Why a shared password is not enough, what 802.1X provides, and how to separate guest, corporate and device networks.
Wireless is where physical access control ends: the signal leaves the building and is reachable from the car park. Yet in many organisations the same shared password has protected it for three years.
WPA2-Personal (and WPA3-Personal) works on a single password everyone knows. Several problems follow:
Not attributable. You cannot tell who connected, only that somebody did.
Not individually revocable. When someone leaves, the password must change for everyone, so it never changes.
It spreads. A password known to fifty people will be known to outsiders within months.
Interceptable. With WPA2, capturing the handshake allows traffic to be decrypted retrospectively once the password is known.
Enterprise Wi-Fi (WPA2-Enterprise or WPA3-Enterprise) uses individual authentication. Each user or device connects with its own identity, typically a certificate or their domain account.
From this it follows that:
The certificate-based variant is stronger than password-based, because it cannot be shared or leaked.
At least three separate networks, routed into separate segments.
Corporate. With 802.1X authentication and access to internal resources.
Guest. Fully isolated with internet access only. With client isolation so guests cannot reach each other. Time-limited or single-use codes.
Devices. Printers, IP cameras, building automation, meeting room equipment. These cannot do 802.1X and typically run with default passwords and old firmware. They belong in their own segment with restricted outbound traffic. We covered this in our internal segmentation article.
Rogue access points. An attacker broadcasts your network name and connecting devices hand over credentials. Certificate-based authentication defends against this, because the client validates the server certificate. This must be enforced on clients, otherwise users simply accept it.
Legacy protocols. WEP and the original WPA are breakable. Where they survive, it is typically because of one old device nobody dared replace.
WPS. Push-button pairing is convenient and vulnerable. Disable it in enterprise environments.
Access point administration. Default passwords, outdated firmware, management interfaces reachable from the internet. The same rules apply as to any other network device.
Coverage beyond the walls. If the signal is strong in the car park, the attack surface extends outside the building. Transmit power and antenna placement are security questions too.
Our IT security services include reviewing network architecture.
Comprehensive IT security services including firewalls, WAF, IPS, SIEM, DLP and endpoint protection from…
A flat internal network is the most expensive legacy. Which four segments to start with, what client…
Next-generation firewall design, deployment and managed services from ARLITECH: Fortinet, Check Point,…
Our specialists are happy to discuss what this means in your organisation's environment.