Bands can start their own "labels" on archive.org, https://archive.org/details/netlabels . is that what you had in mind?
The attraction of youtube for almost all listeners is the huge copyrighted collection, which is (mostly) there through artist permission or upload, because the artists get a chunk of the ad revenue. Any serious competitor would also have to somehow deliver a payment stream, which means ads or subscriptions or something. Not really a fediverse thing.
You have it approximately right, serving from an https domain does nothing to authenticate the thing being downloaded. There is such a thing as signed downloads, authenticated by a "code signing certificate", used for things like Windows installers. Linux distros tend to use PGP signatures instead. Signing the download can in principle be a more secure process than serving a domain over https, since servers get pwned all the time. The download signing, by contrast, can in principle be done completely offline. There is a catch to that involving connecting to a timestamp server, but that gets into the weeds.
https://en.wikipedia.org/wiki/Code_signing