Peter,
You're absolutely right that authentication is valuable in many contexts.
Certainly no one is suggesting that we abandon that option.
We use envelopes for privacy in paper mail. There's no authority
verifying the envelopes really come from the return address, and no one
seems concerned about it. This is much more private than postcards from
an authentic address, which is all PEM seems to require.
For those who are concerned about key spoofing, it makes sense to specify
how authentication will work. But to make authentication mandatory, while
confidentiality is only optional, simply doesn't meet our goals.
Doug