Wireless security is the set of rules that decides who may join a Wi-Fi network and keeps the traffic in the air private. On a wired network, an attacker has to get into the building and plug in a cable. On Wi-Fi, the signal leaks into the car park, the flat next door and the street. Security has to work even when the attacker can receive every radio frame you send.
💡 In simple terms: Wi-Fi without security is like talking loudly in a busy café: anyone at the next table can hear. Wi-Fi security does two things: a door with a lock (only people with the key get in) and a private language (even people who overhear cannot understand).
Why Wi-Fi needs its own security
- Radio goes through walls. You cannot control who is in range.
- Listening is invisible. A laptop can capture every frame without sending anything, so you never see it.
- Joining is easy. Without a lock, anyone in range can join and use your internet, reach your printers, or attack your devices.
- Fakes are easy. Anyone can set up an access point with your network's name.
Authentication vs. encryption
Two words come up constantly. They solve different problems, and good Wi-Fi security needs both.
| Authentication | Encryption | |
|---|---|---|
| Question it answers | Who are you? Are you allowed in? | Can anyone else read or change what you send? |
| Wi-Fi examples | A shared password (Personal), a username or certificate (Enterprise) | AES-CCMP (WPA2), AES-CCMP or GCMP (WPA3) |
| Without it | Strangers can join the network | Strangers can read the traffic in the air |
| Analogy | Showing your ticket at the door | Speaking in a code only you and the AP understand |
A third goal is integrity: making sure nobody changed a frame on the way. Modern Wi-Fi encryption adds a check value (a message integrity code) to every frame, so a tampered frame is dropped.
Where Wi-Fi security sits
Wi-Fi encryption protects only the radio hop between your device and the access point. The AP decrypts each frame before sending it onto the wired LAN. To protect data all the way to a website, you need end-to-end encryption such as HTTPS (TLS) or a VPN.
- 1. Radio hop: encrypted by Wi-Fi. Someone in the car park can capture these frames but cannot read them.
- 2. Wired LAN: Wi-Fi encryption is gone. The AP decrypts each frame and sends a normal Ethernet frame. Wired security is now someone else's job.
- 3. End to end: TLS. HTTPS encrypts from the browser all the way to the web server, on top of the Wi-Fi encryption.
Open networks and their risks
An open network has no password: anyone can join, and frames are sent without encryption. Many cafés, hotels and airports run open networks, often with a captive portal (the web page where you accept terms or enter a room number). A captive portal controls access to the internet, but it does not encrypt anything.
Eavesdropping
Anyone nearby can capture your frames. Websites using HTTPS stay protected, but any unencrypted app, DNS lookup or old protocol is readable.
Evil twin
An attacker sets up an AP with the same name, such as “Airport-Free-WiFi”. Your device may join it, and all your traffic then passes through the attacker.
Attacks from other guests
Everyone is on the same LAN. Unless the network isolates clients, other guests can reach your device directly.
Session hijacking
If a site or app sends a login cookie without encryption, someone listening can copy it and use your account.
🔓 Newer APs offer Enhanced Open (also called OWE, Opportunistic Wireless Encryption). It still needs no password, but each device gets its own encryption keys automatically, so passive listening no longer works. It does not prove that the AP is genuine, so evil twins are still possible.
The history: WEP, WPA, WPA2, WPA3
WEP: broken, never use it
WEP (Wired Equivalent Privacy, 1997) was the first Wi-Fi security. It used the RC4 cipher with a short 24-bit “initialisation vector” added to the key for each frame. On a busy network those values repeat within hours, and researchers found ways to work out the key from captured frames. Today, free tools recover a WEP key in minutes. Any device that can only do WEP should be replaced or kept off the network.
WPA: a stop-gap
WPA (2003) was a quick fix that could run on WEP-era hardware, using a method called TKIP. It too has known weaknesses and is now deprecated. If your router offers “WPA/TKIP”, do not use it.
WPA2: the long-time standard
WPA2 (2004) introduced strong encryption based on AES, in a mode called CCMP. It comes in two flavours, Personal and Enterprise, explained below. Its encryption is still sound; its main weakness is how the Personal version uses the password.
WPA3: the current standard
WPA3 (2018) replaces the way the password is used with SAE, makes management-frame protection mandatory, and is required on the 6 GHz band. Most devices since about 2020 support it.
| WEP | WPA | WPA2 | WPA3 | |
|---|---|---|---|---|
| Year | 1997 | 2003 | 2004 | 2018 |
| Encryption | RC4 | RC4 with TKIP | AES-CCMP | AES-CCMP or AES-GCMP |
| Personal login | Shared key | Pre-shared key (PSK) | Pre-shared key (PSK) | SAE |
| Enterprise login | No | 802.1X | 802.1X | 802.1X (optional 192-bit mode) |
| Offline password guessing | Not even needed | Possible | Possible if the password is weak | Prevented |
| Forward secrecy | No | No | No | Yes |
| Status today | Broken | Deprecated | Acceptable with a strong password | Recommended |
WPA2-Personal (PSK): how it works
In Personal mode, everyone uses the same password, called the pre-shared key (PSK) or passphrase. The password itself is never sent over the air. Instead:
- Both the client and the AP turn the passphrase and the SSID into a 256-bit master key, the PMK (pairwise master key). Every device with the right password gets the same PMK.
- After association, the AP and client run the 4-way handshake. Each side sends a random number (a nonce). From the PMK, both nonces and both MAC addresses, each side calculates a fresh session key, the PTK (pairwise transient key), for this one device.
- Each side proves it got the same answer by adding a check value (MIC) to its messages. A wrong password gives a different PTK, the check fails, and the AP rejects the client.
- The AP also hands over the GTK (group temporal key), shared by all clients, used for broadcast and multicast frames.
⚠️ The weakness of WPA2-Personal: an attacker who records one handshake can take it home and try millions of password guesses per second on their own computer, without touching your network again. A short or common password (“password123”, a phone number, a pet's name) falls quickly. A long random passphrase does not. Worse, anyone who knows the password and captured your handshake can decrypt your traffic: there is no forward secrecy.
WPA2-Enterprise (802.1X): a login per person
In Enterprise mode there is no shared Wi-Fi password. Each user or device logs in with its own credentials: a username and password, or better, a digital certificate. This uses IEEE 802.1X, a standard for checking a device before letting it on the network. Three parties are involved:
Supplicant
The client device and its software, asking to be let in.
Authenticator
The access point (or switch). It blocks everything except login messages until it is told the client is allowed.
Authentication server
Usually a RADIUS server, connected to the user directory. It checks the credentials and says yes or no.
The login conversation uses EAP (Extensible Authentication Protocol). Common methods are PEAP (username and password inside an encrypted tunnel) and EAP-TLS (a certificate on each device, the most secure).
1. Associate · Client ↔ AP
The laptop joins the SSID. The AP only lets EAP login messages through for now.
- Keys:
- Unique to Alex's session
- Logged:
- Who joined, when, from which AP
- Leaves the company:
- Disable one account
| Personal (PSK / SAE) | Enterprise (802.1X) | |
|---|---|---|
| Credentials | One password for everyone | Own login or certificate per user or device |
| Extra servers | None | RADIUS server and a user directory |
| Someone leaves | Change the password on every device | Disable their account |
| Know who is connected | Only by device MAC | By user name |
| Best for | Homes, very small offices, guest networks | Businesses, schools, anywhere with staff turnover |
Enterprise also brings a risk: a device must check the server's certificate. If users are trained to click “Connect anyway” on a certificate warning, an evil twin with a fake RADIUS server can collect their passwords.
WPA3: what it fixes
SAE instead of PSK
WPA3-Personal replaces the pre-shared key method with SAE (Simultaneous Authentication of Equals), sometimes called the Dragonfly handshake. Before the 4-way handshake, the client and AP run an exchange in which both prove they know the password and agree a brand-new random master key, without revealing anything that could be tested offline.
No offline guessing
An attacker must interact with your AP for every single guess, which is slow and noticeable. Even a medium-strength password is far safer than with WPA2.
Forward secrecy
Each session's key is random. If your password leaks next year, traffic recorded today still cannot be decrypted.
Protected management frames (PMF)
Required in WPA3. Fake “disconnect” (deauthentication) frames from an attacker are ignored, stopping a common way to kick people off Wi-Fi.
Transition mode
WPA2/WPA3 mixed mode lets old WPA2 devices and new WPA3 devices share one SSID while you upgrade. Older devices keep WPA2's weaknesses.
WPA3-Enterprise works like WPA2-Enterprise with PMF required, and adds an optional 192-bit mode with stronger ciphers for governments and banks.
What an attacker in range can see
Encryption hides the contents of data frames, but not everything. Wi-Fi headers have to stay readable so radios know who a frame is for.
| Item | Open network | WPA2 / WPA3 |
|---|---|---|
| SSID and beacons | Visible | Visible |
| MAC addresses in the Wi-Fi header | Visible | Visible (many phones use random MACs for privacy) |
| Frame size and timing | Visible | Visible |
IP addresses, ports (e.g. 192.168.1.20 → 198.51.100.53 UDP 53) | Visible | Encrypted |
| DNS names, unencrypted web pages, passwords sent without TLS | Visible | Encrypted |
| HTTPS page contents | Encrypted by TLS | Encrypted twice (Wi-Fi + TLS) |
Guest networks
A guest network is a separate SSID for visitors. Its job is to give guests internet access without access to your own devices. A good guest network:
- Uses its own SSID and password (or a captive portal), changed regularly.
- Puts guests in a separate subnet or VLAN, for example
192.168.50.0/24instead of the staff192.168.1.0/24. - Has firewall rules allowing only internet access, blocking the internal LAN.
- Turns on client isolation, so guests cannot reach each other either.
- Optionally limits bandwidth, so guests cannot slow down work.
- 1. Guest to internet: allowed. The guest SSID maps to its own subnet. The firewall lets it out to the internet.
- 2. Guest to printer: blocked. A rule drops any traffic from 192.168.50.0/24 to the staff network, so the guest never reaches the printer.
- 3. Staff to printer: allowed. Staff devices on Office-Staff are in 192.168.1.0/24 and can print as normal.
This idea of splitting a network into zones with rules between them is covered in depth in Network segmentation and Firewall basics.
Other wireless threats to know
| Threat | What it is | Defence |
|---|---|---|
| Evil twin | A fake AP copying your SSID to lure devices | WPA3, Enterprise with certificate checks, VPN on public Wi-Fi |
| Rogue AP | An unauthorised AP plugged into your wired network, often by a staff member | Wireless scanning, 802.1X on switch ports |
| Deauthentication attack | Forged “disconnect” frames that kick users off, often to capture a handshake | Protected management frames (WPA3, or WPA2 with PMF) |
| WPS PIN attack | The 8-digit “push button / PIN” setup feature can be brute-forced | Turn WPS off |
| Default router admin password | Anyone on the network can log in and change settings | Set a unique admin password; update firmware |
| Password guessing | Offline cracking of a captured WPA2 handshake | Long random passphrase; WPA3 |
🙈 Not real security: hiding the SSID and MAC address filtering. Hidden SSIDs are revealed as soon as a device joins, and MAC addresses travel unencrypted, so an attacker simply copies an allowed one. A hidden SSID can even make your laptop broadcast the network name wherever it goes, looking for it.
A real-world example: the shared office password
A ten-person design studio uses WPA2-Personal with the password Studio2019, written on the kitchen whiteboard. A contractor who worked there last year still has it on his laptop.
- Anyone who ever saw the whiteboard can still join, and the password has never changed because changing it means updating every device.
- The password is short and guessable, so a captured handshake could be cracked offline.
- Because it is WPA2-Personal, anyone with the password who recorded traffic could decrypt it.
The fix: staff move to WPA3-Enterprise (a cloud-hosted RADIUS service tied to their work accounts), so a leaver is removed by disabling one account. Visitors and the contractor get a separate guest SSID with WPA3-Personal and a long passphrase changed every month. The office printer and NAS stay on the staff network only.
When Wi-Fi security goes wrong: troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| “Can't connect to this network” right after entering the password | Wrong password (case-sensitive), or the saved password is out of date | “Forget” the network and re-enter the password carefully |
| An older device cannot join after switching to WPA3 | Device only supports WPA2 | Use WPA2/WPA3 transition mode, or a separate WPA2 SSID for old devices |
| Device sees the 2.4/5 GHz network but not 6 GHz | 6 GHz requires WPA3 and a Wi-Fi 6E/7 device | Check the security setting and device support |
| Enterprise login fails or shows a certificate warning | Wrong credentials, expired account, or the device does not trust the server's certificate | Check the account; install the correct certificate profile. Never accept unknown certificates. |
| Some clients drop after enabling PMF | Old drivers that do not support PMF | Set PMF to “optional” (capable) rather than “required”, or update drivers |
| Guests can see office devices | Guest SSID on the same subnet, no isolation | Separate VLAN/subnet, firewall rules, client isolation |
Useful commands
C:\>netsh wlan show interfaces Name : Wi-Fi State : connected SSID : Home-WiFi BSSID : 02:00:00:00:a0:01 Radio type : 802.11ax Authentication : WPA3-Personal Cipher : CCMP Band : 5 GHz Channel : 36 Signal : 91%
Authentication shows the security mode actually in use (WPA3-Personal, WPA2-Personal, WPA2-Enterprise, Open). Cipher should be CCMP or GCMP (both AES). If you see WEP or TKIP, fix the router settings.
C:\>netsh wlan show profile name="Home-WiFi" key=clear Profile Home-WiFi on interface Wi-Fi: ======================================================================= Security settings ----------------- Authentication : WPA3-Personal Cipher : CCMP Security key : Present Key Content : maple-river-lantern-orbit-42
Shows the security type and the saved password for a network this PC has joined. Useful when you need the password for another device. It also shows why a laptop left unlocked is a Wi-Fi security risk.
$ nmcli -f SSID,SECURITY,SIGNAL dev wifi list SSID SECURITY SIGNAL Home-WiFi WPA3 91 Office-Guest WPA2 WPA3 74 Flat12 WPA2 60 Airport-Free -- 45 Old-Printer WEP 30
The security of every network in range. -- is an open network; WPA2 WPA3 is transition mode; WEP should never appear on a network you control.
$ nmcli dev wifi connect Home-WiFi password wrongpass123 Error: Connection activation failed: Secrets were required, but not provided.
This is how NetworkManager reports a wrong password: the 4-way handshake (or SAE) failed, so it asks for the secret again. Check the password with nmcli connection show Home-WiFi or delete the profile and try again.
Practical checklists
🏠 Home checklist
- Use WPA3-Personal, or WPA2/WPA3 mixed mode if you have old devices. Never WEP, WPA or TKIP.
- Set a long passphrase (four or more random words, 16+ characters).
- Change the router's admin password from the default.
- Turn off WPS.
- Keep the router's firmware updated (turn on automatic updates if offered).
- Put visitors and smart-home gadgets on the guest network.
- Turn off remote administration from the internet unless you need it.
- Use HTTPS everywhere, and a VPN on public Wi-Fi.
🏢 Small-office checklist
- Staff on WPA3-Enterprise (802.1X) if possible, with certificate checks configured on every device.
- If you must use a shared password: WPA3-Personal, a long passphrase, changed when anyone leaves.
- A guest SSID in its own VLAN/subnet, internet only, with client isolation.
- Separate network for printers, cameras and IoT devices.
- Protected management frames on (required with WPA3).
- Disable WPS and default admin accounts; update AP firmware.
- Scan for rogue APs and unknown SSIDs copying your name.
- Keep a list of APs, SSIDs and who manages them.
Common mistakes
- Thinking a captive portal is security. It controls internet access but encrypts nothing.
- Leaving an old WEP or TKIP setting “for compatibility”. One weak setting weakens the whole network.
- Short or shared-forever passwords. With WPA2 they can be cracked offline, and leavers keep access.
- Relying on hidden SSIDs or MAC filters. They stop nobody who is trying.
- Guests on the same LAN as staff. A guest's infected laptop can then reach your file server.
- Ignoring certificate warnings on enterprise Wi-Fi. That is exactly what an evil twin relies on.
- Assuming Wi-Fi encryption protects you on the internet. It stops at the access point.
- Authentication decides who may join; encryption stops others reading the traffic. Wi-Fi needs both.
- Open networks are unencrypted; captive portals do not change that. Enhanced Open (OWE) adds encryption without a password.
- WEP is broken and WPA (TKIP) is deprecated. WPA2 with AES is acceptable; WPA3 is recommended.
- Personal = one shared password; Enterprise (802.1X + RADIUS) = a login per person.
- WPA3's SAE stops offline password guessing and gives forward secrecy; PMF blocks forged disconnects.
- Wi-Fi encryption only covers the radio hop. Use HTTPS or a VPN for the rest of the journey, and keep guests in their own segment.
Knowledge check
A hotel's Wi-Fi has no password, but asks for your room number on a web page before giving internet access. Is your traffic encrypted over the air?
An attacker recorded a WPA2-Personal handshake from your network. Your password is “sunshine1”. What can they do at home?
A company with 80 staff uses one shared Wi-Fi password. An employee leaves on bad terms. Which setup avoids changing the password on every device?
Your laptop shows Authentication: WPA3-Personal, Cipher: CCMP. You then open an HTTP (not HTTPS) website. Who can read the page?
A guest's phone on the guest Wi-Fi can print to the office printer. What is the most likely cause?
Where to go next
This completes the Wireless Fundamentals unit. Wireless security is one part of protecting a network: continue with Basic network security, then Firewall basics, VPN basics and Network segmentation. To review the radio side, revisit Wi-Fi basics and Wi-Fi frequency bands.