A small step towards abolishing the whole, "trusted certificate authority", system altogether, and moving towards some better.

While I realise that Google is doing everyone a favour in this case, I hesitate to replace the current (seriously broken) "trusted certificate authority" system with a "trusted by Google" system.

Things like "Certificate Transparency" seem to be a good step forward, particularly if multiple big players (including some based in Russia and China) join in.

