>Do not use anything on public WiFi unless the security patches are current.
That's good advice for going online in general but nothing about public wifi makes this particularly more dangerous.
>Android [can] have better defenses than a Windows laptop:
>- Android has MAC randomization.
Windows has that too [1]
>- The Bromite fork of Chrome has DNS-over-HTTPS options in settings (I think Chrome requires a command line option to configure DoH, but I don't use Chrome so I'm not sure). ISPs hate DoH. Be aware that non-browser apps will use regular DNS. Some public WiFi blocks DoH (I'm configured for OpenDNS), so be ready to fall back to another browser using regular DNS.
You are conflating Chromium and Chrome but all Chromium based browser have this under security settings [2]
>- Bromite has an option to always check for https - enable it.
Again this is all Chromium browsers under security settings [2]
>- Tor Browser is a bit easier to get on Android.
Huh? [3]
>- SMTP has an opportunistic TLS exchange that can be thwarted, so I wouldn't use it.
You aren't using SMTP directly from a consumer ISP connection anyways. If the ISP doesn't drop the traffic, the server you are connecting to will probably reject the message as spam.
>- For me, I would wipe the stock OS off the device and run Lineage de-Googled.
Sure that's great if you are privacy conscious but has no bearing on whether public wifi is safe. If anything, one could argue you are slightly less safe since Google tends to be very aggressive about signing and certificate pinning so you could be more more likely to notice if someone is doing an MITM.
[1] https://support.microsoft.com/en-us/windows/how-to-use-rando...
[2] chrome://settings/security
[3] https://www.torproject.org/download/