The author lists legitmate motivations for why people want to see 100% SSL adoption.
The CA system also began with such good intentions. But motivations for profit enveloped good intentions. Certificates became a business, and the quality of the software became an afterthought.
The same may be or is happening with SSL/TLS deployment. With a function such as encryption, one cannot ignore software quality. Poor quality can defeat the whole purpose of the software. There is no point in using bad encryption software.
One of the good intentions the author cites is that people want ubiquitous encryption. Is encryption synonymous with SSL? Why? SSL is not the only system ever written to encrypt internet traffic. And it is probably far from the best one that could be written.
Nothing wrong with the good intentions. But is SSL is an asset or a liability? There is a cost to taking on SSL's baggage of complexity and maybe it's only worth it if the benefit achieved is real and not illusory.
If SSL can so easily be exploited, then the false sense of security it's name inspires may cause more problems
than SSL solves. But that's only for users. Others with purely commmercial goals stand to profit immensely from SSL adoption, the same way businesses did from CA certificates.
SSL was not created with the intent to protect non-commercial communications. It was created in the 1990's by Mozilla to allow for "e-commerce" using their Netscape browser. It served it purpose.
SSL is old and people are attempting to retrofit it with "improvements". Such as being able to host multiple sites with one wildcard certificate on one IP address. This is a hack. It's called SNI and it breaks a lot of software. People should consider why such a "feature" even needs to be implemented. Is it for the benefit of the user? The CA business has become nothing more than an impediment for many people.
Costs vs benefits. Not just for business but for users.