HTTPS is great. Unfortunately most think you need to be blessed by a browser root program and CA to use it. Part of that capture has been mitigated by Let’s Encrypt (thank god) and there are other schemes like DANE (domain authentication of named entities) where you can self-generate and self-register your own cert using DNSSEC. But the browser vendors/CAs have little interest in implementing because that cuts them out of the authority loop.
It’s not so much centralization I am worried about; it’s more about authority-creep that leads to centralization.