While I agree with you about pulling the rug out from users - if the CA is already forging certificates for important domains, then how much security do they really have?
It's in the Turkish government's to use these invalid certs as little as possible, so they are probably going to use them against people like Turkish dissidents.
(I don't mean to dismiss their interests, but they are distinct from other people's interests.)