Re #1, it's way more likely you are visiting a site you've already been to on a new wifi hotspot, so the TOS page will refuse to render if they hijack the domain like that. They'd have to work around that themselves otherwise no one would be able to use their wifi. Maybe a https downgrade attack followed by a redirect to another domain so that they can give you a key that doesn't interfere…