> 3. An attacker with a valid certificate can strip dnssec-chain-extension out of a TLS handshake.
That's true but decentralized namespaces are at least starting with a clean slate they could require this extension no CA is issuing names for those anyway.
For names that rely on WebPKI this standard could be less strict about pinning initially (treating DNSSEC as just another CA). Once there's more adoption in a few years browsers should look for it and fallback to querying the DNSSEC chain (could be included with an edns option RFC7901).