Make no mistake, though - the large mining pools are the spacing guild of bitcoin; without them, there is no network.
Unfortunately they (via their users) would not welcome such a switch after so much time and effort and money has already been expended to be able to increase sha256 speed to the point it is at now.
Perhaps this is why Litecoin chose scrypt instead?
Regardless, the proof-of-work we have in Bitcoin today is likely what we'll have in Bitcoin forever, like it or not.
A single lock is much closer to encryption than it is to 'race the world' levels of proof of work.
The security of Bitcoin against double-spending is literally based on wasting so much money that it is unattractive for an attacker to spend a matching amount of money on a double-spend attack. The network must spend this money all the time, though - it can't know in advance when it is being attacked.
An attacker with enough resources can also force the network to either match their spending, or be rendered useless.
Bitcoin is an inherently wasteful system, and it actively resists scaling. There are alternatives, the most proven of which is a centralized ledger run by a trusted third party.
Even if there were no viable alternatives at all, I would still have doubts about the sustainability of the current system. The cost of running the network is just too large compared to the amount of real economic activity.
To go back to the silly analogy, you need a 20 ton lock but you can only use 'cost plus' bidding and all the contractors keep making the lock bigger until they get every possible cent out of the process.
1) There are now more transactions to check.
2) The transactions can be verified by more people now, resulting in a more secure network.
Hell, if bitcoin needs 1000 petaflops just to operate the network when it is still a fringe currency, how exactly is it supposed to scale to mainstream use?
You're incorrect. The proof-of-work requirement is integral to the Bitcoin network, because it makes fraud unprofitable. The amount of computation required to create a block chain longer than the honest one should cost more than the potential benefits of doing so. That said, as far as I know, any proof-of-work algorithm could be used as long as a large portion of clients adopted it, so it should be possible to use work that is useful in itself.
Sure, the perfect currency is valuable. But is such a sheer brute-force approach to security the best we can do?