Getting owned wise - maybe. Privacy wise - no. Not all web traffic is HTTPS, way too much of it still isn't. Not everything is HTTP(S) even, some nastiness comes from other protocols. DNS is still rarely encrypted. NTP basically* isn't encrypted. And all those combined allow a lot of privacy-invasive profiling to be done. Without WPA3 public, it's also passive and you have no clue.
Its still fairly easy to spoof APs. 802.11w aims to prevent this but support is spotty. And a spoofed AP means now the attacker has access to things that would normally gated behind NAT. Although with use of social engineering, you can set up a gateway page that says something like "Log in to Facebook for free wifi", bypassing the need for any exploits.
Even with 802.11w it's easy to impersonate APs, 802.11w doesn't protect against evil twins. I find it a massive pity that we can't freeload off of web PKI to authenticate AP's.