What is WPS technology in Wi-Fi networks and why is it recommended to disable it for security purposes?
WPS, or Wi-Fi Protected Setup, was developed to simplify the process of connecting new wireless devices to a secure home network. Instead of entering a complex, long password, the user only needs to press a physical button on the router and the connected gadget or enter a short eight-digit PIN code. This seemed like a great solution for integrating smart TVs, printers, and other devices without convenient keyboards into the network, but in practice, it led to serious vulnerabilities.
The main problem with WPS lies in the PIN authentication vulnerability. The verification algorithm does not check the PIN as a whole, but splits it into two independent parts. An attacker can use brute-force to determine the first half of the code and then the second, which reduces the number of possible combinations from one hundred million to just a few thousand. Such a brute-force attack can be carried out using special utilities in just a few hours, even with a relatively weak signal from a neighboring apartment.
As soon as an attacker guesses the PIN code via the WPS vulnerability, they gain full access to your network and can find out the main Wi-Fi password. This renders the use of reliable WPA2 or WPA3 encryption pointless, as the security hole is at the connection initiation protocol level. For this reason, network hardware manufacturers and cybersecurity experts strongly recommend completely disabling the WPS function in the settings of every new router.
If you need to connect a device without a screen to Wi-Fi, it is better to temporarily use a guest network with a simple password or set up a cable connection. After completing the setup, the guest network can be disabled. For everyday use of your main network, security should always come first, so abandoning outdated and insecure helpers is a mandatory step to protect personal data.