The problem I see is a false sense of security: Users will just see a lock in their address bar and think they're safe -- even if they're on a phishing site with a self-signed certificate.
It appears that users have been conditioned to look out for at least that little lock symbol, so devaluing it now would throw a lot of user training down the drain and give phishers fresh wind.