Good job, Google. 30,000 unauthorised certificates being issued is 30,000 too many; five or ten you could maybe, kinda, sorta understand, but 30,000 smacks of huge incompetence at best.
Companies who have their root certificates entrusted as part of the TLS core infrastructure need to have better checks and balances than to simply say "oops, we done goofed" after the fact. If they demonstrate - as Symantec has demonstrated - that they can't manage that, their root certificates need to be yanked out of the chain of trust as soon as possible.
It sucks, royally, for those who have paid for their certs in good faith, but this is too important an issue to simply let slide just because Symantec has signed a lot of the certificates out there.
"Their proposed action is irresponsible", claims Symantec. Would that be more, or less, irresponsible than letting 30,000 certificates get improperly issued? Symantec: get your systems in order, fix the problems, show us a reason to trust you, and then, maybe you'll have moral grounds to bitch about irresponsible actions.