>It has become obvious that the PKI system is failing, and the main issue is centralization.
Actually, the problem is exactly the opposite. Any CA can sign a certificate for any domain.
What compounds the problem with the CA system is that CA trust is sticky. When a new CA gets added to trust stores, they are effectively trusted for life. That's not how trust actually works.
What we need is a system that is distributed and that allows for trust to be granted and - most importantly - revoked at will without causing collateral damage (i.e. for innocent sites that end up using a bad CA).
Moxie Marlinspike's convergence[0] was a great idea, but it's never really taken off. TACK[1], also by Marlinspike, looks like nice feature to help transition away from the CA system when we come up with something better.
[0] http://convergence.io/
[1] http://tack.io/