DNS can be trivially MITM'd as well, it's certainly not a secure mechanism for distributing keys.

You just taken down the whole business of dns validated CA issued certificates. Go claim your bounty. :)