I think that's a different attack, where you could passively sniff wifi traffic from networks without WEP. I meant more just hosting your own hotspot with a popular name, forcing clients to connect to it via disconnect/reconnect attacks, and then you're essentially a tiny MITM ISP that can monitor all their unencrypted traffic