With the current implementation of SSL, there really is no point in picking one CA over another for security purposes (unless you don't trust a CA with billing, etc. data). In the typical use case of a web browser, any trusted (root) CA can sign certificates for any Common Name/domain - so any government or private entity that can influence a commonly trusted CA can get a valid certificate for any site - irregardless of which CA you chose to trust.
Furthermore, if done properly, your CA will never handle any of your (private) key material, so the CA itself has no special privilege with respect to the communications you sign with the private key, so there is also no reason to pick one here.
The only cryptographic thing they can do right or wrong is to allow easy and hassle free revocation of your certificate in case of a key compromise..
The main factors I would consider in picking a CA are pricing, customer service, acceptance and whether they are recognized as 'extended validation'.
Furthermore, if done properly, your CA will never handle any of your (private) key material, so the CA itself has no special privilege with respect to the communications you sign with the private key, so there is also no reason to pick one here.
The only cryptographic thing they can do right or wrong is to allow easy and hassle free revocation of your certificate in case of a key compromise.. The main factors I would consider in picking a CA are pricing, customer service, acceptance and whether they are recognized as 'extended validation'.