In this post it is stated that the supplicant (entity who wants to connect) identifies the Access point by its SSID as it would do for any wireless network.
This post says that a de-auth can be sent to a connected client to get the SSID of the network. Am I correctly assuming that the AP does not send its SSID to the world but clients still need to know the SSID to use it during the authentication process?
According to this post a client automatically tries to connect to a network he knows. Does this imply that if I know (as an attacker) the password of a (hidden or non-hidden) wifi network that I can just open a rouge AP – in best case with higher signal strengths – and then all clients having this network "saved" will automatically connect to it?