Why do you think that is true? Cipher suite selection and whitelisting is not a new thing--even if plaintext with CRC32 is in the mix--we deal with it successfully enough in TLS and SSH all the time.
Not quite. Downgrade attacks has been a huge problem for TLS.