For a true security fix, the default for check_hostname would have to be True.  However, that will create a lot of backward compatibility problems for questionable gain.

I think Larry should make an exception for 3.4 and allow this new feature.
