(1) They don't check whether the WiFi network has been secured.Think they want you to do it over a strong secure wifi signal.
So you don[']t get any corrupt data on download.
(2) Any communication channel is secure if the communication is properly encrypted end-to-end.
(3) A cryptographic checksum verifies that the bits you receive are identical to the bits that were transmitted. Your phone won't install new firmware unless the checksum proves the data's integrity.