What if it's the trusted Root CAs who are giving state agencies copies of their signing keys thus allowing them to sign valid certificates to impersonate anyone?
"In addition in Chromium 13, only a very small subset of CAs have the authority to vouch for Gmail (and the Google Accounts login page). This can protect against recent incidents where a CA has its authority abused, and generally protects against the proliferation of signing authority."
(disclaimer: I work for Chrome but not on these features.)