CYBER WELFARE

Protect your Digital Privacy

The impact of weak Wi-Fi encryption: what your hotspot’s protocol leaves exposed

Mark has done things properly. His phone’s hotspot — the feature that turns a smartphone into a small Wi-Fi router and shares its mobile data connection — has a long password, used only there and changed recently. One day, scrolling through the settings, he notices an option he had never looked at: “Security”. Next to it is an acronym, WPA2, and a menu with other choices: no protection, WPA2/WPA3, WPA3. The question he asks himself is a fair one: if the password is good, what difference does an acronym make?

It makes a real difference. The password is the key; the encryption protocol is the lock that key goes into. Encryption is the process that makes data sent over the air unreadable to anyone who doesn’t hold the key; the protocol is the set of rules the phone and the connected devices use to recognise each other and encrypt what they exchange. An excellent key in an old lock protects less than it seems.

The acronyms, in brief: WEP is the first protection system Wi-Fi ever had, now considered obsolete; WPA2 has been the standard for many years and is still solid when used well; WPA3 is the newest generation, designed to close the weak spots of the one before.

So the more useful question is a different one: if the protocol you chose were weak, what would be touched?

This post looks at the impact of weak Wi-Fi encryption through the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are confidentiality, integrity and availability, and they help you see that weak encryption is not a detail for technicians.

It expands on the recommendation on hotspot encryption and complements the one on your mobile hotspot password: that one is about the key, this one is about the lock.

Three questions to measure an impact

They apply every time you open your hotspot’s “Security” setting, and not only when something goes wrong:

  1. What could someone within range of my network read, even without connecting? — this is the confidentiality question.
  2. What could they alter in the traffic, or reach on the connected devices? — this is the integrity question.
  3. What would I no longer be able to do if the connection were cut off or taken up? — this is the availability question.

With WPA3 and a strong password, the answers are modest. With an open network or one protected by WEP, the answer to all three is: a lot, and nobody needs to guess anything. This is where the protocol changes the maths: with weak encryption, the impact no longer depends on how good your password is, but on how easy it is to get around it.

1. Confidentiality: what travels over the air stays readable only to you

Confidentiality is the guarantee that information can be read only by those who are authorised to read it. On Wi-Fi it is a delicate matter, because radio waves don’t stop at your devices. Anyone within a few dozen metres receives the same signals: encryption decides whether those signals are noise or readable text.

A practical example

Years ago, Mark’s old tablet couldn’t connect to the hotspot. He solved it by switching the protection off: an open network, “I only use it for five minutes anyway”. Then it stayed that way. On a network with no encryption, someone nearby with suitable equipment can collect the traffic passing through the air without connecting to anything, and without anyone noticing.

What the incident looks like

Many websites and apps today protect their content with HTTPS — encryption between your device and the website, independent of the Wi-Fi, the sealed envelope of the web — and that greatly limits the damage. But not everything is protected in the same way: the names of the sites you visit, the times, the devices present and the content of any app or service that still communicates without encryption can remain visible. With WEP the situation is similar: the protection exists on paper, but its flaws make it possible to work out the key by observing the traffic for a relatively short time.

With WPA2 the traffic is well encrypted, but there is a subtle point. When a device connects, the phone and the device exchange a few opening messages: the “handshake”, with which they check each other. Anyone who records them can later try, far from your network and with no hurry, a huge number of candidate passwords until one fits. It’s called an “offline” attack because it happens on the attacker’s computer, not on your phone. If the password is long and random, the attempt gets nowhere in any realistic time; if it’s short or predictable, it can succeed. WPA3 changes exactly this: every attempt requires a live exchange with the network, and the offline attack stops being practical.

What to watch for

  • your hotspot settings show the security as “None”, “Open” or WEP;
  • your laptop or tablet flags your network as “not secure” or as using “weak security”;
  • at some point you lowered the protection to let a device connect, and you don’t remember whether you changed it back;
  • your hotspot password is short or based on information that is easy to guess.

What to do

Choose WPA3 if your phone offers it, otherwise WPA2 (often shown as WPA2-Personal or WPA2-PSK). Don’t use an open network or WEP for your hotspot, not even “just for a moment”. Pair the protocol with a long, random password: with WPA2 it is your real defence against the offline attack.

2. Integrity: traffic arrives as it was sent

Integrity is the guarantee that data isn’t altered by anyone without the right to do so. On Wi-Fi, modern encryption doesn’t just hide things: every packet of data carries a check that reveals whether it was changed along the way. A weak protocol, or none at all, removes that check.

A practical example

On a network with no protection, or one protected by WEP, someone nearby can slip into the conversation between the devices and the phone. An unencrypted web page can arrive altered — for example, with a fake notice urging you to download an “update”.

What the incident looks like

The most concrete impact is a chain: a weak protocol makes it possible to work out the key, the key opens the network, and from inside it the connected devices can be reached. Mark’s laptop, with file sharing switched on, becomes visible to a stranger who is effectively “inside the house” without having been invited. Nobody broke into the laptop: it was the protocol that left the door ajar.

What to watch for

  • invalid certificate warnings on websites that normally open without any problem;
  • familiar pages that look different or make unusual requests;
  • devices you don’t recognise in the list of those connected: unknown devices on your hotspot are a sign not to overlook;
  • unexpected prompts to install updates or components while you’re connected to the hotspot.

What to do

With WPA2 or WPA3, tampering with the traffic from outside the network becomes much harder. Never ignore a certificate warning: close the page rather than carrying on. Keep your phone and connected devices up to date, because even solid protocols have had flaws, fixed precisely through keeping your software up to date.

3. Availability: the connection is there when you need it

Availability is the guarantee of being able to use the network at the moment you need it. Here the impact is less intuitive, but real.

A practical example

Mark is on a video call with a client, his laptop connected to the hotspot. The connection drops, comes back, drops again, even though the signal is full and the phone is half a metre away. With WPA2, unless an extra protection called PMF is active (Protected Management Frames, the protection of the network’s service messages), some control messages — such as the one telling a device “disconnect” — aren’t authenticated, and someone nearby can imitate them. WPA3 makes this protection mandatory.

What the incident looks like

Forced disconnections aren’t just a nuisance: every time the device reconnects it repeats the handshake, which can be recorded for the offline attack described above. If the password is worked out, the next step is a crowded network: unfamiliar devices connect and use up data and bandwidth and, since many phones accept only a limited number of simultaneous connections, your own devices may be left out.

There is also a limit worth stating honestly: no protocol prevents actual radio interference. WPA3 reduces disconnections “on command”; it doesn’t make them impossible.

What to watch for

  • repeated disconnections within a short time, with a good signal and the phone close by;
  • mobile data being used up faster than usual;
  • the hotspot reporting that the maximum number of devices has been reached;
  • noticeable slowdowns only when the hotspot is on in crowded places.

What to do

Prefer WPA3, which includes protection for service messages; if you use WPA2, check whether your phone lets you turn on PMF. Switch the hotspot off when you don’t need it, and check the list of connected devices from time to time.

AspectWhat someone exploiting a weak protocol can doWhy it matters
ConfidentialityReads unencrypted traffic, works out the password with an offline attackIt happens at a distance and leaves no trace on the phone
IntegrityAlters unprotected traffic, gets into the network and reaches connected devicesTurns a weakness in the network into access to your devices
AvailabilityCauses disconnections, crowds the network and uses up your dataInterrupts your work and prepares the ground for other attacks

One scenario that brings them together

Three years ago Mark set up his hotspot with WPA2 and a password that was easy to read out: the name of his studio followed by the year. He often turns it on at the station — always the same one — on the mornings he works on the train.

One morning a series of disconnections forces him to reconnect his laptop several times (availability). Each reconnection produces a handshake that can be recorded. Far from the station, the predictable password is found with an offline attack. From then on, the traffic from Mark’s devices recorded on those mornings may become readable wherever it wasn’t protected by HTTPS (confidentiality), and the next time an unfamiliar device can join the network and reach the laptop with its shared folders (integrity).

Three impacts, a single combination: a protocol that allows the offline attack and a password that can’t withstand it. With WPA3, the scenario stops much earlier.

The impacts that show up later

Not every effect appears right away, which is why “nothing has happened” isn’t a reliable check.

  • Traffic recorded today, read tomorrow. With WPA2, someone who knows the password and has recorded the handshakes can also decrypt past traffic. WPA3 introduces forward secrecy: each session has its own keys, and discovering the password later doesn’t open conversations that have already taken place.
  • A password worked out at leisure. The offline attack keeps no timetable: it can happen days or weeks after the recording, without any sign for you.
  • Compatibility that lingers. The mixed WPA2/WPA3 mode lets each device connect with the best protocol it supports. It’s convenient, but an old device will keep using WPA2, and in some cases someone nearby can push a modern one to do the same.
  • Forgotten settings. Protection lowered “for a moment” tends to stay that way for years, as with Mark’s tablet.

This isn’t a reason to live on high alert, but to choose the protocol with care and check it every now and then: WPA3, or at least WPA2 with a long password, reduces all of these effects, including the ones you’ll never see.

Not all protocols weigh the same

Security settingMain impactWhy
No protection (open network)All threeTraffic travels unencrypted and anyone can connect
WEPAll threeThe key can be worked out by observing traffic: the protection is only apparent
WPA, first versionConfidentiality and integrityObsolete, with known weaknesses: not to be used
WPA2-PersonalConfidentiality, if the password is weakSolid, but exposed to the offline attack and, without PMF, to forced disconnections
WPA2/WPA3 (mixed mode)Depends on the oldest deviceEach device uses the best protocol it supports
WPA3-PersonalLow, with updates in orderResists the offline attack, protects service messages, offers forward secrecy

The last row doesn’t mean “100% secure”: it means the protocol is no longer the weak link.

Why the password matters with any protocol

CombinationWhat happens
WEP + very long passwordThe password counts for little: the flaw is in the protocol
WPA2 + Studio2023The protocol holds, the password gives way to the offline attack
WPA2 + long, random passphraseGood protection of content; forced disconnections and the lack of forward secrecy remain
WPA3 + short passwordThe offline attack isn’t practical, but anyone who guesses or is given the password still gets in
WPA3 + long, unique passwordThe most solid combination available for a hotspot today

For the key, the recommendation on your mobile hotspot password applies. And when the network isn’t yours, you don’t choose the protocol: that’s why there is specific guidance on why you should not handle sensitive data on public Wi-Fi and on when a VPN for sensitive traffic genuinely helps.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessRecognising that the encryption protocol, and not only the password, decides what stays exposed
SkillsBeing able to read the acronyms WEP, WPA2 and WPA3 in the settings and understand what they protect
Secure BehaviourChoosing the strongest protocol available and checking it again after a new phone or an update

Reference level: FL2 — Beginner. This is the level at which you move from “I’ve set a password” to “I understand what protects it and what doesn’t”. If you’d like to see where you stand on the other aspects of your digital security, you can start with the digital resilience self-assessment.

Summary

  • Confidentiality is about what gets read: unencrypted traffic, a password worked out with an offline attack, recorded conversations.
  • Integrity is about what gets altered or reached: tampered traffic, exposed connected devices.
  • Availability is about what you can no longer use: a connection that keeps dropping, a crowded network, data used up.

Weak encryption doesn’t produce just one impact: it opens the door to all three, even when the password was chosen with care.

One thing to do today. Open your hotspot settings and look at the “Security” option. If you find “None” or WEP, change it straight away. If WPA3 is there, choose it; if some of your devices can’t connect, use the mixed WPA2/WPA3 mode rather than lowering the protection. Then check that the password is long. It takes about five minutes, and it covers all three impacts at once.

Related content

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.