https://arstechnica.com/security/2017/01/already-on-probatio...
> Ayer discovered the unauthorized certificates by analyzing the publicly available certificate transparency log
That article also links to the primary source, https://www.mail-archive.com/dev-security-policy@lists.mozil... which in turn links to a public viewer for Certificate Transparency logs.