Back to glossary

WPA3

2 min read

In wireless security, WPA3 is the current generation of Wi-Fi protection, whose SAE handshake replaces the pre-shared-key handshake of WPA2 to resist offline password guessing. It is a real improvement with honest limits, and it is the wireless surface an assessment covers on estates that still run WPA2 alongside it.

July 29, 2026
Compartir:

How it works

The weakness WPA3 sets out to fix is that WPA2’s personal mode lets an attacker capture the handshake and then guess the password offline, at whatever speed their hardware allows. WPA3-Personal replaces that with SAE (Simultaneous Authentication of Equals), a handshake in which the exchange itself does not hand an attacker the material to guess offline, so a weak passphrase is no longer trivially crackable from a captured handshake. WPA3 also provides forward secrecy, so recording traffic does not let an attacker decrypt it later if the password is found. WPA3-Enterprise builds on 802.1X with stronger cryptographic options. WPA2 is the previous standard, still in wide use, and the two sit side by side on most estates during the long migration.

What goes wrong

WPA3 is often presented as closing the wireless problem, and it does not. The most common real-world weakness is transition mode, where an access point runs WPA3 and WPA2 together so older devices can connect: an attacker forces a client down to WPA2 and attacks that instead, so the network is only as strong as the weaker protocol it still accepts. Early SAE implementations also had a class of side-channel and downgrade weaknesses that undermined the promise on specific hardware. From the attacker’s side, the winning move is rarely to break SAE; it is to find the WPA2 fallback, the weak passphrase that survives regardless, or a client that will connect to an impostor network entirely.

Where this shows up in an audit

We test the wireless configuration as deployed, not as labelled: whether WPA3 is enforced or running in a transition mode that permits a WPA2 downgrade, whether pre-shared keys are strong enough to matter, and whether enterprise authentication validates properly. Where WPA2 is still present we assess the capture-and-crack and PMKID routes against it. Client behaviour is tested too, because a client that trusts an evil twin makes the access point’s configuration irrelevant. Recommendations tie into general hardening. This is part of how we test your wireless configuration.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.