Key Takeaways
- WPA3 is the newer Wi-Fi security protocol and offers meaningfully stronger protection than WPA2.
- WPA2 remains secure for most home use when paired with a strong, unique password.
- WPA3 introduces protections against offline dictionary attacks that WPA2 cannot offer.
- Many modern routers support both protocols simultaneously via a transition mode.
- Older devices may not support WPA3, making compatibility an important practical consideration.
Option A
WPA2
The long-standing, widely supported Wi-Fi security standard.
Best for: Devices and routers that predate WPA3 adoption, or networks where broad device compatibility is the top priority.
Option B
WPA3
The modern, more robust successor built for today's threat landscape.
Best for: Newer routers and devices where stronger encryption and resistance to password-guessing attacks are needed.
If you have a newer router and mostly modern devices
WPA3
WPA3 delivers stronger encryption and forward secrecy, making it worth enabling if your hardware supports it without sacrificing device compatibility.
If your network includes older smart home devices or legacy hardware
WPA2
Many older devices lack WPA3 support entirely. Using WPA2 or a router's WPA2/WPA3 transition mode prevents frustrating connectivity issues.
If you frequently use public or shared Wi-Fi networks
WPA3
WPA3's Opportunistic Wireless Encryption (OWE) mode can protect open networks that WPA2 leaves entirely unencrypted.
If you manage a small business or shared office network
WPA3
WPA3-Enterprise mode uses 192-bit encryption and stronger authentication, raising the security floor for environments handling sensitive data.
What These Protocols Actually Do
Wi-Fi Protected Access (WPA) protocols are the security frameworks that govern how data is encrypted between your device and a wireless router. Without them, anyone within radio range could potentially intercept the traffic flowing across your network. To understand why the protocol version matters, it helps to first understand how a Wi-Fi connection is actually established — the handshake between your device and the router is precisely where these protocols do their work.
WPA2, introduced in 2004 and mandated for Wi-Fi certified devices from 2006, replaced the older WEP and WPA standards. It uses AES (Advanced Encryption Standard) encryption and a protocol called CCMP, which was a significant leap in security at the time. WPA3, certified by the Wi-Fi Alliance in 2018, builds on that foundation with several important improvements designed to address vulnerabilities that researchers had identified in WPA2 over the years.
| Criterion | WPA2 | WPA3 |
|---|---|---|
| Year introduced | 2004 | 2018 |
| Authentication method | Four-way handshake (PSK) | SAE (Dragonfly handshake) |
| Offline dictionary attack resistance | Vulnerable | Resistant |
| Forward secrecy | No | Yes |
| Open network encryption | None | OWE (optional) |
| Device compatibility | Near-universal | Newer devices only |
| Encryption standard | AES-CCMP (128-bit) | AES-GCMP (128/256-bit) |
Key Security Differences That Matter to Consumers
The most consequential difference between WPA2 and WPA3 is how each handles the authentication process — specifically, what happens when someone tries to guess your Wi-Fi password.
WPA2 uses a four-way handshake during connection. Security researchers demonstrated in 2017 that this handshake data can be captured and subjected to offline dictionary attacks — where an attacker tests millions of password combinations against the captured data without ever reconnecting to your network. This vulnerability, known as KRACK (Key Reinstallation Attack), prompted patches from device manufacturers but exposed a structural limitation.
WPA3 replaces this handshake with a protocol called Simultaneous Authentication of Equals (SAE), often referred to as Dragonfly. SAE requires real-time interaction with the network to verify each password attempt, which effectively blocks offline brute-force attacks. Even if someone captures WPA3 handshake data, it cannot be cracked the same way WPA2 data can.
WPA3 also introduces forward secrecy: each session generates its own unique encryption key. This means that even if a past session's key were somehow compromised, it cannot be used to decrypt other sessions — past or future. WPA2 does not provide this guarantee.
2017
Year KRACK vulnerability was disclosed
Security researchers Mathy Vanhoef and Frank Piessens publicly disclosed the KRACK attack against WPA2's four-way handshake in October 2017.
192-bit
Encryption strength in WPA3-Enterprise
WPA3-Enterprise mode supports a 192-bit security suite, aligned with the Commercial National Security Algorithm (CNSA) Suite standards.
2006
Year WPA2 became mandatory for Wi-Fi certification
The Wi-Fi Alliance required all Wi-Fi CERTIFIED devices to support WPA2 starting in March 2006, establishing it as the baseline security standard.
For open public networks, WPA3 offers Opportunistic Wireless Encryption (OWE), which encrypts traffic even without a password. WPA2 open networks transmit data entirely unencrypted. To understand the real risks this creates, see our overview of what public Wi-Fi risks actually look like.
Compatibility, Transition Mode, and What to Do Now
WPA3 support depends on both the router and the connecting device. Routers sold from roughly 2019 onward increasingly support WPA3, but many smart home gadgets, older laptops, and budget smartphones do not. Forcing WPA3-only mode on a router can lock out these devices entirely.
The practical solution most modern routers offer is WPA2/WPA3 transition mode (sometimes labeled "WPA3 Personal Transition" or "Mixed mode"). In this configuration, WPA3-capable devices connect using WPA3 while older devices fall back to WPA2 — both use the same password and SSID. This is a reasonable middle ground for most households.
It's also worth noting that WPA2, when used with a strong and unique password, still provides solid protection for most home environments. The risks that WPA3 addresses are real but require a relatively sophisticated attacker in proximity to your network. Common threats — like weak passwords and phishing — remain password-dependent regardless of protocol version. Our guide on widespread Wi-Fi security misconceptions covers this distinction in depth.
WPA3 and Wi-Fi Speed Standards Are Separate
WPA3 is a security protocol, not a speed standard. It operates independently of Wi-Fi generations like Wi-Fi 5 (802.11ac) or Wi-Fi 6 (802.11ax). A router can support any combination — WPA2 with Wi-Fi 6, or WPA3 with Wi-Fi 5. When evaluating a router or device, check both the Wi-Fi generation and the supported security protocols separately.
If you're curious how WPA protocols relate to broader Wi-Fi standards like Wi-Fi 5 or Wi-Fi 6, the Wi-Fi Basics hub provides a useful reference point. Security protocols and speed standards operate independently — a Wi-Fi 6 router can run WPA2 or WPA3, and the choice of protocol does not affect throughput.
