Aller au contenu
← Networking and security architecture

Leçon 4 sur 4 · 9 min

Wireless security: WPA3, rogue access points and evil twins

How Wi-Fi encryption evolved from WEP to WPA3, what rogue access points and evil-twin hotspots are, and practical defenses for home, office and public networks.

Cette page est en anglais pour le moment.

A wired network has a physical boundary: to plug in, you need to be inside the building. Wi-Fi has no such wall. Its radio signal passes through windows and into the street, and any device in range can listen. Wireless security is about two things: protecting what travels over the air, and making sure the network you join is the one you think it is.

From WEP to WPA3

StandardIntroducedStatus
WEPLate 1990sBroken; can be cracked in minutes. Never use.
WPA (WPA1, TKIP)2003Obsolete stopgap; treat as weak.
WPA2 (AES)2004Still widely used and acceptable with a strong password.
WPA32018Current standard; use it wherever your devices support it.

The Wi-Fi Alliance introduced WPA3 to fix weaknesses in WPA2. WPA3-Personal replaces the old pre-shared key handshake with SAE (Simultaneous Authentication of Equals). With WPA2, an attacker who records a device joining the network can take that recording away and try millions of password guesses offline. SAE makes that offline guessing impractical: each guess needs a live exchange with the network. WPA3 also requires Protected Management Frames, which make it harder to knock devices off the network with forged disconnect messages. WPA3-Enterprise adds an optional higher-strength mode for sensitive organisations, and Wi-Fi Enhanced Open (OWE) encrypts traffic on open, password-less networks such as café hotspots, although it does not prove who runs the hotspot.

Rogue access points

A rogue access point is a wireless access point connected to a network without permission. Sometimes it is innocent: an employee plugs a cheap router into the office network for better coverage, silently creating an unmanaged, often poorly secured, door into the internal network. Sometimes it is deliberate, a small device hidden on a desk or behind a printer to give an attacker remote access. NIST’s guidance on wireless LAN security, SP 800-153, recommends that organisations regularly scan for unauthorised access points and keep an inventory of authorised ones.

Evil twins

An evil twin is a fake access point that imitates a legitimate one, usually by copying its network name (SSID). MITRE ATT&CK lists it as an adversary-in-the-middle technique. Devices remember networks by name and try to rejoin them automatically, so a laptop that once used “Airport_Free_WiFi” may happily connect to an impostor with the same name. Once connected, the attacker controls the network path: they can watch unencrypted traffic, show fake login pages (“sign in again to use the Wi-Fi”), tamper with DNS answers or try to reach the device directly.

  • An evil twin is easiest to set up for open networks: there is no password to know.
  • Copies of password-protected networks often use weaker or no security, because the attacker does not know the real password.
  • HTTPS still protects the content of your web traffic, but many apps, older protocols and captive portals are not so careful.

Defenses that work

WhereWhat to do
Home routerWPA3 (or WPA2/WPA3), a long unique password, updated firmware, WPS turned off, a guest network for visitors and IoT
OfficeWPA3-Enterprise with individual credentials, regular scans for rogue access points, segmented guest Wi-Fi
Public Wi-FiPrefer your phone’s hotspot; otherwise use a VPN, stick to HTTPS, and never enter passwords on a captive portal that asks for your email account
Every deviceForget networks you no longer use, turn off automatic joining for open networks, keep incoming connections blocked

On a Mac, Apple also protects Wi-Fi at the system level, for example by supporting WPA3 and using private, rotating Wi-Fi addresses on newer versions of macOS so that networks cannot easily track the device.

How FireAI’s Coffee Shop Armor fits in

FireAI includes a feature called Coffee Shop Armor that applies several of these defenses automatically. It checks how each Wi-Fi network is secured: open, weak (old encryption such as WEP or WPA1) or strong (WPA2 or WPA3). On an open or weak network, it switches FireAI to Coffee shop mode, which blocks incoming connections, file and screen sharing to other devices, and unencrypted mail or FTP. It only ever makes FireAI stricter: it never overrides a stricter mode you chose and never switches back down by itself.

It also warns you when a network with a name you have used before appears with weaker security than last time: the classic sign of an evil twin. FireAI is honest about the limit. A fake network with a copied name and a strong password looks the same as the real one from outside, so the warning catches the common case, not every trick. That is why a strict mode on unfamiliar networks remains the safe default. To read the Wi-Fi name at all, macOS requires Location access; FireAI uses it only to recognise networks.

À retenir

  • WEP and WPA1 are broken or weak; use WPA3, or WPA2 with a strong password.
  • WPA3’s SAE handshake stops attackers from guessing the password offline from a recorded connection.
  • A rogue access point is an unauthorised door into a network; an evil twin is a fake copy of a real network.
  • On public Wi-Fi, assume the network may be hostile: block incoming connections and rely on encryption you control.

Vérifiez vos connaissances

  1. 1. What does WPA3-Personal’s SAE handshake prevent?

    • All phishing
    • Offline password guessing from a recorded connection handshake — Exact.
    • The use of HTTPS
    • Devices joining the network

    With SAE, each password guess requires a live exchange with the network, so recording a handshake is no longer enough to crack the password offline.

  2. 2. A network called “Hotel_Guest” appears with no password, although last night it required one. What is the most likely explanation?

    • The hotel improved its security
    • A possible evil twin copying the network name with weaker security — Exact.
    • Your Mac’s Wi-Fi is broken
    • WPA3 was turned on

    The same name with weaker security is the classic sign of an evil twin, and exactly what FireAI’s fake Wi-Fi warning looks for.

  3. 3. An employee plugs their own wireless router into the office network for better signal. What is it called?

    • An evil twin
    • A rogue access point — Exact.
    • A VPN
    • A DMZ

    Any access point connected without authorisation is a rogue access point, even when installed with good intentions.

À vous de jouer avec FireAI

Mettez cette leçon en pratique sur votre propre Mac.

Sources

Mettez-le en pratique sur votre Mac

Essayez toutes les fonctionnalités gratuitement pendant 17 jours, sans carte bancaire.

Télécharger pour Mac Docs