Use the system as it was intended, people!
Part of the explosion was that domains were not just in one TLD, they were bobfoo.com bobfoo.bar bobfoo.xyz and in many cases regionalized to bobfoo.co.uk or whatever. It wasn't "domain hoarding", because if you registered bobfoo.info you'd just get UDRP'd by corporate anyway, and nobody really wanted domains of the form somelongnamebobfoo.com
This was also before something like LetsEncrypt where you could automatically generate certs for programmatic usage, so they were all done manually.
You'd be surprised
and renewing annually is a great way to accidentally forget some of these and let someone use them to hack your customers
Sadly neither our world not its legal system is built on common sense.