Completely agree with John D. - for guest network WPA-PSK doesn't make sense, especially as now client OS shares with unknown number of "friends" access credentials. So it doesn't make sense to have any static reusable credentials, which will become shared very soon. I see it everyday in some companies, which don't want to use any other solutions, and are located in business centers with a lot of neighbors. They Guest network user number grows steady in time until password is changed, and than start to grow again.
Also you can't provide security to users, which are not interested in security, but want only convenience. You can't force them -- they will do as they want anyway, moving to the own mobile hotspot, and degrading environment for everybody.
So use full client isolation, and filter Internet traffic using UTM device. Clients must use only SSL and/or VPN for any type of sensitive traffic, but it have to be done by user...
It makes not much sense to make too secure Wi-Fi network, when traffic goes through all Internet without any security...
Probably, when HotSpot 2.0 will be widely used, it will solve part of problems, but still security will mostly depend on users.
Unfortunately, most users doesn't care about privacy and / or security, convenience is the king. It is not a technical issue, it's a human nature - so no much chance to change it.
May be this will change a bit when more an more payments will be done by mobile phones -- after user wallet will be emptied couple of times as a result of bad security habits, than there will be a slight chance that habits will change...