It's easy to sit back and say "oh government this or corporation that sucks", we need to step up our game as builders of the software sitting on millions of devices.
This is a privacy arms race -- and right now we're losing.
I like how ErrataSec put it: "Welcome to Echelon 2.0: Outsourced Edition"
That's what they did with Verizon. Verizon could not provide you with privacy no matter how much they wanted.
However, cryptography does help you as an individual user of a service. There's no reason we can't build systems which are provably secure and retain strict end-user data privacy.
In the end the government can force the OS vendors to install keyloggers.
The ones who make the law always win.
Case in point: "Microsoft’s tweaks to Skype could facilitate wiretapping" http://www.extremetech.com/computing/132935-microsoft-tweaki...
If that has happened or not under the current system we will never know - which is the exact issue the OP was citing.
Fortunately the 1st Amendment is still mostly respected, at least relative to some of the others.
[Edit] Now, monetizing such software is an interesting problem.
Ripple/OpenCoin may have found one model: include a cryptocurrency that's used as credits in the system, and claim a large portion for yourself, which you can later sell. The problem is if they open source the software too early someone could easily create a new network with the currency allocated to themselves.
[Edit] Perhaps that could be solved with a new open source license that forbids forking the network.
* Build infrastructure necessary for other developers to build provably secure products on, license this.
* Free consumer versions, paid/managed versions for corporations and governments.
* Things like secure telephony have business models built in where you could charge per minute (or message) (and probably still be less than incumbent carrier minutes).
The one huge problem I see here is that designing a managed version which could guarantee security against a wiretap order would be quite difficult. In essence you would have to push all key management issues to your users, and that leaves you a lot less to actually manage.