Those new pods could reference existing secrets, be in any namespace (e.g. kube-system), and are exactly the same as root on all k8s nodes.
Because of that, having access to etcd is equivalent to having admin cluster access. The secrets are no more secret if they're encrypted in etcd or not since anyone with access to etcd can launch pods that will decrypt arbitrary secrets.
This is true iwth vault as well. Once secrets are in vault, access to etcd will still result in all secrets being available to the attacker. The threat model is no better.
There are plans to encrypt them in etcd for the sake of them not appearing in backups and because people like you constantly bitch about it, but it doesn't mater and saying they shouldn't be called secrets because of this is FUD.