Everyone seems to agree that it is REALLY important to protect private keys so the encrypted Internet can remain just that (see for example at How do certification authorities store their private root keys?). Yet, according to www.grc.com and other sources, many browsers, especially mobile ones, do not check sites for revoked certificates due to compromised keys or any other reason (see https://www.grc.com/revocation.htm). Even the new mobile version of Firefox for iOS does not seem to check if the site's certificate is revoked.
My question is very simple: why is this situation tolerated? It would seem to be important, especially with the increasing popularity of mobile browsers supporting e-commerce...