DNSSEC everywhere would make more sense than HTTPS everywhere, which instead won the hype.
I figure enabling DNSSEC validation everywhere and signing what makes sense after doing a cost/benefit trade off would be the rational way to go. As signing technologies get more mature, the cost goes down and even the marginal benefit of signing everything would be justified.
On wasting cycles, if you only encrypt the sensitive stuff, you give away the fact that you’re communicating sensitive stuff when you encrypt.
However, I suspect this isn’t particularly in the charter of this mailing list…
Regards,
-drc