I think there are some issues here.
Browser vendors have indirectly created the money sucking machine that is the certification industry by requiring potential root CAs to have been audited to a very thorough standard (e.g. WebTrust).[0] Most of these audits implicitly require dedicated premises, extreme physical security measures, dedicated hardware, multiple dedicated uplinks, 24x7 personnel, and more. Even browsers that don't use their own cert store prop up this system by using the OS store which does require said audits. (And if anyone doubts how instrumental the browsers are to the continuance of this system, imagine how relatively niche the X509 industry would become if they moved to using something else.) As anyone who has tried to grok the documents at [0] will attest, it's a damn scary thing. Honestly you may as well try to start a bank. Or a country.
This level of difficulty creates a monopoly (or oligopoly, to be more precise.) Few people have the will/finance to do it so few do, and those who do get to take the piss with pricing. As I previously wrote[1], this means FOUR companies control the CAs that issue 91% of ALL the internet's TLS certificates.
LetsEncrypt seems like a good thing, and it might be, but it also might not be. It is, underneath all the PR, pretty much just another root CA who holds itself to the same auditing standards. It is no-doubt a very expensive undertaking and as such we may reasonably assume that there will be few, if any, additional zero-cost, fully-supported CAs in the future: and herein lies one problem. Unless you have specific requirements that LetsEncrypt just doesn't support, you have no reason not to use them. So a future CA landscape might be ONE company controlling 99% of the internet's secrets. Oh dear.
What's more, we should not underestimate the importance of cheap shared hosting. The internet is a medium for information and nothing more, and everybody has something that they might wish to broadcast. Currently, deprecating vanilla HTTP is akin to deprecating the ideas of millions of non-experts who rely on shared hosting to participate. We're telling them to join us in the land of VPSs and terminal emulators/Plesk (shudder), or to use one of the many PaaS services we've created over their own homemade solution. This is fundamentally anti-technology, which is supposed to harness innovation and make lives easier. This point is especially pertinent when you consider that the vast majority of these sites probably don't need encryption at all, so it's not even like you can mitigate the pain with direct benefits - because there are none.
Finally, TLS is a pain in the arse to administer. Really - it's not fun. I'm no stranger to it, and even I get a bit of a sinking feeling when it has to be done. To this day I'm bound to using Chrome, because no matter what I do I cannot get Firefox to parse (never mind accept) my NAS's self-signed cert. Requiring TLS across the board is tantamount to requiring many millions of hours of pain across the world.
To hold up some moral torch that does not have universal applicability and actively makes life difficult, and then declare it as canonical truth that all must adhere to is arrogance of the highest order. A great deal of chat in the tech community is dedicated to lambasting short-sighted and ill-conceived laws (think surveillance, copyright, patents, etc.) and yet here we are, making them. We have to do better.
[0]: http://www.webtrust.org/homepage-documents/item27839.aspx
[1]: http://lorddoig.svbtle.com/heartbleed-should-bleed-x509-to-death