I assumed it was the same risk associated with using the hotel wifi. That's how they identified Broadwell. They knew the IP connecting to the shared GMail account came from a certain hotel on a certain date. Then they looked at other dates where the connection came from a hotel. Then they got all the registered guest lists and found the common guest name. At least that's how the article described the method of identifying Broadwell. The same could be done with airport wifi and passenger lists. Of course it would take more than a one time connection.