Thuta Learning
AdvancedSecurityintermediate

Wireless Security (WPA2/WPA3)

Relax. We'll talk through this in plain words — no textbook voice.

What you'll walk away with

  • Understand Wireless Security (WPA2/WPA3) well enough that it stops being intimidating
  • Get hands-on running the tools yourself in an authorized lab environment
  • Be able to apply this concept immediately in a real assessment or report

Let's think about it this way for a second

WPA2 (Wi-Fi Protected Access 2) is a WiFi encryption standard, and WPA3 is its stronger successor (better protection against offline dictionary attacks). WEP (older, deprecated) should never be used today, since it can be cracked in just a few minutes. If WPS (WiFi Protected Setup, PIN-based quick connect) is enabled, its PIN's brute-force weakness can let an attacker bypass even a strong WPA2 password — so WPS should be disabled.

Let's connect it to a real-world scenario

Checking your home or office router settings, you can confirm the encryption type is 'WPA2' or 'WPA3' (not WEP or Open), that WPS is disabled, and that the WiFi password is strong (not a dictionary word, and long enough) — all of this is basic hygiene for personal/office network security.

Let's look at it together

text
Home/office router wireless security checklist:

[ ] Encryption set to WPA2 or WPA3 (never WEP, never Open)
[ ] WPS (WiFi Protected Setup) disabled
[ ] WiFi password is long and not a dictionary word
[ ] Router admin panel default password changed
[ ] Router firmware kept up to date
[ ] Guest network separated from the main network (segmentation)
You should see
You'll be able to audit a WiFi router's settings and confirm that WPA2/WPA3 is enabled and WPS is disabled.

Try it in 5 minutes

Open your home/office WiFi router's admin panel and run through the checklist above — if anything fails, fix it right away.

A quick word of caution

Only audit or test WiFi networks you own or are authorized to test — attempting to scan or crack a neighbor's or public WiFi network is illegal.

Easy traps

  • Leaving WPS enabled because 'quick connect is convenient' — attackers routinely target its brute-force weakness with well-known tools like Reaver
  • Forgetting to change the router admin panel's default password (admin/admin) — even with a strong WiFi password, every setting can still be changed through the admin panel

Now try it yourself

Open your home/office WiFi router's admin panel and run through the checklist above — if anything fails, fix it right away.

You'll know it worked when: You'll be able to audit a WiFi router's settings and confirm that WPA2/WPA3 is enabled and WPS is disabled.