Is there a cure-all for kleptography?
Algorithms and protocols already exist that could greatly reduce the threats of certain subliminal channels and kleptographic attacks. It isn’t safe to say that these have achieved “cure-all” status, but they are certainly solid measures that could be taken. They have yet to be adopted in industry standards, let alone de facto industry standards. By their very nature kleptographic attacks are designed not to be found. Combine with this with the habit that organizations have of covering up attacks to avoid embarrassment, and you have a problem that could be lurking behind the scenes for a very long time.