That makes sense. The downside is that now if said CA has some interests in whether to re-issue a certificate or not, we have a problem. Imagine that Cloudfare decides you are a bot and doesn't allow you to visit pages. You are going to have a problem because a lot of websites use it
I think the idea of a CA is good but it should be distributed somehow
Yeah, of course. Every solution has pros and cons, you gotta settle on the best one for the world you live in.
CAs are quite distributed already. You probably have a couple dozen or even a hundred different root CAs installed right now, and you can install whatever ones you like if necessary.