I'm in the market for a couple of SSL certificates. With all this NSA news my natural paranoia is being amplified. I'd prefer to spend my money on a CA that's trustworthy on the one hand, and technically competent on the other.
Who would you recommend, and who should be avoided like the plague?
Assuming that an adversary can get one suborned CA to sign a certificate for your domain, the adversary can use that certificate to MITM first connections to your site without causing any sort of warning message within the browser. They can then both sniff and alter messages going in either direction, including e.g. stealing credentials, cookies, and what have you.