What you're describing as "good censorship" doesn't actually require any censorship at all. All you need is a mechanism to notify users (or their client software) that a name is designated as malicious. Then the user or the user's client can decide what to do with that information, including ignoring the designation and connecting to the address anyway. That way it can't be used for censorship but it can be used to put ye olde red screen of malware alert in front of the user.
You obviously need someone to maintain the blacklist. That party could sign their work. If they do a poor job (false positives / false negatives), users and makers of client software can switch to some other blacklist maintainer at any time.
What you're describing as "good censorship" doesn't actually require any censorship at all. All you need is a mechanism to notify users (or their client software) that a name is designated as malicious. Then the user or the user's client can decide what to do with that information, including ignoring the designation and connecting to the address anyway. That way it can't be used for censorship but it can be used to put ye olde red screen of malware alert in front of the user.