DNSSEC is a Government-Controlled PKI -> Not if the root of trust is secured by a proof-of-work blockchain
DNSSEC is Cryptographically Weak -> Not if zone operators upgrade to ECDSA as defined for DNSSEC in https://tools.ietf.org/html/rfc6605
DNSSEC is Unsafe -> NSEC3 is mentioned by the article itself
DNSSEC is Expensive To Deploy -> We can make tools for this, so much has gotten easier already
DNSSEC is Incomplete -> Agreed, we need browser adoption