1. HandyBrowser (supports handhshake): https://github.com/HandyMiner/HandyBrowser
2. TorBrowser: https://www.torproject.org/
3. Opera: https://unstoppabledomains.com/opera
4. Status.im: https://status.im/
5. Brave: https://brave.com/
6. Unstoppable: https://unstoppabledomains.com/browser
7. Blockstack: https://blockstack.org/install
Probably few more - maybe dozens.
For major DNS providers, nextdns supports handshake.
Some people know and can use chose their DNS , many have to rely whatever dns their ISP or corporate IT provides . Very hard to move all that to common new standard
Browsers esp chrome/safari as it is modify the URL way more than I am comfortable with .
As bad as ICANN is I really don’t want Apple and google dictating how dns should run
Consider modern hosting: Load balancers, CDNs, etc all configured and deployed on-demand, with the IPs changing as frequently as the provider likes.
Sure, Amazon lets you get static IPs.. but now I want to re-point traffic at another region because this region is failing, or down for maintenance... sorry, no, can't do that.
Anyone doing even moderate amount of hosting/whitelabelling doesn't have anywhere the IPs they need.
To address the original concern, all we'd have to do is throw out the ICANN root and replace it with a root controlled by a new NOTICANN organization. People were already talking about this when the .org debacle was still playing out.
It might even be healthy for the internet to do this every so often as a warning to those who would dare to try something like this again. They serve at our pleasure.
We're all just agreeing to use their root for convenience. As soon as it stops being convenient, we can literally just decide to give it to someone else.
Answer to Q2: No. They have mass cooperation from network admins and DNS software authors to use ICANN roots.
Answer to Q3: Go for it. I have been running a non-ICANN root for myself over 20 years.