Wi-Fi/Sleep and locks/Wi-Fi security in layers
Lesson 11 of 13 · in 3D and VR

Wi-Fi security in layers

Everyone in range receives your frames, so security decides what they can read. WPA2 and WPA3 lock the payload but never the addresses, the password is never sent, and a weak password stays weak.

Lonely BinaryUpdated 2026-10-095 min readNo board required

View it in VR

Lesson 11 of the Wi-Fi course opens in a VR headset, on a table in front of you, and a voice starts three seconds after you arrive. Type this short address into the browser on a headset such as Meta Quest or Apple Vision Pro, and press Enter VR. No headset? Press Start the lesson: the same lesson, full screen.

learn.lonelybinary.com/vr/wifi/11

Everyone receives

A frame spreads to every radio in range on its channel, and nothing in Wi-Fi stops a nearby receiver from recording it. On an open network nothing is encrypted: anyone in range reads the addresses and the payload alike.

What WPA2 locks

WPA2 encrypts the frame body. The MAC addresses, the frame type and the timing stay visible, so a listener still sees which devices talk to which access point, and when. Encryption hides what is said, not who is talking.

The password is not the key. WPA2-Personal stirs the passphrase, 8 to 63 characters, 4096 times with the network's name (PBKDF2) into a 256-bit key, so the same password on another network name gives another key. When a station joins, the four-way handshake runs: the access point sends a random ANonce, the station a random SNonce, and each derives a key for that station alone from the shared key, both nonces and both MAC addresses, then proves it holds the same one. The password never crosses the air.

Where WPA2 is weak

That handshake is enough to check a guess against. Someone who records it can go away and test passwords offline, at leisure. A password on a word list can be found; a long random passphrase is the defence.

WPA3-Personal starts instead with an exchange called SAE, and a recorded one does not let anyone guess offline. It is stronger, not magic: the Dragonblood research (Mathy Vanhoef and Eyal Ronen, April 2019) found side-channel and downgrade flaws in early implementations and in transition mode, and fixes such as H2E followed. A weak password is still weak.

Older and newer locks

WEP is broken. In 2001 Fluhrer, Mantin and Shamir showed how its key can be recovered from captured traffic. An interim fix called WPA came first, then 802.11i, approved in June 2004 and certified as WPA2. ESP-IDF will not join a WEP or WPA network unless told to: with a password of 8 or more characters its threshold defaults to WPA2. KRACK, disclosed in 2017, tricked devices into reinstalling a key in use; it revealed no passwords, and software updates fixed it. Enhanced Open encrypts each user's traffic on a network with no password, but it cannot prove the network is the one you meant to join.

The code is in the ESP32 book: station mode, and provisioning to give a board its password without writing it into the sketch.

Common mistakes

  • Believing the password is sent to the router. It never crosses the air. Both sides prove they hold the key made from it, and that proof is what a listener records.
  • Thinking encryption hides who is talking. The addresses, the frame types and the timing are in the clear on every network.
  • Choosing a short password because the network uses WPA2 or WPA3. A recorded WPA2 handshake lets anyone test guesses offline, and WPA3 does not make a weak password strong.

Edit this page — content/fundamentals/wifi/wifi-security-in-layers.mdx

Discuss this article

Ask about this page. The answer stays here, on the page it belongs to, for whoever hits the same wall next.

Browse Fundamentals on the forum →