Nice writeup - good to see a solution proposed, rather than the same complaints about 'how TLS is broken'!
That said, the key flaw that's raised at the start of the article (how do you know that amazon.de is Amazon) is not really solved with this solution. You still need a trusted third party to bootstrap that first visit.