(2) The technique that "extended" DNS' security is the same technique that protects plenty of other core Internet protocols, so if it doesn't work at least in the medium term, we're all doomed.
(3) The issue isn't whether DNS is breakable --- it always has been --- it' s how easy it is. The problem is about cost, not about raw capability. If you can't pull the attack off drive-by, it doesn't make a difference in 2009.
(4) Anybody who tries to sell you on a DPI solution to DNS security is scamming you. You'd need a globally deployed network of DPI boxes, all synchronized, to make a dent in the problem.
The current workaround to the DNS spoofing hacks has nothing to do with encryption.
The solution to DNS spoofing has nothing to do with packet inspection (Google for DNSSEC and DNSCurve for details).