Indeed. For some painful background, see eg:
https://bugzilla.mozilla.org/show_bug.cgi?id=215243
A fundamental problem with x509 and Certificate Authorities as it currently stands wrt https and browsers, is that all users almost randomly trust a few organizations to issue certificates -- and get warned of any other certificates -- but there is no decision on part of the user who they trust -- just some vague delegation to browser vendors on vetting CAs.
For some more background, I suggest reading:
http://www.thoughtcrime.org/blog/ssl-and-the-future-of-authenticity/
edit: Also, I tend to forget that cacert isn't included, as Debian are among the distributions that include them as a CA:
http://wiki.cacert.org/InclusionStatus