All this talk about what CF should do, I'm surprised they didn't mention the most obvious step to take: offering an SSL mode that lets you configure what host name to validate the origin as. This would work perfectly for anyone using GitHub pages, cloud front, hyperdev, etc etc etc, all of which have valid ssl Certs, just not for your origin but for theirs.
Am I missing an obvious reason for this not being an option? It must have crossed their minds at some point..?
(Edit: come to think of it, iirc cloud front does support wild card ssl for your own domain these days?)