If checking the revocation list is too hard, how about browsers checking certificates for the
vulnerability?
It might be helpful for browsers to display a "weak certificate" warning for affected certs
signed by a recognised authority (such as "this site uses a weak certificate which could allow
them to be impersonated). Worried customers contacting site owners could well encourage them
to upgrade to a more secure cert.
If there is no recognised CA, there is not much point in such a warning - in this case an
impersonator could just issue their own certificate claiming to be the target - and I guess
this case is already covered by an appropriate warning.