Earlier quoted context omitted.
The “rent-seeking certificate infrastructure” could be solved if web browsers used the DNS (and DNSSEC) to validate certificates. The DNS, on the other hand, is more tricky. If you want human-readable and globally distinct (and stable) names, you have to have a centralized structure to keep track of who has what name. The best we could come up with was the DNS, which is at least hierarchical instead of completely mon…
Human-readable names can potentially be pseudo-random, and thus securely generated. What's hard (indeed, considered largely infeasible) is meaningful , decentralized, secure names.
It wasn't designed to replace DNS, but there are an increasing number of people using it for that.