> Nothing is as cheap as hardware-accelerated AES.
Yes, and at the same time all of modern crypto is incredibly cheap and can be added as wished on almost every application without any visible extra costs.
So the answer to the GP is not that trivial one. The actual answer is about software complexity making errors more likely, and similar encryption schemes not really adding any resiliency.