You could distrust any certificate that was signed before April 7 (or some slightly later date). It might be easier to do that and whitelist the good "pre-apocalypse" certificates. The nice thing about doing this is that your whitelist will inherently go to zero as certificates time out and get renewed (typically 1-3 years?).
The hard thing would be to generate an accurate whitelist.