A great time to raise these questions. What reason have we ever had to trust any of these "authorities" (let alone the deteriorating state of the field, e.g. the recent Turkish fiasco)? Without a firm answer for that question, SSL is reduced to magic thinking.