WPA2-PSK is WPA2 Wi-Fi security with a pre-shared key: one passphrase for every device, also called WPA2-Personal. The passphrase and the SSID make a 256-bit pre-shared key, and each device derives its own session keys through a four-way handshake.
The catch is offline guessing: a captured handshake, or a PMKID from the access point, can be taken away and guessed against with no lockout, so the passphrase is the whole defense.
KRACK attacked the handshake itself and was fixed by patching, not a new password. WPA2-Enterprise gives each user separate 802.1X credentials, and WPA3-Personal resists offline guessing by design.
- WPA2-PSK is WPA2 with one shared passphrase, also called WPA2-Personal
- The passphrase and SSID produce a 256-bit pre-shared key
- Each device derives its own session keys through a four-way handshake
- A captured handshake or PMKID can be guessed against offline
- WPA2-Enterprise gives each user 802.1X credentials via RADIUS
On this page
What it isWhat WPA2-PSK actually is
The name packs three ideas together, and taking them apart explains the whole security model.
WPA2 is the protocol. It is the Wi-Fi security generation that uses AES-CCMP to encrypt traffic. The encryption itself is strong, and it is not where WPA2-PSK networks fall down.
PSK is the authentication method. A pre-shared key is the authentication that validates users on the network, a shared secret, a passphrase the router and every connecting device know in advance. It authenticates a device without sending the password over the air. It is typically 8 to 63 characters.
Personal is the deployment mode. WPA2-PSK and WPA2-Personal are the same thing: one passphrase for the whole network, set on the access point and typed into every device. It is the standard for homes and small offices, and it needs no server.
One key means one identity. Every device authenticates with the same secret, so the network cannot tell one user from another, cannot revoke one device without changing the passphrase for all of them, and cannot produce a per-user record of who connected. That is the trade for having nothing to run.
Passphrase to keysFrom passphrase to session keys
The passphrase is not the encryption key, and understanding the steps between them is what makes the attacks make sense.
The passphrase becomes the PSK. The passphrase and the SSID are run through a key derivation function to produce a 256-bit pre-shared key.
Wireshark's own decryption documentation shows the relationship directly: to decrypt WPA traffic you can supply the passphrase and SSID, or the raw pre-shared key they produce. The SSID is part of the recipe, which is why the same passphrase on two differently named networks yields different keys.
The four-way handshake derives per-session keys. When a device joins, it and the access point exchange four EAPOL messages. From the pre-shared key and fresh random values from each side, both compute a Pairwise Transient Key that actually encrypts the session.
Wireshark cannot decrypt a session unless all four handshake packets were captured, which is the clearest sign that the handshake, not the passphrase, is what crosses the air.
Every device gets different session keys. Two laptops on the same WPA2-PSK network do not share the same live encryption key, because the random values in each handshake differ. What they share is the pre-shared key underneath, and that is the part an attacker wants.
The handshake can be forced. An attacker does not have to wait for a device to join. Wireshark's guidance notes that to capture a handshake you make a machine re-join the network while capturing, and a deauthentication frame does exactly that. This is why a network is not safer just because nobody is connecting right now.
Offline guessingWhy a captured handshake is a password problem
This is the sentence that matters most about WPA2-PSK: capturing the handshake turns network security into password strength, offline.
The captured material is guessable at leisure. Once an attacker has the four-way handshake, or a PMKID that an access point can hand out without any client at all, they take it away and try passphrases against it on their own hardware. hashcat documents a hash mode, 22000, built for exactly this, combining PMKID and EAPOL captures into one format for cracking.
Offline means no lockout and no alarm. There is no account to lock, no failed-login counter, nothing on the network to notice. The attacker guesses billions of candidates against the captured hash, limited only by their GPUs and the passphrase.
So the passphrase is the control. A long, random passphrase is infeasible to guess; a short or common one falls in minutes. On WPA2-PSK there is no second factor and no server to slow anyone down, so length and unpredictability are the entire defense.
A leaked passphrase is a silent, total compromise. Because everyone shares it, a passphrase written on a whiteboard or kept by a departed employee gives full access, and nothing in the logs shows it was used. Changing it means re-keying every device.
KRACKKRACK, and why a new password did not fix it
In 2017 the four-way handshake itself was broken, and the episode is worth knowing because the instinctive fix was the wrong one.
KRACK attacked the handshake, not the password. The key reinstallation attack, disclosed by Mathy Vanhoef, forced reuse of a handshake value so that traffic could be replayed, decrypted or forged. The site describing it is blunt on the popular reaction: changing the Wi-Fi password does not prevent or mitigate the attack.
It hit personal and enterprise alike. The researchers state the attack works against WPA1 and WPA2, against personal and enterprise networks, and against any cipher suite, including AES-CCMP. A stronger passphrase would not have helped, because the passphrase was not the weakness.
The fix was patching both ends. Their guidance is to update all client devices and the router firmware, and they note that both the client and the access point must be patched to defend against all variants. This is the clearest example that Wi-Fi security is software that needs updating, covered more generally in patch management.
The lesson generalizes. When a protocol is broken, the answer is a patch, not a new secret. Rotating the passphrase after patching is fine housekeeping, but it fixes nothing about KRACK on its own.
WPA3-PersonalWPA3-Personal and what it changes
WPA3 is the successor, and the Wi-Fi Alliance is specific about what its personal mode improves.
It is mandatory for new certified devices. The Wi-Fi Alliance states that WPA3 is required for Wi-Fi CERTIFIED devices, that WPA3 networks use the latest security protocols and disallow outdated legacy ones, and that they require Protected Management Frames.
Personal mode targets exactly the WPA2-PSK weakness. The Alliance says WPA3-Personal users receive increased protection from password guessing attempts. WPA3-Personal replaces the four-way handshake's key exchange with one designed so that a captured exchange cannot be taken away and guessed against offline the way a WPA2 handshake can.
Transition takes time. Devices roll over as they are replaced, and many networks run a mixed mode so older clients still connect, which keeps the WPA2 behavior available. A network is only as strong as the mode a given client actually negotiates.
It does not remove the case for enterprise. WPA3-Personal is still one shared secret. Per-user identity, revocation and an audit trail still mean 802.1X, whether under WPA2-Enterprise or WPA3-Enterprise.
EnterpriseThe enterprise alternative, briefly
WPA2-PSK's limits are what WPA2-Enterprise exists to remove, and the difference is the authentication method.
Enterprise gives every user separate credentials. Instead of one shared passphrase, WPA2-Enterprise uses 802.1X authentication: each user or device authenticates with its own credentials, often a username and password or a client certificate, verified by a RADIUS server, and each session gets its own encryption keys.
There is no shared secret to leak, a single user can be revoked without touching anyone else, and the RADIUS server records who connected and when.
The cost is the server. Enterprise needs the RADIUS infrastructure and a way to issue and manage credentials, which is why homes and small offices stay on PSK. A guest network on PSK, kept separate on its own VLAN, is a common and reasonable middle ground.
The decision is about identity, not encryption. Both modes encrypt wireless traffic with the same ciphers. The question is whether the network needs to authenticate and record each user, which is the same instinct behind zero trust. Certificate-based authentication removes the shared password entirely, at the cost of issuing and managing certificates.
PitfallsWhere people go wrong
Trusting a short passphrase because the encryption is strong. AES is not the weak point. A captured handshake is guessed against offline, so a weak passphrase is a weak network no matter the cipher.
Assuming nobody can capture the handshake. An attacker can force a device to reconnect and capture it in seconds, or pull a PMKID from the access point with no client involved.
Changing the password after a protocol flaw. KRACK was fixed by patching, not by a new passphrase. Match the fix to the problem: a protocol break needs a patch, a leaked secret needs a new secret.
Sharing one passphrase across staff and guests. One key is one identity. A single passphrase for everyone means no revocation and no record, and it walks out the door with whoever leaves.
Leaving mixed WPA2 and WPA3 mode and assuming WPA3 protection. A client that negotiates WPA2 gets WPA2's exposure. The stronger mode only helps the sessions that actually use it.
Reusing the office passphrase as a personal password. It is known to everyone on the network and it is exactly the kind of secret that ends up in a cracking wordlist.
Skipping the guest network. Visitors on the same PSK as the servers is the most common avoidable mistake. A separate guest SSID on its own VLAN costs nothing and contains the damage.
ComparisonPersonal, enterprise and WPA3 Wi-Fi security
| Criterion | WPA2-PSK | WPA2-Enterprise | WPA3-Personal |
|---|---|---|---|
| Authentication | One shared passphrase | Per user, 802.1X | One passphrase, stronger exchange |
| Needs a RADIUS server | No | Yes | No |
| Per-user identity | No | Yes | No |
| Can revoke one device | No | Yes | No |
| Offline guessing of a capture | Feasible | Much harder | Resisted by design |
| Connection record per user | No | Yes | No |
| Fits homes and small offices | Yes | Rarely | Yes |
| Protected Management Frames | Optional | Optional | Required |
The offline-guessing row is the one that sends security-conscious networks to enterprise or to WPA3.
FAQFrequently asked questions
What is WPA2-PSK?
WPA2 Wi-Fi security using a pre-shared key: a single passphrase, shared by every device, also called WPA2-Personal. The passphrase and the SSID produce a 256-bit pre-shared key, and each device derives its own session keys from a four-way handshake.
Is WPA2-PSK the same as WPA2-Personal?
Yes. The two names describe the same mode: one shared passphrase, no authentication server, intended for homes and small offices.
What is the difference between WPA2-PSK and WPA2-Enterprise?
PSK uses one shared passphrase for everyone. Enterprise uses 802.1X authentication, so each user or device has its own credentials, a password or a certificate, verified by a RADIUS server, which allows per-user revocation and a record of which users connected. Enterprise needs that server; PSK needs nothing.
Is WPA2-PSK secure?
The encryption is strong, but the security rests entirely on the passphrase, because a captured handshake can be guessed against offline with no lockout. A long, random passphrase is secure; a short or common one is not.
How is a WPA2-PSK password cracked?
An attacker captures the four-way handshake, often by forcing a device to reconnect, or captures a PMKID from the access point, then guesses passphrases against it offline. hashcat has a dedicated mode, 22000, for this.
What is the four-way handshake?
The exchange of four EAPOL messages when a device joins a WPA2 network. From the pre-shared key and random values from each side, both derive the session keys that encrypt traffic. Wireshark needs all four packets to decrypt a session.
Does changing my Wi-Fi password stop KRACK?
No. The researchers behind KRACK state that changing the password does not prevent or mitigate the attack. The fix is patching both client devices and the access point.
Was KRACK a WPA2-PSK problem specifically?
No. It affected WPA1 and WPA2, personal and enterprise, and every cipher suite, because it attacked the handshake rather than the passphrase.
Should I use WPA3 instead?
Where devices support it, yes. The Wi-Fi Alliance says WPA3 is mandatory for newly certified devices, and WPA3-Personal increases protection against password guessing. Watch for mixed mode, where an older client still negotiates WPA2.
How long should a WPA2-PSK passphrase be?
The standard allows 8 to 63 characters. Because the only defense is guessing difficulty, use a long, random passphrase rather than the minimum, and never a dictionary word or a reused password.
Can I tell who is on a WPA2-PSK network?
Only by device, not by person, because everyone shares one secret. Per-user identity and a connection record require WPA2-Enterprise or WPA3-Enterprise with 802.1X.
What is a PMKID attack?
An attack where the access point discloses a PMKID that is derived from the pre-shared key, letting an attacker attempt offline guessing without needing a client to be present. It is one of the capture types hashcat's mode 22000 handles.
What makes for good WiFi password security?
With WPA2-PSK the passphrase is the only thing protecting the network, so length matters most. Use at least 16 characters, or several random words. Change it when staff leave, since everyone shares it. Keep guests on a separate network. WPA3 adds protection against offline guessing.
Keep readingRelated concepts
Read next · Cryptography Encryption Algorithms, and the Two Families They Fall Into The AES-CCMP that WPA2 actually encrypts with, and why it is not the weak point. Open this next11 min- Wireless · 9 min A WLAN Is a LAN With a Radio in Front of It The wireless network WPA2-PSK secures, and where the SSID and access points fit.
- Ports · 10 min TACACS+ vs RADIUS, Port by Port and Claim by Claim The RADIUS server that WPA2-Enterprise uses to give each user separate credentials.