> We should strive to solve both problems, keeping an open internet
I recently looked at HTTP/3 proposals. TLS is required, but you can't use a self-signed certificate: without the CA root it will not connect, and the specifications for HTTP/3 says this should be the default.
This is horrible. It's using security and performance as good excuses to remove features, like how in practice, chrome changes result in extra hurdles for ad blockers.
In my perfect world, the identity problem (is this website really mybank.com?) would be handled at the DNS level (DNSSEC!), and for a new HTTP format based on UDP (great idea!) it would be the http CLIENTS that would each create their own keys and give public keys to the servers.
It would be less risky than a breach of trust down the CA authority, as the traffic would not be decryptable.