
This is the last post in a short series on wireless, and it is the one to act on. The earlier posts explained how Wi-Fi works and where it breaks; this turns that into a list you can run through in about ten minutes, once, and mostly forget.
Every item has a reason and a way to check it. Skip the ones that do not apply, but read the reason first - most Wi-Fi "advice" online is old myth that trades real security for hassle.
1. Use WPA3, or WPA2/WPA3 mixed
The security mode is the setting that matters most. In your router admin page, set it to WPA3-Personal if every device supports it, or WPA2/WPA3 mixed if you still have older ones.
If the only options are WPA or WEP, the hardware predates 2004 and should be replaced - there is no setting that makes those safe. Why each mode is what it is, and the trap in mixed mode, is in the encryption post.
Verify: from your phone, check the security type the network actually negotiated, not just what the router claims - mixed mode can quietly place an old device on the weaker path.
2. Make the passphrase long, not clever
Under WPA2 the passphrase is the entire defence against an offline attack, and even under WPA3 a genuinely trivial one is a liability. The attack is a guessing race against leaked-password lists, so the winning move is length: four or five unrelated words beats a short string of symbols, and is easier to type onto a TV.
The attack post explains why length is the lever and complexity mostly is not.
Verify: if your current password is short, a dictionary word, or a phone number, change it now. Those are the first things any attack tries.
3. Turn WPS off
WPS - the "press a button or type an 8-digit PIN to join" feature - has a PIN mode that can be brute-forced in hours, bypassing your strong passphrase entirely. It is the most common way a well-chosen password gets defeated without being guessed.
The convenience is not worth it. Turn it off.
Verify: look for "WPS" in the wireless settings and confirm it is disabled.
4. Change the router admin password
This is a different password from your Wi-Fi passphrase, and it is the one people forget. The default admin login for most router models is printed in public manuals. Anyone who gets onto your network - or, on some models, reaches the router from the internet - can walk into the admin page with defaults and reconfigure everything.
Verify: log in to the admin page. If it took admin / admin or admin /
password, change it before you do anything else.
5. Keep the firmware updated
Router firmware has security flaws like all software, and KRACK in 2017 showed even sound protocols need patches. Many modern routers auto-update; older ones do not and are the ones most likely to be exposed.
Verify: find the firmware section, apply any pending update, and turn on automatic updates if the option exists. If the router is years past its last update, that is a sign to replace it.
6. Put untrusted devices on a guest network
A guest network is a separate SSID that hands out internet but keeps clients away from your main LAN. Two good uses: visitors, and cheap smart-home gadgets - the plugs, bulbs and cameras whose own security you have no control over. If one is compromised, it sits on the guest side and cannot reach your laptop or NAS.
Verify: enable the guest network, and move IoT devices onto it. Your phone and computers stay on the main one.
7. Do not bother hiding the SSID
This one is a myth. Hiding the network name is sold as security and is not: the name still travels in the frames your own devices send looking for it, so it is easily recovered, while your devices now broadcast the network name everywhere you carry them. It also breaks discovery on some clients for no real gain. Leave the SSID visible and rely on the passphrase, which is what actually protects you. The Wi-Fi basics post covers why.
Same idea: MAC address filtering. MAC addresses are sent unencrypted and easily copied, so a filter stops a curious neighbour and no one else, while adding a chore every time you get a new device. Skip it.
8. Pick a good channel and band while you are here
Not strictly security, but this is when you are already in the settings. A network on a congested channel is slow no matter how fast the plan is. On 2.4 GHz use channel 1, 6 or 11; on 5 GHz pick a channel your neighbours are not on; keep the channel width reasonable, not maxed out. The reasoning, and how to read what is actually around you, is in the Wi-Fi basics post.
9. Know what is connected
The final habit, and an ongoing one rather than a one-time setting. You cannot notice an intruder on a network you have never looked at. Periodically list the devices on your LAN; anything you do not recognise is worth chasing down. On a healthy home network the list should be boring and familiar.
Verifying from the device
Most of the checklist is set in the router. Confirming it is best done from a phone on the network, because the router reports what you configured and the device reports what actually happened - and those differ more often than you would think, especially with mixed-mode security and band steering.
NetTools: Network Analyzer reads the security type, band, channel and BSSID of the network you are on, and lists every device answering on the LAN - the two checks (item 1 and item 9) that a router page cannot honestly confirm on its own. No account, and nothing it measures leaves the phone.
That is the series: Wi-Fi standards, encryption, how the attacks work, and this checklist to close it out. Ten minutes now is worth more than any single gadget you could buy.
Cover photo by dlxmedia.hu on Unsplash.



