1. When I go to google.com, I want to be sure it's the same google.com everyone else connects to.
2. When I go to google.com many more times, I want to get to the same google.com as I was visiting before.
It's relatively easy to do #2 (SSH was doing it for years), but it's very hard task to do #1 correctly. The first problem is essentially a problem of global consensus. It can only be solved using Bitcoin blockchain, poorly simulated with Certificate Authorities, or left alone as SSH did (which is fine for hackers connecting to their own machines, but not fine for global name system).
If anyone is interested in improving SSL/TLS, the way forward is to use blockchain to associate names and public keys so that users could know for sure that they connect to the same name as anyone else without trusting any CAs. Of course, that'd require development not only of a new DNS-meets-SSL protocol, but also robust lightweight Bitcoin nodes and correct UX conventions. That's hard, time consuming, but the only way forward out of the current mess.
Relevant quote from Nick Szabo ("leaving small holes unplugged"): http://blog.oleganza.com/post/69174500046/leaving-small-hole...