Switching to HTTPS everywhere means that we have to drop the traditional CA model; certificates from CAs are just too expensive. (Replacements are either DANE, which depends on DNSSEC, or Namecoin, which replaces the DNS system entirely and has many problems of its own.) Expect all this to be fought tooth and nail.
What is this, 2005? StartSSL offer free SSL certificates that are trusted by all browsers. If that's too cheap, you can get a Comodo certificate through Namecheap for $10 a year...
If you can afford a domain, you can afford an SSL certificate...
Have you not been paying attention to the Heartbleed thing? StartSSL is a scummy company that breaks the rules they've agreed to with browser vendors. I would not trust them if I had a choice in the matter.
I have a bunch of domains which, frankly, I don't care enough about to pay money for an SSL certificate for.