So perhaps this should start with a reduction in the cost of valid, "don't throw a security warning" certificates down to zero. At the moment the SSL certificate industry is one big ripoff fest...
And then people will complain that the CA is not required to revoke certificates that it issued for free when their keys become compromised.
What is people’s idea of DANE? DNSSEC adoption seems slow at the moment, but otherwise it appears to be a valid approach to this whole distributing-public-keys issue?