In fairness, Google wasn't vulnerable (in Chrome) to the root cert. issues because they had added a cert hashing check and whitelists to their browser specifically to work around this kind of attack (something I love about them as the modern Xerox PARC, Sun, or Bell Labs of our time). It only worked if you were using Chrome, but they did think about it.