@winterschon I'll buy the "it should wrap in SSL by default' as solution.. I hope all the linux stack for this does that by default...

I don't buy the VPN argument; that's not reasonable in practice.