I suppose they were relying on the prepending of "verify_fail" to the hostname (with an invalid character - '_') to cause the browser to fail the certificate name check, so Superfish is doing certificate checking? Shouldn't the browser then complain with a "certificate's hostname does not match the site's" warning?
...Or am I looking at this in the wrong way?