Isn't part of the problem that the current wifi encryption standards require client authentication in order to get encryption, but don't normally provide any authentication of the AP. In other words, in order to get a WPA2 encrypted connection I have to provide at least a passphrase (which is a barrier in a public setting), yet I have no assurance that I'm connected to a trusted access point, as opposed to a rogue AP.
Maybe what's needed is something more like HTTPS, where by default the client doesn't need to authenticate, but the certificate provides some assurance that you're connected to the correct site.