Didn't the botdev community decide that they most likely only bothered to switch to NLS because of some obscure security flaw -- something that the SID_AUTH_*PROOF packets were supposed to take care of? I don't even remember what information they prove, but I am correct in my assumption, then it seems rather unlikely that they will re-reinvent the login sequence, as far as the packets that are used. We may well see a new version of NLS, though.
[edit] Am I correct in inferring that the client silently discards the unused portion of the packet buffer? I tend to verify that my buffers are empty post-processing for debugging purposes (raise a warning, but continue anyways) for most of my packet handlers.