Sophos Researcher Suggests Password 'Free' to Spur Wi-Fi Encryption(nakedsecurity.sophos.com)
nakedsecurity.sophos.com
Sophos Researcher Suggests Password 'Free' to Spur Wi-Fi Encryption
http://nakedsecurity.sophos.com/2010/11/09/dear-starbucks-the-skinny-on-how-you-can-be-a-security-hero/
This doesn't address problems with arp-spoofing, fraudulent DHCP servers or fraudulent access points, but it does raise the bar in the complexity of the attack.
HTTPS with a valid signed certificate would still be necessary to deal with the other attacks. Or maybe a VPN connection to a network you trust.