CYBER WELFARE

Protect your Digital Privacy

How WPA3 works: the encryption that protects your phone’s hotspot

When you turn on your hotspot, your phone creates a small wireless network. Everything that travels between the phone and the devices connected to it goes through the air, as radio waves that anyone close enough can pick up. What decides whether those signals stay meaningless noise or become readable information is the network’s encryption: the system that scrambles the data in transit so that it can’t be read without the key.

In your hotspot settings, this choice appears as a set of unfriendly acronyms: WPA2, WPA3, sometimes “WPA2/WPA3”. Understanding how WPA3 works lets you choose with confidence, rather than leaving the default setting in place without knowing what it does.

This post sets out the technologies behind those acronyms, with their real advantages and limits, without pointing to any specific product. It is the technology side of the recommendation on hotspot encryption: choosing the strongest protection available.

How to read this list

First, a little history, because each version was created to fix the flaws of the one before.

ProtocolIntroducedIn shortToday
WEPlate 1990sThe first Wi-Fi encryption, with design flaws that allow its key to be recoveredDo not use
WPA2003A stopgap, designed to run on the devices of the timeObsolete
WPA22004Strong encryption and the reference standard for many yearsAcceptable, with a long password
WPA32018A new handshake and additional mandatory protectionsThe best choice, where supported

WPA stands for Wi-Fi Protected Access. The Personal variant, the one hotspots use, relies on a shared password; the Enterprise variant, typical of companies, gives each person their own credentials.

The technologies are organised into four functions, the same ones used in the post on how to turn on WPA3 on your hotspot:

  • prevention — stopping the traffic from being read or the password from being worked out;
  • detection — noticing that the network is using weaker protection than you think;
  • response — closing the doors that have been left open;
  • governance — keeping things in order over time, when there are many devices.

For each one you’ll find the risk it reduces, its advantages, its honest limits, and how complex it is to use. The hotspot’s other settings are covered in the post on how a phone hotspot works: here we focus on the protocol.

1. Prevention technologies

The SAE handshake, the heart of WPA3

The handshake is the short exchange of messages in which a device and the network recognise each other and agree on the keys that will encrypt the session. WPA3 replaces it with a method called SAE, Simultaneous Authentication of Equals.

With WPA2-Personal, someone nearby who records the handshake of a device joining the network gets enough material to try one password after another on their own computer, with no further need for the network. This is the offline dictionary attack (“dictionary” meaning lists of common passwords): time is on the attacker’s side, and nobody notices.

With SAE, the two sides prove they know the same password without transmitting anything from which it could be worked out. Recording the exchange is no use: every guess needs a fresh, live exchange with the network, one at a time.

  • Risk reduced: the network password being worked out from a recorded exchange.
  • Advantages: it makes offline attacks on the password pointless; it offers forward secrecy, meaning each session has new keys, so someone who discovered the password tomorrow could not decrypt traffic recorded today.
  • Limits: it doesn’t make a weak password strong, since a weak one can still be guessed live; early implementations had flaws, which were later fixed.
  • Example: in a waiting room, someone records your laptop joining your hotspot over WPA3. That recording doesn’t let them sit at home and guess the password at leisure.
  • Complexity: basic: you turn it on by choosing WPA3 in the settings.

AES encryption instead of the stopgaps

AES (Advanced Encryption Standard) is the algorithm that actually encrypts the data, used by both WPA2 and WPA3. WEP and WPA relied on older methods, such as RC4 and TKIP, now considered obsolete.

  • Risk reduced: traffic being decrypted, and packets — the small blocks in which data travels — being tampered with.
  • Advantages: a strong standard, used well beyond Wi-Fi; it also protects integrity, because an altered packet is discarded.
  • Limits: some phones and routers still offer TKIP, or an “AES/TKIP” combination, for compatibility: leaving it on means accepting the weaker part too.
  • Complexity: basic.

Protected management frames (PMF)

Besides data, a Wi-Fi network exchanges service messages, known as management frames: “I’m joining”, “I’m leaving”, “I’m here”. They used to travel unprotected, so someone could forge fake ones, such as a bogus disconnection order. Protected Management Frames (PMF) make them verifiable: devices recognise the fake ones and ignore them.

  • Risk reduced: forced disconnections, often used to make a device repeat the handshake or connect somewhere else.
  • Advantages: in WPA3 they are mandatory, not optional; they work without your having to do anything.
  • Limits: they don’t cover every service message; with WPA2 they are optional, and many older devices don’t support them.
  • Complexity: basic, automatic with WPA3.

WPA2/WPA3 transition mode

A mixed mode, often labelled “WPA2/WPA3” or “WPA3 transition”, in which the hotspot accepts both recent devices over WPA3 and older ones over WPA2, with the same password.

  • Risk reduced: falling back to plain WPA2, or to an open network, because one device won’t connect.
  • Advantages: devices that support WPA3 use it, and the others keep working; it’s a reasonable bridge.
  • Limits: any device joining over WPA2 reopens the door to offline attacks on the password, which is the same for everyone; someone may try to push a device towards the weaker version, known as a downgrade. How these attacks work is explained, without instructions, in the post on attacks on Wi-Fi encryption.
  • Example: a tablet that is a few years old can’t see the network in WPA3: you turn on mixed mode while you decide whether to update it.
  • Complexity: basic.

Individual encryption on open networks (OWE)

OWE (Opportunistic Wireless Encryption) is a technology introduced alongside WPA3 for networks without a password, such as those in cafés and stations. Each device agrees a key of its own with the network, without entering anything: people nearby can no longer see the traffic in plain text.

  • Risk reduced: passive eavesdropping on open networks.
  • Advantages: it turns an open network into an encrypted one, with no password to hand out.
  • Limits: it encrypts but does not authenticate: it doesn’t prove the network is the right one, and a fake network with the same name can do the same; it isn’t yet widespread; it isn’t suitable for a personal hotspot, because anyone could join. On public networks, the usual care about sensitive data on public Wi-Fi and the use of a VPN for sensitive traffic still applies.
  • Complexity: basic, automatic where available.

2. Detection technologies

Security type shown in the settings

Both the phone acting as a hotspot and the connected devices show, in the network details, the type of protection in use: “WPA3”, “WPA2/WPA3”, “WPA2” or “none”.

  • Risk reduced: believing you’re using WPA3 when the network, or a single device, is still on WPA2.
  • Advantages: a direct, verifiable check that takes a few seconds; it helps you work out which device is keeping the network in mixed mode.
  • Limits: the labels vary from one system to another and don’t always say which version a device has connected with; you have to check it actively.
  • Complexity: basic.

Weak security warnings

Many operating systems show a warning when you join an open network or one protected with WEP, WPA or TKIP.

  • Risk reduced: joining a poorly protected network without realising it.
  • Advantages: they reach you without your having to look; they are often the first sign that a setting has fallen behind.
  • Limits: if they appear often, people learn to ignore them; the absence of a warning says nothing about the strength of the password. The other signs worth watching are explained in the post on the signs your hotspot is poorly protected.
  • Complexity: basic.

3. Response technologies

Corrective system updates

Updates to the operating system of your phone and of the connected devices also fix flaws discovered in Wi-Fi protocols.

  • Risk reduced: known vulnerabilities, already fixed by manufacturers, that stay open on devices that aren’t updated.
  • Advantages: in 2017 a weakness in the WPA2 handshake, and in 2019 some flaws in early WPA3 implementations, were closed in exactly this way, without changing protocol; sometimes an update adds WPA3 support. The post on keeping your software up to date explains how to make updates a habit.
  • Limits: devices that no longer receive updates stay exposed to any flaws discovered later.
  • Example: after an update, your old laptop finally connects over WPA3 and you can leave mixed mode.
  • Complexity: basic.

Leaving transition mode

Once the last older device has been updated or replaced, you switch from mixed mode to WPA3 only.

  • Risk reduced: downgrade attacks, and a WPA2 handshake still being available.
  • Advantages: it closes the weakest door; it takes a single setting. Many devices also remember that the network used WPA3 and refuse to connect if it reappears with weaker protection.
  • Limits: a forgotten device will stop connecting; it’s worth thinking first about who actually uses the hotspot.
  • Complexity: basic.

Changing the password after the switch

A new password when you move to WPA3, or when you suspect the old one has been worked out.

  • Risk reduced: a password that may already have been discovered while the network was on WPA2.
  • Advantages: SAE protects future sessions, but it can’t make a password that is already known secret again: changing it resets the situation.
  • Limits: it has to be updated on every device. How to choose it and how often to change it is explained in the recommendation on your mobile hotspot password.
  • Complexity: basic.

4. Governance technologies

These become relevant when there are many devices to connect, or when they aren’t all yours: a family, a small office, a working group.

An inventory of devices and their compatibility

A list of the devices that use the hotspot, with the protection each one supports. Since 2020, the industry consortium that certifies Wi-Fi products has required WPA3 for new certifications.

  • Risk reduced: mixed mode left on for years for a device nobody uses any more.
  • Advantages: you know which device is holding back the move to WPA3, and you can decide whether to update it, replace it or connect it another way, for example with a cable.
  • Limits: it needs to be kept up to date; specifications for older devices are hard to find.
  • Complexity: basic.

WPA3-Enterprise and individual credentials

The version for organisations: each person signs in with their own credentials, checked by an authentication server, instead of using a shared password. A variant with 192-bit encryption serves environments with higher requirements.

  • Risk reduced: a shared password that spreads beyond the group.
  • Advantages: you can exclude one person without changing anything for everyone else; there is no password to share.
  • Limits: it requires dedicated infrastructure and someone to manage it; a personal hotspot does not normally offer it.
  • Complexity: advanced.

Comparison table

FunctionTechnologyRisk reducedMain advantageMain limitComplexity
PreventionSAE handshakePassword worked out offlineEvery guess has to be made liveDoesn’t strengthen a weak passwordBasic
PreventionAES encryptionTraffic decrypted or alteredStrong standard, protects integrityTKIP sometimes still onBasic
PreventionProtected management framesForced disconnectionsAutomatic and mandatory in WPA3Optional in WPA2Basic
PreventionTransition modeFalling back to weaker protectionWorks with older devicesReopens offline attacksBasic
PreventionOWEEavesdropping on open networksEncryption without a passwordDoesn’t authenticate the networkBasic
DetectionSecurity type shownProtocol other than expectedChecked in secondsInconsistent labelsBasic
DetectionWeak security warningsPoorly protected networksArrive on their ownPeople learn to ignore themBasic
ResponseCorrective updatesKnown vulnerabilitiesFix flaws without changing protocolDevices no longer updatedBasic
ResponseLeaving transition modeWPA2 door still openCloses the weakest pointLocks out forgotten devicesBasic
ResponseChanging the passwordPassword already discoveredResets the situationMust be updated everywhereBasic
GovernanceDevice inventoryNeedless mixed modeShows what holds back the switchMust be kept up to dateBasic
GovernanceWPA3-EnterpriseShared password spreadingIndividual credentialsRequires infrastructureAdvanced

How to choose

If you only use your hotspot with recent devices. WPA3 only, a long random password, automatic updates switched on: the simplest configuration and the best protected.

If you have at least one older device. WPA2/WPA3 mixed mode as a bridge, never WPA or TKIP, never an open network. Meanwhile, look for an update, consider connecting that device by cable, and set yourself a deadline for leaving transition mode.

If you share your hotspot or work in a small office. Keep an inventory of devices, agree a minimum threshold (never below WPA2), and change the password when you move to WPA3. For many people on a fixed network, the right direction is WPA3-Enterprise, on the office network.

A rule of thumb. No protocol makes a network invulnerable. The combination that gives the best result for the effort involved is WPA3 + a long random password + updates: WPA3 with a weak password can still be guessed, and a strong password in mixed mode is still exposed to offline attacks through the devices on WPA2. And Wi-Fi encryption only protects the stretch between the device and the phone; beyond that, the websites’ own encryption takes over, as the post on browsing only over HTTPS explains.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsUnderstanding what WPA2, WPA3 and mixed mode do, so you can choose the right setting without help
AwarenessRecognising that a network is only as protected as its oldest device and its weakest password
Secure BehaviourUpdating, checking the security type and leaving transition mode as soon as possible, as a habit

Reference level: FL3 — Autonomous. This is the level at which you understand a technology well enough to configure it on your own and adapt it to your devices.

Conclusion

WPA3 isn’t jargon for specialists: it’s how your phone’s network stops people nearby from reading what passes through the air and from working out the password at their leisure. Knowing how it works lets you choose it when it’s there, and use mixed mode only for as long as you need it. If you’d like to know where to start, the digital resilience self-assessment gives you a reference point.

What to do next. Open your hotspot settings and look at the security option. If it says WPA3, you’re already on the best choice; if it says WPA2/WPA3, find the device that needs it; if it says anything else, it’s time to change it.

Related content

Related resources

Short pieces from the Resources section, for anyone who wants to look at a single aspect more closely:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.