Corollary: operate a rogue AP in a bag with the same SSID and password as a public one and get the clients to connect to you instead of the "real" AP. Getting a stronger signal than it should be easy due to closer proximity. OK, it's no longer a passive attack and can easily be detected if you're looking for it, but if you're even aware of the possibility, you'll be using a VPN anyway. If you're after facebook passwords and the like, this will work well enough.
Isn't part of the problem that the current wifi encryption standards require client authentication in order to get encryption, but don't normally provide any authentication of the AP. In other words, in order to get a WPA2 encrypted connection I have to provide at least a passphrase (which is a barrier in a public setting), yet I have no assurance that I'm connected to a trusted access point, as opposed to a rogue AP.
Maybe what's needed is something more like HTTPS, where by default the client doesn't need to authenticate, but the certificate provides some assurance that you're connected to the correct site.
WPA(2)-EAP ("WPA enterprise") has supported this for years. It also has other advantages, such as supporting multiple usernames, each with their own password. It also works on most existing client devices (iPhones, etc.) I use it at home; unfortunately, very few APs have a built-in authentication server for it, so you need to run FreeRADIUS on some always-on Linux/BSD device.