I can self-sign certs. The problem is that no browser recognizes my self-signed certs, so they put up dialog boxes filled with warnings. (Which many users will just dismiss without a second thought, since they are very used to their machines crying wolf. But let's ignore that big problem for now.)
So the problem is that some of the CAs whose credentials are pre-installed and pre-trusted in various browsers or clients turn out to have shoddy verification practices. Does the answer to this involve Mozilla, Webkit, Microsoft et al. decertifying these CAs, which would turn them into the equivalent of someone like me, signing certificates in his basement?
I guess the problem with that is that all the existing paying customers of these CAs would wake up one day to find that their certs don't work anymore and that their money was wasted.
What is the answer to this problem? What kind of contract do you have to sign to become a CA, and with whom?