"“lack of native file-based encryption unfortunately makes it a nonstarter"
Yeah - because we really want embed (lots of incompatible, independently developed implementations of) encryption within the filesystem rather than using well managed code sitting on top or beneath the it.