Lezione 4 di 4 · 9 min
Wireless security: WPA3, rogue access points and evil twins
How Wi-Fi encryption evolved from WEP to WPA3, what rogue access points and evil-twin hotspots are, and practical defenses for home, office and public networks.
Per ora questa pagina è in inglese.
A wired network has a physical boundary: to plug in, you need to be inside the building. Wi-Fi has no such wall. Its radio signal passes through windows and into the street, and any device in range can listen. Wireless security is about two things: protecting what travels over the air, and making sure the network you join is the one you think it is.
From WEP to WPA3
| Standard | Introduced | Status |
|---|---|---|
| WEP | Late 1990s | Broken; can be cracked in minutes. Never use. |
| WPA (WPA1, TKIP) | 2003 | Obsolete stopgap; treat as weak. |
| WPA2 (AES) | 2004 | Still widely used and acceptable with a strong password. |
| WPA3 | 2018 | Current standard; use it wherever your devices support it. |
The Wi-Fi Alliance introduced WPA3 to fix weaknesses in WPA2. WPA3-Personal replaces the old pre-shared key handshake with SAE (Simultaneous Authentication of Equals). With WPA2, an attacker who records a device joining the network can take that recording away and try millions of password guesses offline. SAE makes that offline guessing impractical: each guess needs a live exchange with the network. WPA3 also requires Protected Management Frames, which make it harder to knock devices off the network with forged disconnect messages. WPA3-Enterprise adds an optional higher-strength mode for sensitive organisations, and Wi-Fi Enhanced Open (OWE) encrypts traffic on open, password-less networks such as café hotspots, although it does not prove who runs the hotspot.
Rogue access points
A rogue access point is a wireless access point connected to a network without permission. Sometimes it is innocent: an employee plugs a cheap router into the office network for better coverage, silently creating an unmanaged, often poorly secured, door into the internal network. Sometimes it is deliberate, a small device hidden on a desk or behind a printer to give an attacker remote access. NIST’s guidance on wireless LAN security, SP 800-153, recommends that organisations regularly scan for unauthorised access points and keep an inventory of authorised ones.
Evil twins
An evil twin is a fake access point that imitates a legitimate one, usually by copying its network name (SSID). MITRE ATT&CK lists it as an adversary-in-the-middle technique. Devices remember networks by name and try to rejoin them automatically, so a laptop that once used “Airport_Free_WiFi” may happily connect to an impostor with the same name. Once connected, the attacker controls the network path: they can watch unencrypted traffic, show fake login pages (“sign in again to use the Wi-Fi”), tamper with DNS answers or try to reach the device directly.
- An evil twin is easiest to set up for open networks: there is no password to know.
- Copies of password-protected networks often use weaker or no security, because the attacker does not know the real password.
- HTTPS still protects the content of your web traffic, but many apps, older protocols and captive portals are not so careful.
Defenses that work
| Where | What to do |
|---|---|
| Home router | WPA3 (or WPA2/WPA3), a long unique password, updated firmware, WPS turned off, a guest network for visitors and IoT |
| Office | WPA3-Enterprise with individual credentials, regular scans for rogue access points, segmented guest Wi-Fi |
| Public Wi-Fi | Prefer your phone’s hotspot; otherwise use a VPN, stick to HTTPS, and never enter passwords on a captive portal that asks for your email account |
| Every device | Forget networks you no longer use, turn off automatic joining for open networks, keep incoming connections blocked |
On a Mac, Apple also protects Wi-Fi at the system level, for example by supporting WPA3 and using private, rotating Wi-Fi addresses on newer versions of macOS so that networks cannot easily track the device.
How FireAI’s Coffee Shop Armor fits in
FireAI includes a feature called Coffee Shop Armor that applies several of these defenses automatically. It checks how each Wi-Fi network is secured: open, weak (old encryption such as WEP or WPA1) or strong (WPA2 or WPA3). On an open or weak network, it switches FireAI to Coffee shop mode, which blocks incoming connections, file and screen sharing to other devices, and unencrypted mail or FTP. It only ever makes FireAI stricter: it never overrides a stricter mode you chose and never switches back down by itself.
It also warns you when a network with a name you have used before appears with weaker security than last time: the classic sign of an evil twin. FireAI is honest about the limit. A fake network with a copied name and a strong password looks the same as the real one from outside, so the warning catches the common case, not every trick. That is why a strict mode on unfamiliar networks remains the safe default. To read the Wi-Fi name at all, macOS requires Location access; FireAI uses it only to recognise networks.
Da ricordare
- WEP and WPA1 are broken or weak; use WPA3, or WPA2 with a strong password.
- WPA3’s SAE handshake stops attackers from guessing the password offline from a recorded connection.
- A rogue access point is an unauthorised door into a network; an evil twin is a fake copy of a real network.
- On public Wi-Fi, assume the network may be hostile: block incoming connections and rely on encryption you control.
Mettiti alla prova
1. What does WPA3-Personal’s SAE handshake prevent?
- All phishing
- Offline password guessing from a recorded connection handshake — Esatto.
- The use of HTTPS
- Devices joining the network
With SAE, each password guess requires a live exchange with the network, so recording a handshake is no longer enough to crack the password offline.
2. A network called “Hotel_Guest” appears with no password, although last night it required one. What is the most likely explanation?
- The hotel improved its security
- A possible evil twin copying the network name with weaker security — Esatto.
- Your Mac’s Wi-Fi is broken
- WPA3 was turned on
The same name with weaker security is the classic sign of an evil twin, and exactly what FireAI’s fake Wi-Fi warning looks for.
3. An employee plugs their own wireless router into the office network for better signal. What is it called?
- An evil twin
- A rogue access point — Esatto.
- A VPN
- A DMZ
Any access point connected without authorisation is a rogue access point, even when installed with good intentions.
Mettilo in pratica con FireAI
Metti in pratica questa lezione sul tuo Mac.
- Come FireAI osserva le connessioni del tuo Mac — Sappi quale app sta comunicando con internet, in termini chiari, senza installare nulla che funzioni come servizio nascosto in background.
- Regole: app, sito, dominio, IP o un intervallo, per sempre o fino al riavvio — Scrivi una regola precisa quanto un solo indirizzo o ampia quanto un intero dominio.
- Coffee Shop Armor: safer on public Wi-Fi, and warned about fake networks — Sit down in any café, hotel or airport and let FireAI tighten up for you.
- Who’s online: see every device on your network, and get told when one comes or goes — Know what’s on your Wi-Fi, from the TV to your kid’s phone, without any extra box.
Fonti
- Wi-Fi Alliance: Wi-Fi security (WPA3)
- NIST SP 800-153: Guidelines for Securing Wireless Local Area Networks
- MITRE ATT&CK: Adversary-in-the-Middle: Evil Twin (T1557.004)
- Apple Platform Security: Wi-Fi security
Mettilo in pratica sul tuo Mac
Prova tutte le funzioni gratis per 17 giorni, senza carta.