They have ruined security for everyone by allowing government agencies (they didn't even bother to setup a front) and other questionable entities on that list. The correct response is not to send out a nice letter asking everyone to please give up crucial business information, but to kick everyone off that list and start over.
Mozilla was compromised, not the CAs.