Earlier quoted context omitted.
I think the real sentiment here is: good PKI is an unsolved (and perhaps unsolvable) problem.
I agree. The CA model is broken (why should I trust a Russian to certify cia.gov?). The Web of Trust model is less broken in some ways, more in others. I think a real solution would be something like a multi-root, score-based system (e.g. if the U.S. government, Underwriters Laboratories & ICANN all state that I'm talking to www.google.com/172.217.13.238, then I honestly probably am) — but I'm worried that it'd be wa…
CAA records help with this, where available, but still leave some things to be desired.