Why not to add secure NTP support to make NTP more secure or even migrate to DNS-based time?

Because NTP is a de-facto standard and this attack would only cause problems if you use it in server-mode; which most people don't do anyway.

We are still talking about end-user devices. Not military grade. And it is needed to be added to OpenWrt first.