Realistically, it doesn't matter. My ISP uses RADIUS for authenticating customers in the access network. If someone manages to intercept messages in the middle of my network, I've got bigger problems. Even if someone does inject in the middle, the worst case is that they can forge packets of residential end users. Those customers are already untrusted, so it really does not matter.