Asia VPNAsiaVPNGet app
All posts

Why WPA2 Passwords Crack, and WPA3 Resists

4 min read

The previous post said the WPA2 password is "the whole game" and that a weak one falls to an offline attack. This post explains what that actually means, because understanding how it works tells you whether your own network would survive it.

This is defensive material. Everything below is about how the attack works so you can defeat it, and how to test the one network you are allowed to test: your own. Running any of this against a network you do not own is illegal in most countries, full stop, and nothing here is a how-to for doing so.

What is actually protecting your network

When a device joins a WPA2 network it runs the 4-way handshake - a four-message exchange that proves both sides know the password without ever sending it. Out of that exchange both sides derive the session keys that encrypt your traffic.

The catch is what the handshake contains. Those four messages include a value that is derived from your password. Not the password itself, but something only the correct password could have produced. Which means: anyone in radio range who records the handshake now holds a verifier they can test password guesses against.

Why "offline" is the whole problem

Here is the distinction that decides everything.

An online attack means guessing passwords by actually trying to log in, one attempt at a time, against a device that can slow you down, lock you out, or simply be too slow to allow millions of tries. Online guessing against a decent password is hopeless.

An offline attack means the attacker has captured the handshake and now tests guesses on their own hardware, with no further contact with your network. No rate limit. No lockout. Nothing to alert you. A modern machine tries billions of candidates against a captured WPA2 handshake, working through wordlists of leaked passwords and every common pattern first. The tools that do this - the aircrack-ng suite is the well-known one - are standard, public, and used every day by penetration testers auditing networks they were hired to audit.

The password never travels through the air, and it does not need to. The verifier in the handshake is enough. That is why WPA2's cipher can be flawless while the network still falls: the weak point is the password's resistance to being guessed offline, and nothing else.

You do not even have to be connected

A natural assumption is that an attacker needs to wait for someone to join to see a handshake. In practice they do not have to wait. Wi-Fi management frames that trigger a reconnection are not encrypted under WPA2, so a device that is already connected can be made to reconnect - which produces a fresh handshake. WPA3 fixes this class of problem too, by protecting those management frames.

The takeaway is not the technique - it is the consequence: assume any WPA2 handshake on your network is capturable by someone in range. Your security therefore rests entirely on whether the password behind it can be guessed. Which is a thing you can test.

Testing your own network, legitimately

Auditing the password strength of a network you own is legal, sensible, and the only honest way to know if the guidance in these posts applies to you. The approach, at a high level and without a command playbook:

  1. Capture your own handshake by reconnecting one of your own devices while a capture runs on hardware you control.
  2. Run a wordlist against it using the same offline tools an attacker would - start with the public lists of the most common passwords and leaked credentials, because that is exactly what an attacker starts with.
  3. Read the result as a yes/no. If your password appears in a common wordlist, it would fall in minutes and must change today. If a serious run does not crack it, you have evidence your passphrase is doing its job.

The point of the exercise is not to become an attacker. It is to see your own network the way one does, and to find a weak passphrase before someone else does. Security certifications teach exactly this on exactly this basis.

Making the attack fail

Everything the offline attack relies on has a defence, and none of it is complicated:

  • A long passphrase is the whole defence under WPA2. The attack is a guessing race; a passphrase of four or five unrelated words is not in any wordlist and is too long to brute-force. This single choice is worth more than everything else combined.
  • WPA3 removes the offline race entirely. Its SAE handshake requires a live exchange with the router for every guess, so a captured handshake is no longer something to test against on their own machine. Move to WPA3, or WPA2/WPA3 mixed mode if some devices are old - remembering that a device on the WPA2 side of mixed mode still has the WPA2 exposure.
  • Turn WPS off. The 8-digit PIN is a separate door that bypasses your passphrase regardless of how strong it is.
  • Forward secrecy (WPA3) protects the past. Even if your password leaks later, traffic recorded earlier cannot be decrypted with it. Under WPA2 it can.

Where a phone analyzer fits, and where it does not

To be clear about scope: an analyzer app is not a cracking tool, and NetTools does not capture handshakes or run attacks - Android does not even grant apps the access that would require. What it does is the defensive half of this picture, and it is the half you use far more often:

  • Confirm what security a network actually negotiated - WPA2 or WPA3 - rather than what the router claims. Mixed mode can quietly put a device on the weaker path, and reading it from the device is how you catch that.
  • See every device on your LAN, so an unfamiliar one is something you notice rather than something that lives there for months.

Knowing your network runs WPA3 with a long passphrase and holds no strangers is the outcome this whole series is aimed at. The last post turns it into a checklist: securing your home Wi-Fi.


Cover photo by FlyD on Unsplash.

Keep reading