We have secure DNS now which in theory allows the browsers to completely bypass the CAs (by simply storing keys in the DNS records). Why don't Mozilla and Google get together, introduce a source authentication based on secure DNS, run that for a while and then deprecate the whole bloody corrupt designed by the NSA CA system?