Snowden just tweeted:
This attack could have been prevent post-2013, when the @IETF considered including mandatory encryption as part of the new HTTP/2.0 standard. But they blocked it despite explicit warnings that without that protection, users would soon face exactly the attacks we see today.
https:// twitter.com/Snowden/status/972115183572267009