Wifi basics
TL;DR
Most wifi security comes down to the WPA2 handshake and how strong the passphrase is. An attacker can capture the handshake and crack it offline, so a long, unguessable passphrase (or enterprise 802.1X, or WPA3) is what actually protects a network.
Only test wireless networks you own or are authorised to test.
What it is
When a device joins a WPA2 network it performs a four-way handshake that proves both sides know the passphrase without sending it. That handshake, once captured, is enough to attack the passphrase offline.
How it works
An attacker within range captures the handshake (or a related PMKID) and then, away from the network, tries passphrases against it. Nothing is brute-forced over the air — the whole attack happens offline, so the only thing standing in the way is how good the passphrase is. A dictionary word or a short one falls quickly.
How to defend
- A long, random passphrase — the single most important control for a pre-shared-key network.
- WPA3 where supported, which hardens this handshake considerably.
- For anything sensitive, enterprise 802.1X with per-user credentials rather than one shared password.