It seems the "51% attack" can be mitigated simply by waiting for 6 or more confirmations before sending off merchandise or in the case of an exchange, allowing withdrawal of funds. Those who can't wait that long can rely on 3rd parties who attempt to take on fraud in exchange for transaction fees, similar to the current credit card system.
2) Attacker sends payment to merchant but does not include payment in fork in (1)
3) Attacker waits 6 confirmations then receives goods.
4) Attacker double spends the money in the fork (1).
5) Attacker releases fork when it is longer than the main chain.
If they have greater than 51% they will always be able to do (5) because at some point they'll be longer than the main chain. It doesn't matter how many confirmations the merchant waits for.
How so? Isn't a double spend only possible if the attacker's blockchain fork endures for the customary 6 blocks it takes to confirm a transaction? A single block fork would be ignored by the majority chain and thus the attacker's chain transactions would be useless.