@eff imo security is broken every time the user has no control over which CA is trusted and which isn't. Which sadly is already normal on many systems. What the EU wants to do is horribly bad - but it isn't as much worse as it might sound/already is