If I recall correctly even current phones will connect to open wi-fi spots preferentially and/or automatically. Bingo, job MITM done! Bonus points for having a tool on the red-teamers' laptop that can send wi-fi de-auth packets :)
That would be the first thing I would look in to to see if it is still do-able today if the problem was 'hmmmmm. Given the parameters, how could I MITM the blue-teamer?'
I'm sure that others can come up with even wilder ideas involving can-tennas or bird-dogging the blue-teamer into a elevator with a 'running useful and interesting stuff' laptop in a backpack and wait for the blue-teamers' cell phone to start reaching out desperately for a way to remain connected (cell tower, wifi, 2G cell signal etc) either of which might work
If you start on HTTPS and never access plain HTTP resources, it's powerless, otherwise there would be no way to be safe on a public network at all.
sslstrip will still work today on any website that doesn't use HSTS. It will work for the first ever visit (by that browser) of a website that uses HSTS if they aren't on the preload list. A surprising number of websites have neither.
So yes, you can catch a subset of users who type new urls into their address bar, but that's a minority of people a minority of the time.