

Signing (intermediate) certs have been compromised before. That means a bad actor can issue fake certs that are validated up to your root ca certs
While you can invalidate that signing cert, without useful and ubiquitous revocation lists, there’s nothing you can do to propagate that.
A compromised signing certs, effectively means invalidating the ca cert, to limit the damage

I’ve been through river cleanups everywhere I ve lived. There’s always something toxic that corps got away with dumping for so many years and then just left it. Government on the hook for so many billions of dollars cleaning up the mess. Where’s that sense of personal/corporate responsibility we hear so much about?