Corollary: operate a rogue AP in a bag with the same SSID and password as a public one and get the clients to connect to you instead of the "real" AP. Getting a stronger signal than it should be easy due to closer proximity. OK, it's no longer a passive attack and can easily be detected if you're looking for it, but if you're even aware of the possibility, you'll be using a VPN anyway. If you're after facebook passwords and the like, this will work well enough.