Mēh! We got the entire web, almost, on HTTPS.
How painful is that? (it was hugely painful in the day, but no more)
My point is encrypted by default can work.
The protocols already exist, and the libraries. I think it is a sensible default
But I (probably) am not the one to do it.