I still think a decentralized DNS alternative could scale, if done the right way. I also think that the majority of sites would be more secure if they used a system like ssh to deal with certificates, and government-controlled trust chains should be left for banking and other "official" stuff.
I'm working on something like this with Dap[1] (full disclosure, I used to be heavy into the Handshake[2] ecosystem). Where previous alt-roots failed is having nothing to build on it. Lots of marketing about how "things will be different" this time while providing nothing in the way of getting developers building experiences atop this new naming system.
Claiming your root is more secure isn't enough, what can people DO with it and WHY should they care? I've ranted enough about this to deaf ears over a half decade to no avail. Even if Dap doesn't end up being the first credible alt-root, I do hope something appears and is not immediately linked to (objectively) illegal/evil activity.