SSL certs are an utter commodity, and generally the CA system is a broken system, but we'd be a lot better off with free "real" SSL certs everywhere rather than a bunch of self signed stuff. The loss here is the large number of applications with self-signed certs on the Internet, as well as the general hassle involved in purchasing and renewing certs for everyone who does.
The cost of having a well-run base CA is small number of millions to set up and maybe $1-2mm/yr. It would do a lot more good than many other charities. The marginal costs to do mail-from auth S/MIME and domain-verify certs would be limited.
I used to think StartCom was a good solution for this, but after recent staff departures, and their shortsighted-at-best policy here, I can't recommend them.
With commercial CAs, people use wildcard certs in a lot of places where they should be using distinct other certs. It's maybe not an issue for https for main company websites ($49/yr isn't too big a deal), but I want people to use real certs for START TLS email, client certs, etc. I also want one CA to be really popular, or at least one simple cert-issuance protocol to be popular, so "automatically generate a cert and CSR and get the cert loaded" becomes an automatic part of software setup.
I'm kind of surprised Google hasn't done this, in exchange for people proving ownership of a Google+ account or something. FB, Twitter, etc. could all easily bury the costs of a genuinely free CA.