WiFi/WLAN security: for personal/PSK mode, choose WPA2 with AES and a strong password and SSID name. Don’t use TKIP or WPS PIN
Posted by jpluimers on 2012/07/20
To make WPA2 as secure as possible in PSK mode aka personal mode, make sure you don’t trap into the major WPA2 weaknesses:
- choosing weak passwords (anything less than about 15 characters is to easy to crack)
- choosing weak SSID names (as rainbow tables have been generated for popular SSID names)
- don’t use TKIP, but use AES as there is a WPA short packet spoofing based on TKIP that also affects WPA2
- don’t use WPS PIN, as there is a WPS PIN recovery also affecting WPA2
So this is what I did on my TomatoUSB flashed Asus RT N66U router:
- strong and different passwords for 2.4 Ghz and 5Ghz WiFi
- unique SSIDs for both the WiFi bands
- AES encryption
- no WPS PIN
Easy to setup: follow the WiKi here, using the basic link from the link list.
–jeroen
via:






Leave a comment