Impersonating a CA is not transparent and risks losing that CA if anyone finds out it's forging certs. They probably can do that, but it's a risky nuclear option.
This is a transparent dragnet that can easily be blamed away, which has been shown to be much more preferable in the NSA's M.O.