that Linux act differently (https://utcc.utoronto.ca/~cks/space/blog/linux/CARootStoreTr...), and this post is a follow-up explaining the value browsers get out of this partial-trust situation.
a sketchy CA should not be given the benefit of the doubt. and customers of sketchy CA should suffer for not doing their homework and should rightly scramble to secure certs from other providers to resume their business.
the only sin of kernel/distro maintainers is not dropping those CAs faster.
what browsers did is the ultimate sin of sacrificing users to not be blamed by something they are fixing under the guise of backward compatibility.