Design thoughts on next-gen PKI for better privacy
ledgersmbdev.blogspot.com
ledgersmbdev.blogspot.com
This is already the case - if you compromise a CA you can sign certificates for any domain you'd like, enabling you to pull off active MitM attacks, but you can't passively eavesdrop anything. Private keys are not registered with CAs; rather, public keys are submitted to get signed.
While the CA system majorly sucks, and needs to be fixed, I don't think it's the answer to mass surveillance, at least in the US. Even if the NSA could sign any certificate they wanted, it seems extremely difficult to pull off active MitM attacks for every connection across the entire Internet. An easier approach is to attack the endpoints (Google, Facebook, etc.) which they're allegedly already doing with PRISM. SSL/TLS can't protect against that.
Maybe the Web isn't the right tool because everything is in the open.