Dropping TLS in favor of IPSec. Now every protocol is transparently secure by default and there's no chance of developers accidentally messing it up.
http://www.mail-archive.com/cryptography@metzdowd.com/msg123...
https://www.schneier.com/academic/paperfiles/paper-ipsec.pdf
IKE and ISAKMP was the problem, that stuff is an absolute nightmare. Maybe now with IKE2 it might get better...
Could you elaborate?