Just my 0.02 (anyway I suppose the guys in power don't really bother), but if certificate authorities want to survive, they will not only need to improve their certification process (something that their *customers* may not be truely ready to pay for btw) but also to solve the entire X.509 revocation model. Because maybe it is time to realize that... well, it does not work.
Personally, I have no idea how to do that. However, I've been repeating for years to students that issuing access rights is easy and that all the difficulty is in *removing* rights; so maybe I'm just too bored to figure out something clever and someone else will find.
In the meantime, I'll turn to other things (whether PGP or Convergence).