Routelearn.net
Course menu

Unit 11: Wireless FundamentalsLesson 11.3 (3 of 3 in this unit)65 of 84 in the Network Fundamentals course

Wireless security

Radio signals go through walls, so anyone nearby can try to join your Wi-Fi or listen to it. This lesson explains how Wi-Fi keeps them out: the difference between authentication and encryption, the risks of open networks, why WEP is broken, WPA2 Personal and Enterprise, what WPA3 improves, how guest networks work, and a practical checklist for a home and a small office.

Beginner · 17 min read · Before this: Wi-Fi basics, Wireless access points

Wireless security is the set of measures that protect a Wi-Fi network by authenticating who may join and encrypting the frames sent over the air, today mainly WPA2 and WPA3 in Personal (shared passphrase) or Enterprise (802.1X, a login per user) mode.

In simple terms: Radio passes through walls, so Wi-Fi needs a lock on the door (a password or login) and a way to scramble the data, so outsiders can neither join nor read your traffic.

Wireless security is the set of rules that decides who may join a Wi-Fi network and keeps the traffic in the air private. On a wired network, an attacker has to get into the building and plug in a cable. On Wi-Fi, the signal leaks into the car park, the flat next door and the street. Security has to work even when the attacker can receive every radio frame you send.

💡 In simple terms: Wi-Fi without security is like talking loudly in a busy café: anyone at the next table can hear. Wi-Fi security does two things: a door with a lock (only people with the key get in) and a private language (even people who overhear cannot understand).

Why Wi-Fi needs its own security

  • Radio goes through walls. You cannot control who is in range.
  • Listening is invisible. A laptop can capture every frame without sending anything, so you never see it.
  • Joining is easy. Without a lock, anyone in range can join and use your internet, reach your printers, or attack your devices.
  • Fakes are easy. Anyone can set up an access point with your network's name.

Authentication vs. encryption

Two words come up constantly. They solve different problems, and good Wi-Fi security needs both.

AuthenticationEncryption
Question it answersWho are you? Are you allowed in?Can anyone else read or change what you send?
Wi-Fi examplesA shared password (Personal), a username or certificate (Enterprise)AES-CCMP (WPA2), AES-CCMP or GCMP (WPA3)
Without itStrangers can join the networkStrangers can read the traffic in the air
AnalogyShowing your ticket at the doorSpeaking in a code only you and the AP understand

A third goal is integrity: making sure nobody changed a frame on the way. Modern Wi-Fi encryption adds a check value (a message integrity code) to every frame, so a tampered frame is dropped.

Where Wi-Fi security sits

Wi-Fi encryption protects only the radio hop between your device and the access point. The AP decrypts each frame before sending it onto the wired LAN. To protect data all the way to a website, you need end-to-end encryption such as HTTPS (TLS) or a VPN.

WPA3 encryptedinternetLaptop192.168.1.20Access pointWPA3SwitchRouter192.168.1.1Web server203.0.113.80:443
  1. 1. Radio hop: encrypted by Wi-Fi. Someone in the car park can capture these frames but cannot read them.
  2. 2. Wired LAN: Wi-Fi encryption is gone. The AP decrypts each frame and sends a normal Ethernet frame. Wired security is now someone else's job.
  3. 3. End to end: TLS. HTTPS encrypts from the browser all the way to the web server, on top of the Wi-Fi encryption.
Wi-Fi security protects the air. HTTPS and VPNs protect the whole journey.

Open networks and their risks

An open network has no password: anyone can join, and frames are sent without encryption. Many cafés, hotels and airports run open networks, often with a captive portal (the web page where you accept terms or enter a room number). A captive portal controls access to the internet, but it does not encrypt anything.

Eavesdropping

Anyone nearby can capture your frames. Websites using HTTPS stay protected, but any unencrypted app, DNS lookup or old protocol is readable.

Evil twin

An attacker sets up an AP with the same name, such as “Airport-Free-WiFi”. Your device may join it, and all your traffic then passes through the attacker.

Attacks from other guests

Everyone is on the same LAN. Unless the network isolates clients, other guests can reach your device directly.

Session hijacking

If a site or app sends a login cookie without encryption, someone listening can copy it and use your account.

🔓 Newer APs offer Enhanced Open (also called OWE, Opportunistic Wireless Encryption). It still needs no password, but each device gets its own encryption keys automatically, so passive listening no longer works. It does not prove that the AP is genuine, so evil twins are still possible.

The history: WEP, WPA, WPA2, WPA3

WEP: broken, never use it

WEP (Wired Equivalent Privacy, 1997) was the first Wi-Fi security. It used the RC4 cipher with a short 24-bit “initialisation vector” added to the key for each frame. On a busy network those values repeat within hours, and researchers found ways to work out the key from captured frames. Today, free tools recover a WEP key in minutes. Any device that can only do WEP should be replaced or kept off the network.

WPA: a stop-gap

WPA (2003) was a quick fix that could run on WEP-era hardware, using a method called TKIP. It too has known weaknesses and is now deprecated. If your router offers “WPA/TKIP”, do not use it.

WPA2: the long-time standard

WPA2 (2004) introduced strong encryption based on AES, in a mode called CCMP. It comes in two flavours, Personal and Enterprise, explained below. Its encryption is still sound; its main weakness is how the Personal version uses the password.

WPA3: the current standard

WPA3 (2018) replaces the way the password is used with SAE, makes management-frame protection mandatory, and is required on the 6 GHz band. Most devices since about 2020 support it.

WEPWPAWPA2WPA3
Year1997200320042018
EncryptionRC4RC4 with TKIPAES-CCMPAES-CCMP or AES-GCMP
Personal loginShared keyPre-shared key (PSK)Pre-shared key (PSK)SAE
Enterprise loginNo802.1X802.1X802.1X (optional 192-bit mode)
Offline password guessingNot even neededPossiblePossible if the password is weakPrevented
Forward secrecyNoNoNoYes
Status todayBrokenDeprecatedAcceptable with a strong passwordRecommended

WPA2-Personal (PSK): how it works

In Personal mode, everyone uses the same password, called the pre-shared key (PSK) or passphrase. The password itself is never sent over the air. Instead:

  1. Both the client and the AP turn the passphrase and the SSID into a 256-bit master key, the PMK (pairwise master key). Every device with the right password gets the same PMK.
  2. After association, the AP and client run the 4-way handshake. Each side sends a random number (a nonce). From the PMK, both nonces and both MAC addresses, each side calculates a fresh session key, the PTK (pairwise transient key), for this one device.
  3. Each side proves it got the same answer by adding a check value (MIC) to its messages. A wrong password gives a different PTK, the check fails, and the AP rejects the client.
  4. The AP also hands over the GTK (group temporal key), shared by all clients, used for broadcast and multicast frames.
Step 1 of 5 · Message 1: ANonce
Laptop (supplicant)
02:00:00:00:00:51
SSID Home-WiFi
WPA2-Personal
Access point
BSSID 02:00:00:00:a0:01
The WPA2 4-way handshake. The password never crosses the air, but the handshake is enough for an attacker to test password guesses offline.

⚠️ The weakness of WPA2-Personal: an attacker who records one handshake can take it home and try millions of password guesses per second on their own computer, without touching your network again. A short or common password (“password123”, a phone number, a pet's name) falls quickly. A long random passphrase does not. Worse, anyone who knows the password and captured your handshake can decrypt your traffic: there is no forward secrecy.

WPA2-Enterprise (802.1X): a login per person

In Enterprise mode there is no shared Wi-Fi password. Each user or device logs in with its own credentials: a username and password, or better, a digital certificate. This uses IEEE 802.1X, a standard for checking a device before letting it on the network. Three parties are involved:

Supplicant

The client device and its software, asking to be let in.

Authenticator

The access point (or switch). It blocks everything except login messages until it is told the client is allowed.

Authentication server

Usually a RADIUS server, connected to the user directory. It checks the credentials and says yes or no.

The login conversation uses EAP (Extensible Authentication Protocol). Common methods are PEAP (username and password inside an encrypted tunnel) and EAP-TLS (a certificate on each device, the most secure).

Step 1 of 6 · Associate
SSID Office-Staff · WPA2/WPA3-Enterprise
Laptop
Supplicant
Access point
Authenticator
RADIUS server
10.0.0.10

1. Associate · Client ↔ AP

The laptop joins the SSID. The AP only lets EAP login messages through for now.

Alex is on the network
Keys:
Unique to Alex's session
Logged:
Who joined, when, from which AP
Leaves the company:
Disable one account
802.1X: the AP asks a RADIUS server whether each person may join.
Personal (PSK / SAE)Enterprise (802.1X)
CredentialsOne password for everyoneOwn login or certificate per user or device
Extra serversNoneRADIUS server and a user directory
Someone leavesChange the password on every deviceDisable their account
Know who is connectedOnly by device MACBy user name
Best forHomes, very small offices, guest networksBusinesses, schools, anywhere with staff turnover

Enterprise also brings a risk: a device must check the server's certificate. If users are trained to click “Connect anyway” on a certificate warning, an evil twin with a fake RADIUS server can collect their passwords.

WPA3: what it fixes

SAE instead of PSK

WPA3-Personal replaces the pre-shared key method with SAE (Simultaneous Authentication of Equals), sometimes called the Dragonfly handshake. Before the 4-way handshake, the client and AP run an exchange in which both prove they know the password and agree a brand-new random master key, without revealing anything that could be tested offline.

Both sides know the password
Laptop and AP each start from the passphrase, as in WPA2.
SAE exchange (commit and confirm)
Each side sends values that prove it knows the password and creates a fresh secret. Recording them gives an attacker nothing to test guesses against.
New random master key (PMK)
Different every time a device joins, even with the same password.
4-way handshake, then encrypted data
As before, but the starting key cannot be calculated from the password alone.
WPA3-Personal: SAE runs during the 802.11 authentication step, before the 4-way handshake.

No offline guessing

An attacker must interact with your AP for every single guess, which is slow and noticeable. Even a medium-strength password is far safer than with WPA2.

Forward secrecy

Each session's key is random. If your password leaks next year, traffic recorded today still cannot be decrypted.

Protected management frames (PMF)

Required in WPA3. Fake “disconnect” (deauthentication) frames from an attacker are ignored, stopping a common way to kick people off Wi-Fi.

Transition mode

WPA2/WPA3 mixed mode lets old WPA2 devices and new WPA3 devices share one SSID while you upgrade. Older devices keep WPA2's weaknesses.

WPA3-Enterprise works like WPA2-Enterprise with PMF required, and adds an optional 192-bit mode with stronger ciphers for governments and banks.

What an attacker in range can see

Encryption hides the contents of data frames, but not everything. Wi-Fi headers have to stay readable so radios know who a frame is for.

ItemOpen networkWPA2 / WPA3
SSID and beaconsVisibleVisible
MAC addresses in the Wi-Fi headerVisibleVisible (many phones use random MACs for privacy)
Frame size and timingVisibleVisible
IP addresses, ports (e.g. 192.168.1.20 → 198.51.100.53 UDP 53)VisibleEncrypted
DNS names, unencrypted web pages, passwords sent without TLSVisibleEncrypted
HTTPS page contentsEncrypted by TLSEncrypted twice (Wi-Fi + TLS)

Guest networks

A guest network is a separate SSID for visitors. Its job is to give guests internet access without access to your own devices. A good guest network:

  • Uses its own SSID and password (or a captive portal), changed regularly.
  • Puts guests in a separate subnet or VLAN, for example 192.168.50.0/24 instead of the staff 192.168.1.0/24.
  • Has firewall rules allowing only internet access, blocking the internal LAN.
  • Turns on client isolation, so guests cannot reach each other either.
  • Optionally limits bandwidth, so guests cannot slow down work.
two VLANsGuestGuest phone192.168.50.23StaffStaff laptop192.168.1.20Access pointSSIDs: Office-Staff, Office-GuestRouter / firewallguest → internet onlyInternetOffice printer192.168.1.30
  1. 1. Guest to internet: allowed. The guest SSID maps to its own subnet. The firewall lets it out to the internet.
  2. 2. Guest to printer: blocked. A rule drops any traffic from 192.168.50.0/24 to the staff network, so the guest never reaches the printer.
  3. 3. Staff to printer: allowed. Staff devices on Office-Staff are in 192.168.1.0/24 and can print as normal.
Separating guests is a simple form of network segmentation.

This idea of splitting a network into zones with rules between them is covered in depth in Network segmentation and Firewall basics.

Other wireless threats to know

ThreatWhat it isDefence
Evil twinA fake AP copying your SSID to lure devicesWPA3, Enterprise with certificate checks, VPN on public Wi-Fi
Rogue APAn unauthorised AP plugged into your wired network, often by a staff memberWireless scanning, 802.1X on switch ports
Deauthentication attackForged “disconnect” frames that kick users off, often to capture a handshakeProtected management frames (WPA3, or WPA2 with PMF)
WPS PIN attackThe 8-digit “push button / PIN” setup feature can be brute-forcedTurn WPS off
Default router admin passwordAnyone on the network can log in and change settingsSet a unique admin password; update firmware
Password guessingOffline cracking of a captured WPA2 handshakeLong random passphrase; WPA3

🙈 Not real security: hiding the SSID and MAC address filtering. Hidden SSIDs are revealed as soon as a device joins, and MAC addresses travel unencrypted, so an attacker simply copies an allowed one. A hidden SSID can even make your laptop broadcast the network name wherever it goes, looking for it.

A real-world example: the shared office password

A ten-person design studio uses WPA2-Personal with the password Studio2019, written on the kitchen whiteboard. A contractor who worked there last year still has it on his laptop.

  1. Anyone who ever saw the whiteboard can still join, and the password has never changed because changing it means updating every device.
  2. The password is short and guessable, so a captured handshake could be cracked offline.
  3. Because it is WPA2-Personal, anyone with the password who recorded traffic could decrypt it.

The fix: staff move to WPA3-Enterprise (a cloud-hosted RADIUS service tied to their work accounts), so a leaver is removed by disabling one account. Visitors and the contractor get a separate guest SSID with WPA3-Personal and a long passphrase changed every month. The office printer and NAS stay on the staff network only.

When Wi-Fi security goes wrong: troubleshooting

SymptomLikely causeWhat to do
“Can't connect to this network” right after entering the passwordWrong password (case-sensitive), or the saved password is out of date“Forget” the network and re-enter the password carefully
An older device cannot join after switching to WPA3Device only supports WPA2Use WPA2/WPA3 transition mode, or a separate WPA2 SSID for old devices
Device sees the 2.4/5 GHz network but not 6 GHz6 GHz requires WPA3 and a Wi-Fi 6E/7 deviceCheck the security setting and device support
Enterprise login fails or shows a certificate warningWrong credentials, expired account, or the device does not trust the server's certificateCheck the account; install the correct certificate profile. Never accept unknown certificates.
Some clients drop after enabling PMFOld drivers that do not support PMFSet PMF to “optional” (capable) rather than “required”, or update drivers
Guests can see office devicesGuest SSID on the same subnet, no isolationSeparate VLAN/subnet, firewall rules, client isolation

Useful commands

Example output from a Windows laptop (trimmed), written for this lesson
C:\>netsh wlan show interfaces
    Name                   : Wi-Fi
    State                  : connected
    SSID                   : Home-WiFi
    BSSID                  : 02:00:00:00:a0:01
    Radio type             : 802.11ax
    Authentication         : WPA3-Personal
    Cipher                 : CCMP
    Band                   : 5 GHz
    Channel                : 36
    Signal                 : 91%

Authentication shows the security mode actually in use (WPA3-Personal, WPA2-Personal, WPA2-Enterprise, Open). Cipher should be CCMP or GCMP (both AES). If you see WEP or TKIP, fix the router settings.

Example output from a Windows laptop (trimmed; run as administrator), written for this lesson
C:\>netsh wlan show profile name="Home-WiFi" key=clear
Profile Home-WiFi on interface Wi-Fi:
=======================================================================

Security settings
-----------------
    Authentication         : WPA3-Personal
    Cipher                 : CCMP
    Security key           : Present
    Key Content            : maple-river-lantern-orbit-42

Shows the security type and the saved password for a network this PC has joined. Useful when you need the password for another device. It also shows why a laptop left unlocked is a Wi-Fi security risk.

Example output from a Linux laptop using NetworkManager, written for this lesson
$ nmcli -f SSID,SECURITY,SIGNAL dev wifi list
SSID             SECURITY          SIGNAL
Home-WiFi        WPA3              91
Office-Guest     WPA2 WPA3         74
Flat12           WPA2              60
Airport-Free     --                45
Old-Printer      WEP               30

The security of every network in range. -- is an open network; WPA2 WPA3 is transition mode; WEP should never appear on a network you control.

Example output from a Linux laptop using NetworkManager, written for this lesson
$ nmcli dev wifi connect Home-WiFi password wrongpass123
Error: Connection activation failed: Secrets were required, but not provided.

This is how NetworkManager reports a wrong password: the 4-way handshake (or SAE) failed, so it asks for the secret again. Check the password with nmcli connection show Home-WiFi or delete the profile and try again.

Practical checklists

🏠 Home checklist

  • Use WPA3-Personal, or WPA2/WPA3 mixed mode if you have old devices. Never WEP, WPA or TKIP.
  • Set a long passphrase (four or more random words, 16+ characters).
  • Change the router's admin password from the default.
  • Turn off WPS.
  • Keep the router's firmware updated (turn on automatic updates if offered).
  • Put visitors and smart-home gadgets on the guest network.
  • Turn off remote administration from the internet unless you need it.
  • Use HTTPS everywhere, and a VPN on public Wi-Fi.

🏢 Small-office checklist

  • Staff on WPA3-Enterprise (802.1X) if possible, with certificate checks configured on every device.
  • If you must use a shared password: WPA3-Personal, a long passphrase, changed when anyone leaves.
  • A guest SSID in its own VLAN/subnet, internet only, with client isolation.
  • Separate network for printers, cameras and IoT devices.
  • Protected management frames on (required with WPA3).
  • Disable WPS and default admin accounts; update AP firmware.
  • Scan for rogue APs and unknown SSIDs copying your name.
  • Keep a list of APs, SSIDs and who manages them.

Common mistakes

  • Thinking a captive portal is security. It controls internet access but encrypts nothing.
  • Leaving an old WEP or TKIP setting “for compatibility”. One weak setting weakens the whole network.
  • Short or shared-forever passwords. With WPA2 they can be cracked offline, and leavers keep access.
  • Relying on hidden SSIDs or MAC filters. They stop nobody who is trying.
  • Guests on the same LAN as staff. A guest's infected laptop can then reach your file server.
  • Ignoring certificate warnings on enterprise Wi-Fi. That is exactly what an evil twin relies on.
  • Assuming Wi-Fi encryption protects you on the internet. It stops at the access point.
✅ Key takeaways
  • Authentication decides who may join; encryption stops others reading the traffic. Wi-Fi needs both.
  • Open networks are unencrypted; captive portals do not change that. Enhanced Open (OWE) adds encryption without a password.
  • WEP is broken and WPA (TKIP) is deprecated. WPA2 with AES is acceptable; WPA3 is recommended.
  • Personal = one shared password; Enterprise (802.1X + RADIUS) = a login per person.
  • WPA3's SAE stops offline password guessing and gives forward secrecy; PMF blocks forged disconnects.
  • Wi-Fi encryption only covers the radio hop. Use HTTPS or a VPN for the rest of the journey, and keep guests in their own segment.

Knowledge check

Predict · scenario 1

A hotel's Wi-Fi has no password, but asks for your room number on a web page before giving internet access. Is your traffic encrypted over the air?

Predict · scenario 2

An attacker recorded a WPA2-Personal handshake from your network. Your password is “sunshine1”. What can they do at home?

Predict · scenario 3

A company with 80 staff uses one shared Wi-Fi password. An employee leaves on bad terms. Which setup avoids changing the password on every device?

Predict · scenario 4

Your laptop shows Authentication: WPA3-Personal, Cipher: CCMP. You then open an HTTP (not HTTPS) website. Who can read the page?

Predict · scenario 5

A guest's phone on the guest Wi-Fi can print to the office printer. What is the most likely cause?

Where to go next

This completes the Wireless Fundamentals unit. Wireless security is one part of protecting a network: continue with Basic network security, then Firewall basics, VPN basics and Network segmentation. To review the radio side, revisit Wi-Fi basics and Wi-Fi frequency bands.

FAQ

Is WPA2 still safe to use?
WPA2 with AES (CCMP) and a long, random password is still reasonably safe for a home, but WPA3 is better: it resists password guessing and protects past traffic if the password later leaks. Use WPA3, or WPA2/WPA3 mixed mode if you still have older devices. Never use WEP or WPA with TKIP.
Does hiding my SSID or filtering MAC addresses make Wi-Fi secure?
No. A hidden SSID still appears in the frames that devices send when they join, and MAC addresses are sent unencrypted, so an attacker can copy an allowed one. These settings add hassle for you without stopping a real attacker. Strong WPA2 or WPA3 security is what protects the network.
Is public Wi-Fi with a password safe?
Only partly. If everyone in the café shares the same password, anyone who knows it can set up a fake network with the same name. Your HTTPS connections are still encrypted end to end, but use a VPN for extra protection on public Wi-Fi, and avoid ignoring certificate warnings.
What is the difference between WPA2-Personal and WPA2-Enterprise?
Personal uses one shared password for everyone. Enterprise uses 802.1X: every user or device logs in with its own username and password or certificate, checked by a RADIUS server, and each gets its own keys. Enterprise lets you remove one person without changing the password for everybody.