From a security perspective, most issues with modern computer security have absolutely nothing with the TCP/IP protocol. If you take a look at top 10 vulnerabilties (https://www.owasp.org/index.php/Top_10_2013-Table_of_Content...), none of them are directly related to TCP/IP.
It is always easier to look back in hindsight and criticize something knowing what we know today. Saying we should leave design to "grown-ups" is not a fair assessment of TCP/IP and its designers. Engineering is difficult and every design comes with trade-offs.
P.S. If you want to see truly bad protocols, look to ones designed by "professional", "grown-up", organizations. CORBA and anything WS-* are a few that come to mind.
If grown-ups know better they should show us by shipping things. If I can't use it it doesn't exist.
IMHO one of the more general anti-patterns in security is to try to secure the network not the device. It's a fool's errand for many reasons, most notably the fact that there is an intrinsic trade-off between the transparency / audit-ability / firewall-ability of network protocols and the security of the protocol itself. A secure protocol is utterly opaque and therefore cannot be inspected at the perimeter. Secure the device. While it's important to pay attention to your network, if your devices are not secure netsec will not save you.
[1] This wouldn't stop attacks, of course, but it would provide strong enough attribution to create a deterrence effect (at least in The Man's mind).