I think if the redirection problem by attackers that are on-path
temporarily is limited to individual unprotected sessions, we are not
materially worse off than today as the same attacker could break the
sessions today also, and redirecting an unprotected session presumably
isn't worse than breaking it as the contents aren't secret.
I think there is a difference between
- someone breaking into to office looking at the pieces of paper on
my desk
- someone breaking into my office and installing a device which allows
them to look at all future pieces of paper I will place on my desk
Thus there is a difference between looking at unprotected communication
while being on the path, and looking at unprotected communication
long after having left the path.
But this might be a case where we can make things be slightly worse
in today's Internet since this communication was unprotected in any