Hi Brett,
Thank you for your concern on this. A few things to reassure you:
We don’t use linux and don’t use wpa_supplicant which is the most affected by the vulnerabilities that were disclosed by KRACK.
We don’t use HTTP/HTTPS for communications with our servers so tools like sslstrip that try to trick a user into downgrading from HTTPS to HTTP wouldn’t work.