Just waiting for Minecraft to be so reverse engineered as to be its own protocol with multiple server and client implementations that just work.
replies(2):
most servers leave it enabled because preventing player impersonation is pretty important so people can't just easily grief each other. some piracy servers implemented their own auth on top.