Instiq
Chapter 6 · Security·v1.0.0·Updated 7/17/2026·~13 min

What's changed: Initial version

6.3Wireless security settings on a home router

Key points

Covers the generational differences of the wireless encryption standards WPA/WPA2/WPA3 that protect home and SOHO Wi-Fi, how to choose between Personal (PSK) using a pre-shared key and Enterprise (802.1X/RADIUS) using per-user authentication, and why the still-seen WEP and WPA (TKIP) are deprecated—as the basic judgment of "which method to choose for this environment."

Because Wi-Fi is radio, unlike wired networks it must be protected on the assumption that "anyone nearby can attempt to receive it." A home router's security settings look daunting, but the essentials are two: "which encryption standard to choose" and "how to distribute the key." This section covers the generations of wireless encryption—WPA/WPA2/WPA3—the two modes of home-oriented Personal (PSK) and enterprise-oriented Enterprise (802.1X/RADIUS), and why the old WEP and WPA (TKIP) still offered as options should be avoided—framed as the basic judgment of "which to choose for this environment."

6.3.1The WPA/WPA2/WPA3 generations

  • WPA2 was the long-standing standard, using the strong cipher AES/CCMP. Still widely used, it is an acceptable safe minimum on a home router. The TKIP used by the original WPA is already weak and deprecated.
  • WPA3 is the newest generation, adopting SAE for key exchange to resist password-guessing attacks, and mandating PMF (protected management frames) for greater safety. When all devices support it, choosing WPA3 is best.
  • The strength order is WPA (TKIP) < WPA2 (AES) < WPA3 (SAE). When old devices are mixed and you cannot standardize on WPA3, the next-best is a WPA2/WPA3 mixed (transition) mode—and at minimum avoid WEP and the original WPA.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.