The monolothic CA model has largely failed, and this draft merely seeks to reorganize it. Apart from "not needing to do business with CAs", that's the only value provided by DANE: your DNS administrators are now your CAs.
This isn't a win; it's a push.
In the short term, the untrustworthy CA problem can be addressed tactically through pinning, which provides key continuity. TACK is a protocol proposed by Trevor Perrin and Moxie Marlinspike to do that using only the insecure DNS we have now.
Over the long term, we need to engage with the fact that this is a UX problem, not a protocol problem. We haven't figured out how to encode the policy decisions we are requiring users to make into browser UIs. Moxie Marlinspike's Convergence system, which is a step towards a web-of-trust style peer-to-peer verification system (it would allow, say, the EFF to create a trust anchor for its followers), is one example of a genuine rethinking of the Internet trust model.
Taking the trust model we have now and baking it into a core Internet protocol seems like exactly the wrong thing to do. Centralized PKI isn't working. The right response isn't "double down on PKI".