This is so true in practice ;-)
Also a problem I encountered in the wild, is that a potential attacker tries to trick a user into installing a malicious CA Public key as requirement to be allowed past the captive portal.
Unfortunately mitigating this is hard(er) and only mTLS could solve that issue.