Following up on #111: on second thought and some discussion, I think that we should reinstate slow-retrieval attacks in the spec, but only if we make it optional (because not everyone has control over their network stacks), and make it clear how to do so (e.g., moving average download speed must be X bytes/sec).
What do others think?