" There's a little program for Linux that will make every client authenticate with certificates to the server running the WAP so that spoofing and man-in-the-middle is no longer possible."
You can do the same thing with Windows, to be fair.
But... you must make sure theres no split tunneling, otherwise if you're plugged into a hardwired network, you are bridging the two... your wireless client can be attacked, and the attacker can use your pc to access the hardwires net...
I'm interested for my Windows boxes. To see if they're the same, check out what I was talking about, WaveSEC