WPA2 vs WPA3: what's the difference?
WPA3 is the WiFi security standard that succeeded WPA2 in 2018, adding stronger encryption (192-bit security mode for enterprise networks) and — the change that matters most for home networks — protection against offline dictionary attacks on your WiFi password.
WPA2, introduced in 2004, was the standard for nearly a decade and a half, and it's still what the majority of home routers ship with today. Its core weakness: if an attacker captures the handshake when a device joins your network, they can take that capture offline and try password guesses against it indefinitely, with no rate limiting, using cheap cloud compute.
WPA3 closes that specific hole with a new handshake method (Simultaneous Authentication of Equals, SAE) that makes offline guessing computationally impractical — each guess requires interacting with the live access point, so it can't be parallelized offline the way WPA2's handshake capture can. WPA3 also adds forward secrecy (past traffic stays safe even if the password is later compromised) and individualized data encryption on open networks.
In practice: WPA3 requires both a WPA3-capable router and WPA3-capable client devices, and many routers ship in a WPA2/WPA3 mixed mode for compatibility with older devices, which doesn't get the full benefit. If your router supports WPA3-only mode and all your devices are recent enough to support it, that's the stronger configuration.
FAQ
- Should I switch my router to WPA3?
- Yes, if your router and all your devices support it. Check your router's WiFi security settings — if WPA3 or WPA2/WPA3-mixed is available, use it. If any older device on your network can't connect once you switch, you'll need mixed mode until you upgrade that device.
- Is WPA2 still safe to use?
- WPA2 with a strong, long passphrase is still reasonably safe for typical home use — the offline-attack weakness matters most against attackers who specifically target you and capture a handshake. It's meaningfully weaker than WPA3, but it's not "broken" in the sense of being trivially crackable with a strong password.
- What about WEP?
- WEP is the WiFi security standard from 1997 and is genuinely broken — it can be cracked in minutes regardless of password strength. If any device on your network still offers WEP, don't use it; it predates both WPA2 and WPA3 by years and has no place on a modern network.