DNSSEC PKI does not preclude one from hardcoding specific keys in the client as well.
Providing global PKI and enabling end-to-end authentication by default for all clients and protocols certainly would make the internet a safer place.
So now we're running two PKIs? What does the second one do? Why not three?
So now we're running two PKIs? What does the second one do? Why not three?