To set up a secure home Wi-Fi network, open your router's settings and choose WPA3-Personal, or WPA2/WPA3 transition mode if older devices still need to connect. Then set a passphrase of at least 16 characters, turn off WPS, put visitors and smart devices on their own networks and switch on automatic firmware updates. Hiding the network name adds no security.

Each setting answers a specific attack, and knowing which one makes the trade-offs easier when an old printer or smart plug refuses to connect. This guide covers the wireless security settings one at a time, with a checklist at the end. The rest of router setup (the admin password, remote management, UPnP) and Wi-Fi coverage are separate jobs. For how attackers intercept Wi-Fi traffic in the first place, see our explainer on eavesdropping attacks.

A short history of Wi-Fi security protocols

Your router's security menu is a record of the last three decades. Each protocol replaced one that had been broken, and many routers still offer the old ones for compatibility.

ProtocolIntroducedHow it protects the connectionUse it today?
WEP (Wired Equivalent Privacy)1997, in the first IEEE 802.11 standardRC4 cipher with a 40-bit key in the standard; vendors added 104-bit keysNo: the key can be computed from captured traffic
WPA (Wi-Fi Protected Access)2003, as a stopgap from the Wi-Fi AllianceTKIP: WEP's RC4-based mechanism with a longer key and a new key for every packetNo
WPA22004, the certification of IEEE 802.11iCCMP, based on AESOnly WPA2-Personal (AES), for devices that lack WPA3
WPA32018The SAE handshake for Personal networks, with Protected Management Frames requiredYes: WPA3-Personal

The dates come from the Wi-Fi Alliance's summary of legacy protocols and NIST's archived guide to securing legacy 802.11 networks, which records that the IEEE approved the first 802.11 standard, with WEP, in 1997. WPA was an interim fix that ran on WEP-era hardware; the IEEE finished the real replacement, 802.11i, in June 2004, and WPA2 is the Wi-Fi Alliance's interoperability certification for it. The Wi-Fi Alliance introduced WPA3 on June 25, 2018, and WPA3 support has been required in every new Wi-Fi CERTIFIED device since 2020. Its use is mandatory on the 6 GHz band, so a device that cannot do WPA3 cannot use a router's 6 GHz band at all.

WPA3 vs WPA2: what WPA3-Personal fixes

Both WPA2 and WPA3 encrypt your traffic well once a device is connected. The difference is in how a device proves it knows the password, and in what an attacker can do with a recording of that moment.

With WPA2-Personal (also labelled WPA2-PSK, for pre-shared key), a device and the router run a short handshake based on the shared password, and anyone within radio range can record it. That recording is enough to test password guesses offline: the attacker tries candidates on their own hardware, as fast as it runs, and the router never sees a single attempt. The researchers behind the Dragonblood study of WPA3 state it directly: a captured WPA2 handshake can be used to recover the network's password by brute force or with a dictionary. A short or common password falls quickly; a long random one does not.

A laptop copies the messages a phone and a router exchange as the phone joins the network, then, away from the router, tries a long row of keys until an orange one fits.
Fig. 1 With WPA2-Personal, one recorded join is enough: the guessing happens later, on the attacker's own hardware, where your router can neither slow it down nor notice it.

WPA3-Personal replaces that exchange with the Dragonfly handshake, which the Wi-Fi standard calls Simultaneous Authentication of Equals (SAE). The Wi-Fi Alliance puts the result plainly: with WPA3, an offline dictionary attack is not possible. An attacker has to guess against your router in real time, one exchange per guess. The Alliance says this protects even passwords weaker than usual advice recommends, which is no reason to choose one. SAE comes with three further protections:

  • Forward secrecy. Even if someone later learns the password, they cannot decrypt traffic they recorded earlier, or other users' traffic on the network.
  • Protected Management Frames (PMF). Every WPA3 network must use PMF, which protects management frames from forging: the control messages that devices and access points exchange.
  • No legacy fallbacks. WPA3 networks disallow outdated legacy protocols by design.

Most devices bought in recent years support it: Apple notes that WPA3 Personal works with every device that supports Wi-Fi 6 (802.11ax) and with some older ones. The router needs support too (see the note on firmware at the end). WPA3-Enterprise is the business variant, with an optional 192-bit security mode for sensitive networks; at home, WPA3-Personal is the one you want.

Use transition mode while older devices need WPA2

If your router offers WPA3-Personal but a printer, games console or smart plug only speaks WPA2, you have three options:

  1. WPA2/WPA3 transition mode (Apple's name is "WPA2/WPA3 Transitional"; router menus vary). WPA3 devices connect with WPA3 and older ones with WPA2, on the same network name and password. Apple recommends it for compatibility with older devices.
  2. Two networks: one WPA3-only network for phones and laptops, and one WPA2 network for the devices that need it, each with its own password. The Wi-Fi Alliance suggests this because some older or uncertified devices have trouble connecting to a transition-mode network, and it combines well with the smart-device network described below.
  3. WPA3-Personal compatibility mode, a newer option that hides WPA3 from older devices so they see a plain WPA2 network, while updated devices still connect with WPA3. It needs a firmware update on the router, and the Wi-Fi Alliance asks vendors to label it "WPA3-Personal compatibility" in their settings.

Transition mode has a known cost. Because the WPA2 side uses the same password, an attacker nearby can set up a fake WPA2-only copy of your network, force a WPA3-capable device onto it and record a WPA2 handshake to guess against offline. That is the Dragonblood downgrade attack disclosed in April 2019, and it is why the passphrase still matters on a transition network. A fake access point is the same trick behind evil twin attacks on public Wi-Fi. Once every device on the network supports WPA3, switch to WPA3-Personal only.

One mixed setting to avoid is WPA/WPA2 mixed mode. Apple lists it, with WPA Personal, WEP and anything with TKIP in the name, among the weak security settings to avoid. After you change the security mode, some devices need to forget the network and join it again to pick up the new settings.

Why WEP and WPA-TKIP have to go

If your router's menu offers WEP, WPA or anything with TKIP in the name, none of them belongs on a network you care about.

  • WEP is broken by design. NIST's guide explains that an attacker who captures enough traffic can compute a WEP key, and that longer keys do not help because the flaw lies in how WEP uses its initialization vector and the RC4 cipher.
  • WPA with TKIP was a stopgap. The Wi-Fi Alliance describes TKIP as an older technology with some vulnerability to cryptographic attacks, and says only WPA3 devices should be bought and used.
  • Operating systems are closing the door. Since Windows 10 version 1903, Windows shows a warning when joining a WEP or TKIP network, and Microsoft says a future release will refuse the connection. Apple devices show a security warning for the same settings.

If the router offers nothing better than WEP, WPA or WPA2 with TKIP, CISA's advice is to ask the internet provider that supplied it for an upgrade, or buy a new router. A router that old is also likely past the end of its firmware updates (see the last section). If you are choosing a replacement, Wi-Fi 7 explained covers what the newest generation needs to pay off.

Warning

Never switch security off, not even for a few minutes or only on the guest network. Apple's guidance is blunt: an open network lets anyone in range join, use your connection, reach shared devices and monitor the websites you visit.

Choose a long passphrase

WPA3 protects a weak password better than WPA2 did, but the password still carries weight: transition mode, a separate WPA2 network for old devices and a WPA2 guest network all keep a WPA2 handshake on the air. CISA suggests a memorable passphrase of 5 to 7 unrelated words, at least 16 characters in total, used for nothing else.

  • Pick the words at random, with dice or a password manager's generator, not a line from a song. A shape like lantern orbit maple cobalt ferry (do not use this one) is long and still easy to read out.
  • Keep personal details out: no address, surname, pet's name or phone number.
  • Change it when someone who had it should no longer have access, such as a former housemate, or when you find a device you cannot account for. Every device then needs the new one, which is the price of a shared password and the reason visitors belong on the guest network.

This is the Wi-Fi password. The router's admin password is a different secret, and it needs changing from the default as part of router setup.

Name the network, and do not bother hiding it

The network name (the SSID, or service set identifier) is broadcast to everyone in range, so treat it as public.

Hiding the SSID does not add security. A hidden network still transmits; the router only leaves its name out of its beacon frames, and a device that wants to join has to send probe requests that contain the name. Microsoft advises against hiding networks, because there are minimal security benefits and clients may have issues connecting and roaming; finding the name is trivial. Apple goes further: because of how devices search for networks, using a hidden network can expose information that identifies you and the hidden networks you use, such as your home network.

A laptop on a café table sends out signals that each carry a small house symbol, the name of its hidden home network. A second laptop nearby catches one of them, drawn in orange.
Fig. 2 A hidden network's name does not disappear: your devices ask for it by name, which can point back to your home network.

You will still find checklists that recommend hiding the name, including the Canadian Centre for Cyber Security's (CCCS) router best practices. The companies that write the Wi-Fi software on phones and laptops, Apple and Microsoft, both advise against it, and their reasoning holds: the encryption mode and passphrase protect the network, and the name only identifies it.

Give guests and smart devices their own networks

A guest network is a second Wi-Fi network from the same router, with its own name and password, that reaches the internet but not the devices on your main network. Use it for two groups:

  • Visitors. CISA's rule of thumb is that the guest network is for anyone who does not routinely connect to your home Wi-Fi, with its own long, random password. Visitors never learn the main password, so you never have to change it after they leave.
  • Smart devices. Cameras, plugs, speakers and TVs that only need the internet do not belong beside your laptop. On a guest network they cannot discover your other devices, reach the router's settings or bring their own vulnerabilities onto your main network, CISA notes. The CCCS recommends a guest network for your guests and for your IoT devices for the same reason.

If the router can run more than one extra network, give smart devices one and visitors another, so a guest's infected phone and your doorbell camera cannot reach each other either. The smart-device network is also the natural home for anything stuck on WPA2, which lets the main network run WPA3 only. If the router offers a single guest network, put both groups on it, as CISA and the CCCS suggest: it still keeps them away from your computers and phones. Our guide to smart home devices covers choosing and securing the devices themselves; auditing and segmenting an existing network in depth is a separate job from setting up its Wi-Fi.

Settings worth checking on any guest network:

  1. Security on. Use WPA2 or WPA3 with its own password, different from every other network and account.
  2. No access to the local network. Whatever your router calls the option, guests should reach the internet and nothing else.
  3. Time limits if the router offers them. The CCCS suggests limiting how long a guest password stays valid, so only current guests can connect.
  4. Wi-Fi Enhanced Open, if offered, encrypts an open network's traffic without a password. Anyone in range can still join, so it suits a café better than a home.

Turn off WPS

Wi-Fi Protected Setup (WPS) was meant to make joining easier: press a button on the router, or type the 8-digit PIN printed on its label. In December 2011, CERT/CC vulnerability note VU#723755 documented a design flaw in the PIN method:

  • the router's replies to a wrong PIN reveal whether the first half was right, so each half can be guessed on its own;
  • the last digit is a checksum, so it never needs guessing;
  • together, that cuts the search from 100 million attempts to at most 11,000 (10,000 for the first half, 1,000 for the second);
  • many routers did not lock out repeated attempts.

An attacker within range who finds the PIN can recover the Wi-Fi password, change the router's configuration or knock it offline. CERT/CC's workaround was to disable WPS, and the CCCS and CISA still say to turn it off. Look for the setting under the names CERT/CC lists, such as "WiFi Protected Setup", "router PIN" or "external registrar", and turn off the PIN method along with the rest. If a router gives you no way to turn it off, that is one more reason to replace it. Android itself deprecated WPS in Android 9.

Share Wi-Fi safely: QR codes and Wi-Fi Easy Connect

Reading a long passphrase aloud is the main reason people choose short ones. Share it without typing instead:

  • Android: open Settings, then Network & internet, Internet, your network and Share. The phone shows a QR code another device can scan to join.
  • iPhone: in the Passwords app, open Wi-Fi, choose the network and tap Show Network QR Code. Between Apple devices that are in each other's contacts and within range, the iPhone also offers to share the password when the other device tries to join.
  • A printed card: print the guest network's QR code for visitors, never the main one. Anyone who photographs it can join, so treat it like the password itself.

Wi-Fi Easy Connect, which the Wi-Fi Alliance introduced alongside WPA3 in 2018, goes one step further for devices without a screen. You scan the QR code on the new device, such as a smart plug or a camera, with your phone, and the phone hands it the network credentials. Android has supported it since Android 10 under its technical name, the Device Provisioning Protocol (DPP), for both WPA2 and WPA3 networks, and describes it as an alternative to WPS. The new device has to support it too; where it does, it is the cleanest way to add a device without a PIN or a typed password.

Skip MAC address filtering

MAC address filtering lets only devices on an allow list join. It sounds strict and protects little. Apple's router guidance says to leave it disabled and not rely on it, for three reasons: it does nothing against someone monitoring traffic on the network; MAC addresses can easily be copied, spoofed or changed; and devices now use a different address for each network. The CCCS checklist still lists it as an optional extra; it cannot keep out anyone who can copy an address.

A router checks the orange tag on each device's messages against an allow list. A laptop copies the tag a phone uses, puts the same tag on its own messages and is let through too.
Fig. 3 A MAC allow list checks a label every device announces in the open; copying the label is all it takes to pass.

The last point turns MAC filtering from weak into a nuisance. iPhones and iPads since iOS 14 use a private Wi-Fi address for each network, and since iOS 18 that address rotates every two weeks by default on networks with weak or no security. Android has used a randomized MAC address by default since Android 10. A phone that resets its network settings joins with a new address and is locked out of your own allow list. Encryption and a strong passphrase decide who joins; the address list does not.

Check who is connected

The router's app or admin page lists the connected devices, usually with a name, an IP address and a MAC address. Look at it every few months, and after any change to the network:

  1. Match each entry to a device you own, and rename entries in the router if it allows, so the list stays readable.
  2. Expect unfamiliar MAC addresses. With private addresses, the address a phone uses on your network is not its hardware address; compare with the Wi-Fi address shown in the device's own network details.
  3. Change the passphrase if something cannot be accounted for, then rejoin your own devices. Anything that does not come back was not yours.
  4. Turn on new-device alerts if the router or its app offers them, and keep watching the guest network too: the CCCS guest Wi-Fi guidance says to monitor what is connected there as well.

Keep the router's firmware updated

Wi-Fi security keeps changing after you buy the router. The fixes for Dragonblood shipped as vendor updates, WPA3-Personal compatibility mode requires one, and Apple notes that updates can change the security settings a router offers. Set the router to install firmware updates automatically if it can; if it cannot, check for updates in its app or admin page every few months.

A router that no longer receives updates is a standing risk. In May 2025 the FBI warned that criminals were compromising end-of-life routers with variants of TheMoon malware and using them to run criminal proxy services, noting that routers dated 2010 or earlier are likely no longer updated and that some compromised routers had remote administration turned on. The FBI's advice is to replace an end-of-life router, apply every available update and turn off remote management. Signs that a router itself is compromised include overheating, connection problems and settings changes you do not recognize. If your internet provider supplied the router, ask them whether it still receives updates.

Important

Firmware updates are also how new security modes arrive. If your router shows no WPA3 option, or no way to turn off WPS, update it and look again before deciding it needs replacing.

Home Wi-Fi security checklist

SettingSet it toWhy
Security modeWPA3-Personal; WPA2/WPA3 transition while old devices need itSAE stops offline password guessing
Never useWEP, WPA, TKIP, WPA/WPA2 mixed, openBroken, obsolete or unencrypted
Wi-Fi passphrase5 to 7 random words, 16 characters or moreIt still guards every WPA2 connection
Network nameChanged from the default, nothing personalDefault names reveal the router model
Hidden networkOffNo security benefit; devices announce the name
Guest networkOn, own password, no local network accessVisitors never get the main password
Smart devicesTheir own networkA compromised camera cannot reach your laptop
WPSOff, including the PINThe PIN falls in at most 11,000 guesses
MAC address filteringOffAddresses are easy to copy and now private per network
Firmware updatesAutomaticSecurity fixes and new modes arrive this way

The same settings apply to a small office, with more at stake: staff, visitor and device networks to keep apart, and more people who know the password. Our IT support team takes on projects such as a new office, and security scanning checks what your public IP addresses expose to the internet, such as open ports and services.