whatever became of it? I thought at the time security experts would swarm and dissect it to death to give us articles after articles of concrete tampering examples... but it just vanished?
I do run DHCP/NTP/etc on that subnet, but those services are running in FreeBSD Jails connected to the host OS with vnet(9) "epair" interfaces given RFC3021-style /31 addresses (and/or the IPv6 equivalent) and firewalled with PF on the host-OS side such that none of them have the ability to explore any other parts of my network if they get popped :)