> Nearby patrons, using their phones or laptops, can easily see everything you’re sending or receiving — email and website contents, for example — using free “sniffer” programs.
Is the author assuming the absence of https encryption here, or is there some widely available exploit I don't know about?