There are two issues. You're arguing that encryption doesn't insure identity, and we know that, and we don't care*. We're arguing that encryption will prevent your ISP, your government, and/or some 3rd-party from reading your traffic. That's all this new, free CA will do.

* really, we don't, because real, charge-what-the-market-will-bear CA's have been delisted for improperly issuing certificates. This is an ongoing, yet separate, problem (see Google's recent ultimatum to Symantec) and you'll never solve both of them at once.

