>Anyone can disconnect you
so can someone with a jammer. I'm not sure how a protocol upgrade would protect against that.
>The password can be cracked offline
true, but the solutions presented don't really address the issue. they're variants of key stretching (using a better kdf, mandating stronger passwords, etc.). at the end he mentions "Contemporary cryptography provides tools that could solve this problem.", but that's hand wavy at best. i'm not quite sure it's even possible to implement such a feature in a PSK setting.
>Once you know the password, you can sniff traffic and spoof anyone
>This problem could be solved by using Diffie–Hellman key exchange (DH).
Doubt it. DHE does not offer protection against MITM attacks, which an active attacker can certainly do with a powerful enough antenna.
>From the user's perspective, unless you really know what you're doing, I advise you not to browse any sensitive websites (especially banking) over wireless
this is fearmongering. most "sensitive" websites already use https, which makes this an non-issue.
>It won't let you secure a passwordless network
>How could this be solved? The new WPA security standard could support the "passwordless" mode that requires no authentication, but keeps an encrypted channel of communication so that the anonymous user can identify himself and make traffic only readable by the access point.
how does this protect against MITM? that is, a rogue router pretending to be an hotspot?
> Silly "terms of service" in your cafe can break your applications and expose you to risk
valid point, but already solved: https://en.wikipedia.org/wiki/Hotspot_(Wi-Fi)#Hotspot_2.0