I know users of CyanogenMod in Iran who are directly impacted by this compromise of DigiNotar. Additionally, they use the GSM network and it is possible to set the clocks of GSM phones - so certificates that have been issued are not valid only during some window of time - the attackers literally control time. The attackers here have all of the cards and only by removing the trust in DigiNotar *at the root* will help those users to stay secure

DigiNotar fully compromised - CyanogenMod Android ROM - Google Project Hosting | Issue 4266 - cyanogenmod - 2011-09-03
