Wireless Security
Why Wi-Fi Is a Special Risk
With a cable, an attacker must plug in. With Wi-Fi, the signal goes through walls, into the car park and the cafe next door. Anyone in range can listen, so wireless security depends on strong encryption and authentication.
Legal note: Only test wireless networks you own or have written permission to test. Attacking someone else's Wi-Fi is illegal under laws such as Nigeria's Cybercrimes Act 2015 and the UK Computer Misuse Act 1990.
WEP vs WPA vs WPA2 vs WPA3
| Standard | Year | Encryption | Status |
|---|---|---|---|
| WEP | 1997 | RC4 with a tiny 24-bit IV | Broken. Cracked in minutes. Never use |
| WPA | 2003 | RC4 with TKIP | Obsolete. Only a stop-gap |
| WPA2 | 2004 | AES-CCMP | Still common. Strong if the password is strong |
| WPA3 | 2018 | AES with SAE ("Dragonfly") handshake | Current standard |
Why WEP failed
WEP reused a short initialisation vector, so after collecting enough packets attackers could recover the key mathematically. No user password can fix a broken design.
WPA2's weakness: the captured handshake
When a device joins a WPA2 Personal network, it performs a 4-way handshake. An attacker can capture it and try passwords offline, with no further contact with the network, guessing billions of passwords per second with a GPU. A weak password such as lagos2024 falls quickly. A long random passphrase does not. (The 2017 KRACK flaw also showed protocol-level weaknesses, fixed by patches.)
What WPA3 improves
- SAE stops offline guessing: each guess needs a live interaction with the router.
- Forward secrecy: recorded traffic cannot be decrypted later if the password leaks.
- Protected Management Frames (PMF) are mandatory.
- Better protection for open networks (Enhanced Open / OWE).
Enterprise Wi-Fi (WPA2/WPA3-Enterprise, 802.1X) gives each user their own credentials or certificate instead of one shared password, so you can remove one person without changing everything. Universities, banks and large offices use it.
Common Wireless Attacks
Evil twin
The attacker sets up a hotspot with the same name (SSID) as a real one, such as "Airport_Free_WiFi" or your office network, usually with a stronger signal. Devices join it, and the attacker can capture traffic or show a fake login page. Defence: use a VPN, HTTPS and certificate warnings, and 802.1X with certificate validation in enterprises. Never accept certificate errors.
Deauthentication attack
Older Wi-Fi management frames were unauthenticated. An attacker can forge a "you are disconnected" message, kicking devices off the network. This is used to cause disruption or to force a device to reconnect so that the handshake can be captured. Protected Management Frames (802.11w), required by WPA3, defeat this.
WPS attacks
The "push button / PIN" feature has a weak 8-digit PIN that can be brute-forced. Turn WPS off.
Rogue access points
An employee plugs a cheap router into an office socket, creating an unmanaged back door. Enterprises scan for rogue access points and use port security.
Hardening Checklist
- Use WPA3 (or WPA2-AES). Never WEP or open networks for business.
- Use a long passphrase: 4+ random words or 16+ characters.
- Change the router's admin password, keep firmware updated, disable WPS and remote administration.
- Separate guest and IoT devices onto their own network.
- Use 802.1X (Enterprise) for staff, and hide nothing behind "hidden SSID" as it is not real security.
- On public Wi-Fi, use a VPN and pay attention to certificate warnings.
Nigerian and Global Context
Cafes, hotels, co-working spaces and estates in Lagos, Abuja and Port Harcourt commonly share one Wi-Fi password with everybody, and travellers everywhere face the same at airports. Shared passwords and old routers with default settings are common causes of compromise. Use your own mobile data or a VPN for banking on any shared network.
Try It: How Long Would Your Passphrase Survive?
In the editor on the right, type a Wi-Fi password. The tool estimates how long an offline attack would take against a captured WPA2 handshake. Compare a short password with a passphrase of random words.
Try it yourself
Key Takeaways
- WEP is broken and WPA is obsolete. Use WPA3, or WPA2-AES with a long random passphrase.
- WPA2-Personal handshakes can be captured and cracked offline, so passphrase strength matters. WPA3's SAE and forward secrecy fix this.
- Evil twin hotspots copy a real network name to intercept traffic. Use a VPN and never ignore certificate warnings.
- Deauthentication attacks forge disconnect frames. Protected Management Frames (802.11w) prevent them.
- Turn off WPS, update firmware, separate guest and IoT devices, and use 802.1X Enterprise for staff. Only test networks you are authorised to test.
Quick Quiz
1.Why can an attacker crack a weak WPA2-Personal password offline?
2.What is an evil twin attack?
3.Which feature, mandatory in WPA3, stops attackers forging deauthentication frames?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx