Google.com is still SHA-1 but they green-light their domains
tls.so
tls.so
http://googleonlinesecurity.blogspot.com/2014/09/gradually-s...
"Sites with end-entity certificates that expire between 1 January 2016 and 31 December 2016 (inclusive), and which include a SHA-1-based signature as part of the certificate chain, will be treated as 'secure, but with minor errors' [i.e., the lock-with-yellow-triangle you also get for mixed content].
"Sites with end-entity certificates that expire on or after 1 January 2017, and which include a SHA-1-based signature as part of the certificate chain, will be treated as 'affirmatively insecure'. Subresources from such domain will be treated as 'active mixed content'."
My SSL provider (namecheap) did send me one email at some point, but I'm sure I glossed over it because I didn't realize this change was coming.
They seem to get new certs every three months.
And it incentivizes moving to a system that's not so weak.
The other part is that, if something about a cert turns out to have been a bad idea, it's much better to only have to wait a few days or even months than to wait a few years. "Something" could be the algorithm (precisely why Chrome is yelling at SHA-1 certs that will still be valid in 2017, even though there's no attack as of right today). It could also be certification practices: if the community decides that, say, certificates without the `subjectAltName` extension need to be deprecated because the CN field is underspecified, nobody's going to want to do revocations for that. So you are stuck waiting until all current certs expire and get renewed to follow current best practices.