If you're starting a new commercial venture, something that cost $1000 and took a week would still be one of the cheapest and fastest parts of that process. If you're doing a hobby project or a speculative startup, using a subdomain would be fine. It worked for Altavista.digital.com and Google.stanford.edu.
The argument for shifting (back) to a model like that would be that the hierarchial DNS served as a chain of responsibility. Today a lot of companies irresponsibly use dozens of domains, presumably either because they think people are too stupid to learn to type an additional period in a name, or because their internal dysfunction makes provisioning a subdomain an 11-month project. It's terrible that citibankonline.com, citibank.com, citicards.com, citientertainment.com, citi.com, and citigroup.com are all official domains that Citigroup uses. A user seeing a link to, say, 'citicardbenefits dot com' has zero methods of establishing provenance.
And of course, under conditions where 2LDs were expensive again, 'free subdomains' would certainly still be a thing, as they even back were when .coms were $50 or whatever. We had cjb.net, a bunch of clever '.to' domains, afraid.org, etc.
Under the 'modern' system, the problem of "who do we need to contact about an obvious scam site" has been pushed up to the largest possible scale - the GTLD registries, whereas a scammer abusing a "free subdomain" would be shut down by the admins at that second level.
In the end though, I admit we're stuck with the current way, or, (possibly) some hare-brained KYC scheme that will subject everyone to a high level of government censorship and make anonymity unavailable to good actors who really deserve it.