This is my main sticking point; for a lot of simple blog-style sites (especially for nonprofits, etc.), not only acquiring a CA-signed certificate, but then maintaining that certificate, renewing it, installing it on a host... these things all need to be made much more easy/simple before HTTPS everywhere can become a reality.