The flip side is: Just imagine if Kerberos 1.0 with 40-bit DES was baked into X11 or even IPv4. We'd still be fighting those downgrade attacks. Or maybe we'd be layering real encryption over the broken-but-unremovable encryption, with all the overhead that entails.