A real-life situation
A café's Wi-Fi uses one password printed on the menu. Someone at the next table runs a capture tool. On a cable they would need to plug into a switch; on Wi-Fi they only need to be in range. What can they see, and what stops them joining or impersonating the café's network? The answers depend entirely on which security the network uses.
The three jobs
- Authentication: prove the client is allowed in (and, ideally, that the network is the real one).
- Encryption (privacy): scramble each frame so only the client and AP can read it.
- Integrity: add a message integrity check (MIC) so a changed frame is detected and dropped.
From WEP to WPA3
| WEP | WPA | WPA2 | WPA3 | |
|---|---|---|---|---|
| Year | 1999 | 2003 | 2004 | 2018 |
| Encryption | RC4, static key | TKIP (RC4, per-packet keys) | AES-CCMP | AES-CCMP; GCMP-256 in 192-bit mode |
| Integrity | CRC-32 (weak) | Michael MIC | CBC-MAC (in CCMP) | CCMP / GCMP |
| Personal mode | Shared WEP key | PSK | PSK | SAE |
| Enterprise mode | – | 802.1X | 802.1X | 802.1X, optional 192-bit mode |
| Management frame protection | No | No | Optional (802.11w) | Required |
| Status | Broken | Deprecated | Acceptable | Recommended |
WEP's short initialisation vector made keys recoverable from captured traffic in minutes. WPA was a firmware upgrade for the same hardware, so it kept RC4 but changed the key for each packet (TKIP). WPA2 moved to AES. WPA3 fixed the weaknesses left in WPA2-Personal and made management frame protection mandatory.
Personal: one shared password
With WPA2-PSK, everyone uses the same passphrase. An attacker who captures one four-way handshake can test millions of guesses offline until one matches, so short passwords fall quickly. And anyone who knows the passphrase and captures a handshake can decrypt that client's traffic.
WPA3-Personal (SAE) replaces the handshake's first step with a password-authenticated key exchange. Each guess needs a live exchange with the AP, so offline guessing doesn't work, and every session gets a fresh key (forward secrecy): knowing the password later doesn't unlock old captures.
Enterprise: 802.1X and EAP
In Enterprise mode every user or device has its own credentials, checked by a RADIUS server. The client (supplicant) and the server talk EAP, relayed by the WLC or AP (authenticator). EAP is a framework; the method decides what is proven:
| EAP method | Server proves itself with | Client proves itself with | Notes |
|---|---|---|---|
| EAP-TLS | Certificate | Certificate | Strongest; needs certificates on every client |
| PEAP | Certificate | Username and password (MSCHAPv2) inside a TLS tunnel | Most common; clients should check the server certificate |
| EAP-TTLS | Certificate | Various inner methods inside a TLS tunnel | Similar idea to PEAP |
| EAP-FAST | PAC (protected access credential), optionally certificate | Username and password inside a tunnel | Cisco-developed, avoids certificates |
| LEAP | – | Username and password (MS-CHAP) | Old Cisco method, vulnerable: don't use |
After EAP succeeds, the RADIUS server sends key material to the WLC, and the four-way handshake creates the session keys exactly as in Personal mode.
Open networks and guests
- Open: no authentication and no encryption. Anyone nearby can read the traffic.
- Enhanced Open (OWE): still no password, but each client gets its own encryption key, so neighbours can't read each other's traffic. It doesn't prove who the AP is.
- Web authentication: a captive portal page for terms, a voucher or a guest login, often on an open or OWE WLAN.
Threats and their defences
| Threat | What happens | Defence |
|---|---|---|
| Eavesdropping | Frames captured from the air | WPA2/WPA3 encryption; OWE on open networks |
| Offline password cracking | A captured PSK handshake is guessed offline | Long passphrases; WPA3-SAE; 802.1X |
| Rogue AP | An unauthorised AP plugged into the wired network | Rogue detection on the WLC, port security, 802.1X on switch ports |
| Evil twin | A fake AP with your SSID collects logins | 802.1X with clients that verify the server certificate; WIPS |
| Deauthentication attack | Forged deauth frames knock clients off | Protected Management Frames (802.11w), required in WPA3 |
Why it works this way
Radio has no walls, so Wi-Fi assumes an attacker can hear and send every frame. Each generation answered a practical attack on the last one: WEP's keys could be recovered, so WPA changed keys per packet; RC4 was weak, so WPA2 used AES; PSK handshakes could be cracked offline, so WPA3 introduced SAE.
Common mistakes
- Choosing "WPA2 with TKIP" for compatibility: TKIP is deprecated and limits speed to 802.11a/g rates.
- Using PEAP without making clients validate the server certificate, which lets an evil twin collect passwords.
- Thinking a hidden SSID or MAC filter replaces encryption.
💡 Exam tip: match each WPA version to its encryption: WPA = TKIP, WPA2 = AES-CCMP, WPA3 = SAE for Personal plus mandatory PMF. Know that 802.1X roles are supplicant, authenticator and authentication server.
Key takeaways
- Wireless security does authentication, encryption and integrity.
- WEP is broken and WPA (TKIP) deprecated; use WPA2 (AES-CCMP) or, better, WPA3.
- WPA3-Personal's SAE stops offline guessing and gives forward secrecy; WPA3 requires PMF.
- Enterprise mode uses 802.1X/EAP with RADIUS: EAP-TLS (certificates), PEAP and EAP-FAST (passwords in a tunnel).
- Enhanced Open (OWE) encrypts open networks without a password.
Check yourself
Which encryption does WPA2 use?
Which WPA3-Personal feature stops an attacker guessing the password offline from a capture?
Which EAP method uses certificates on both the server and the client?
Attackers keep disconnecting clients with forged deauthentication frames. What defends against this?