I think the perfect is being the enemy of the good here.
Personally I would pay for a really good UI for doing that -- just encrypting files so I can stash them safely in cloud storage or transfer really sensitive stuff. I'd love to be able to right-click and encrypt/decrypt with a GPG public key or symmetric passphrase.
I have full disk encryption, but that's very coarse-grained. Unlock the machine and it's defeated. My hack right now is to use encrypted OS X .sparseimage files, but that's OS-specific and clunky. I also have these scripts:
https://raw.githubusercontent.com/zerotier/ZeroTierOne/maste...
https://raw.githubusercontent.com/zerotier/ZeroTierOne/maste...
They kind of suck but do the job in a platform-independent way. They could be made slightly better by trying to secure-erase the original source file, etc., but they work.
The other problem with invisible omnipresent encryption is that it lacks a quality that I call "situational awareness." I like knowing that something has in fact been encrypted. Seeing a file extension change, like gzipping a file, tells me that yes in fact something has happened.
A classic example I use of poor situational awareness in security is IPSec encryption setup between two boxes. The only way I know of to verify that the traffic is actually encrypted is to tcpdump the raw interface and look. The (piss-poor) IPSec tools do not really tell you this in a non-confusing straightforward way.
Right now I solve this by using command line tools or encrypted .sparsebundle images. That sucks.
The key itself can be kept secure using hardware tokens for encryption/decryption/signing. The major problem with that seems to be access across multiple devices. Would it be possible to produce a wireless access token with a secure handshake that could be used for all devices?
I have no idea how we'd get there or how we'd convince people to go along with it.