Wi-Fi Security: Should You Use WPA2-AES, WPA2-TKIP, or Both? (2024)

Quick Links

  • WPA2 vs. WEP, WPA, and WPA3

  • AES vs. TKIP

  • Wi-Fi Security Modes Explained: Which Should You Use?

  • WPA and TKIP Will Slow Your Wi-Fi Down

  • When In Doubt, Always Choose WPA 2 (AES) or WPA3

Key Takeaways

For maximum security, you should use WPA2 (AES) if you have older devices on your network and WPA3 if you have a newer router and newer devices that support it.

Your Wi-Fi router offers encryption options like WPA2-PSK (TKIP), WPA2-PSK (AES), and WPA2-PSK (TKIP/AES) and even, if it's modern enough, WPA3 (AES). It can be a bit confusing, and if you choose the wrong one, you'll have a slower, less-secure network. Here's what you need to know.

WPA2 vs. WEP, WPA, and WPA3

When you read about Wi-Fi security, the primary focus is usually on the type of encryption used to secure the wireless connection. That makes sense, after all, because, by the very nature of a Wi-Fi router, all communications between your client device (like your smartphone or laptop) and the router are flung through the open air. Anybody in range of your router can snoop on that communication or even gain access to your router if the wireless connection is insecure.

This wireless connection is secured using security algorithms specifically designed for Wi-Fi. These algorithms aren't strictly just encryption (though that's a crucial component) but include additional functions that govern how keys are exchanged and verified, and more.

Wired Equivalent Privacy (WEP), Wi-Fi Protected Access (WPA), and Wi-Fi Protected Access II (WPA2) are the primary security algorithms you'll see when setting up a wireless network. If you have a newer router, you may also see Wi-Fi Protected Access III (WPA3), too.

WEP is the oldest and has proven to be vulnerable as more and more security flaws have been discovered. WPA improved security but is now also considered vulnerable to intrusion.

WPA2, while imperfect, is more secure than WEP or WPA and is one of the most widely used Wi-Fi security algorithms. WPA and WPA2 networks can use one of two encryption protocols, Temporal Key Integrity Protocol (TKIP) and Advanced Encryption Standard (AES). We'll look at the difference between those two encryption protocols in a moment.

Finally, WPA3 networks only use the AES encryption protocol. Although introduced in 2018, WPA3 still doesn't have widespread adoption.

AES vs. TKIP

TKIP and AES are two different types of encryption that can be used by a Wi-Fi network. TKIP is actually an older encryption protocol introduced with WPA to replace the very-insecure WEP encryption at the time. TKIP is actually quite similar to WEP encryption. TKIP isno longer considered secure and is now deprecated. In other words, you shouldn't be using it.

AES isa more secure encryption protocol introduced with WPA2. AESisn't some creaky standard developed specifically for Wi-Fi networks, either. It's a serious worldwide encryption standard that's even been adopted by the US government.

For example, when youencrypt a hard drive with TrueCrypt, it can use AES encryption for that. Window's built-in encryption tool BitLocker also uses AES, as does macOS's tool FileVault. AES is generally considered quite secure, and the main weaknesses would bebrute-force attacks(prevented by using a strong passphrase) andsecurity weaknesses in other aspects of WPA2.

The short version is thatTKIP is an older encryption standard used by the WPA standard. AES is a newer Wi-Fi encryption solution used by the new-and-secure WPA2 standard. In theory, that's the end of it. But, depending on your router, justchoosing WPA2may not be good enough.

While WPA2 is supposed to use AES for optimal security, it can alsouse TKIP, where backward compatibility with legacy devices is needed. In such a state, devices that support WPA2 will connect with WPA2, and devices that support WPA will connect with WPA. So "WPA2" doesn't always mean WPA2-AES. However, on devices without a visible "TKIP" or "AES" option, WPA2 is generally synonymous with WPA2-AES.

Wi-Fi Security Modes Explained: Which Should You Use?

Wi-Fi Security: Should You Use WPA2-AES, WPA2-TKIP, or Both? (1)

Confused yet? Don't feel bad if you are. The world of Wi-Fi security is pretty arcane if you're not a diehard network geek. Thankfully you don't need to understand the intricacies of how security protocols and handshakes changed between all the generations of Wi-Fi.

You just need to review our list below and select the most secure option that works with all of your hardware and devices. To help you avoid older and insecure options, we've flagged them with [Deprecated] after their name.

And, to be clear, we're not arbitrarily gatekeeping these protocols and declaring them deprecated based on our opinions. Both Microsoft and Apple have designated them as such, too, which is why your Windows laptop warns you when a Wi-Fi network isn't secure, and your iPhone warns you when Wi-Fi networks have weak security.

Additionally, we have not listed "Enterprise" options in the list below because Enterprise, or RADIUS-server based Wi-Fi security, is uncommon in residential settings and requires additional infrastructure.

Further, please note that depending on your router, the non-Enterprise options may be designated as either "Personal" or "PSK"---PSK stands for "Pre-Shared Key" and indicates that, unlike an Enterprise setup, the security doesn't rely on an authentication server but instead on the user having the pre-shared key (the Wi-Fi password) to input as their method of authentication. Starting with WPA2, and especially with WPA3, it's more common to see "Personal" instead of "PSK."

With those notes in mind, here are theoptions you're likely to see on your router.

  • Open [Deprecated]: Open Wi-Fi networks have no passphrase. You shouldn't set up an open Wi-Fi network---seriously,you could have your door busted down by police.
  • WEP 64 [Deprecated]: The old WEP protocol standard is vulnerable, and you shouldn't use it.
  • WEP 128 [Deprecated]: This is WEP, but with a larger encryption key size. It isn't really any less vulnerable than WEP 64.
  • WPA-PSK (TKIP) [Deprecated]: This uses the original version of the WPA protocol(essentially WPA1). It has been superseded by WPA2 and isn't secure.
  • WPA-PSK (AES) [Deprecated]: This uses the original WPA protocol but replaces TKIP with the more modern AES encryption. It's offered as a stopgap, but devices that support AES will almost always support WPA2, while devices that require WPA will almost never support AES encryption. So, this option makes little sense.
  • WPA2-PSK (TKIP) [Deprecated]: This uses the modern WPA2 standard with older TKIP encryption.This isn't secure, and is only a good idea if you have older devices thatcan't connect to a WPA2-PSK (AES) network.
  • WPA2-PSK (AES): This is the most secure option (outside of the newer WPA3.) It uses WPA2, the latest Wi-Fi encryption standard, and the latest AES encryption protocol.You should use this option unless your router supports WPA3---then use that instead.On some devices, you'll just see the option "WPA2" or "WPA2-PSK." If you do, it will probably justuse AES, as that's a common-sense choice.
  • WPA/WPA2-PSK (TKIP/AES): Some devices offer---and even recommend---this mixed-modeoption. This option enables both WPA and WPA2, with bothTKIP and AES. This provides maximum compatibility with any ancient devices you might have, but it also allows an attacker to breach your network by cracking the more vulnerable WPA and TKIP protocols.
  • WPA2/WPA3 Personal(AES): Like the WPA/WPA2 hybrid, this mode is designed for backward compatibility. Your WPA2-only devices will connect using WPA2 (AES) and your WPA3 devices will use the more advanced protocol. It may also be labeled as "WPA3 Transitional" or a variation thereof.
  • WPA3 Personal (AES): Older routers don't have WPA3, and older devices can't use WPA3. But if you have a new router that supports WPA3 and all newer devices, there's no reason not to switch over entirely to WPA3.

WPA2 certification became available in 2004. In 2006, WPA2 certification became mandatory. Any device manufactured after 2006 with a "Wi-Fi" logo must support WPA2 encryption. WPA3 certification became available in 2018, and any device certified after July 1, 2020, must support WPA3. (Do note the use of certified and not manufactured, a company can still manufacture and sell an older design that was certified before the adoption of a new standard.)

Given that it's quite likely every Wi-Fi device on your network (including the router itself) was certified and manufactured after 2006, there is no reason you shouldn't use any security protocol below WPA2-PSK (AES). You should be able to select that option in your router and experience zero issues.

If you have a newer router that supports WPA3, we recommend trying WPA3 (AES) to jump to the highest level of security. If you run into any issues, switch to WPA2/WPA3 Hybrid (AES). This way, the newest devices will use the best security, and the older devices will fall back to WPA2---either way, they'll be using AES, which is ideal.

If you don't have a newer router, it's probably time to recycle it and upgrade to a current Wi-Fi router with up-to-date standards and all the Wi-Fi improvements that come with it. You don't need to buy a cutting-edge Wi-Fi 7 model, but it's a great time to jump to Wi-Fi 6 or Wi-Fi 6E if you haven't already.

WPA and TKIP Will Slow Your Wi-Fi Down

Maybe you've been reading along so far and thinking, "I don't really care that much about security." While we'd encourage you to be more concerned about Wi-Fi network security, we understand that's not a pressing priority for everyone.

So here's a compelling reason to use better Wi-Fi security algorithms everyone can get behind. WPA and TKIP compatability options aren't just bad from a security standpoint. They can slow down your Wi-Fi network, too.

When you run WPA/TKIP on a router that supports 802.11n and newer, fasterstandards, it will slow down to 802.11g speeds (54 Mbps) to ensure backward compatibility with older clients. That's agonizingly slow.

By comparison, even 802.11n (Wi-Fi 4) supports up to 300 Mbps if you're using WPA2 with AES. Most folks have newer routers now, though. If you have an 802.11ac (Wi-Fi 5), or 802.11ax (Wi-Fi 6) router and you're using WPA/TKIP, you're leaving a huge amount of performance on the table.

In Wi-Fi generations, 802.11g is essentially "Wi-Fi 2" and came out in 2003. There's just no good reason to use a Wi-Fi security standard that insecure, out of date, and slow.

When In Doubt, Always Choose WPA 2 (AES) or WPA3

We've said it multiple times so far, but one last time for emphasis. If you're not sure what setting to pick on your router, always pick the most secure, and for any route made after 2010 or so, that's WPA 2 (AES) or WPA 3.

On most routers we've seen certified prior to 2018, the options aregenerally WEP, WPA (TKIP), and WPA2 (AES)---with perhaps a WPA (TKIP) + WPA2 (AES) compatibility mode thrown in for good measure. If this is what you're router offers you, set your router to WPA2 (AES).

On routers certified after 2018 (especially after the July 1, 2020 deadline), you'll find WPA3 and WPA2/WPA3 compatibility modes. We strongly recommend trying pure WPA3 mode. If everything works, great! You're rocking the best Wi-Fi security setup you can. If you find there are a few older mission-critical items in your home (like a Wi-Fi thermostat) that won't play nice with WPS then fall back to WPA2/WPA3 compatibility mode.

But whatever you do, it's time to shelve all the lesser Wi-Fi security protocols like WEP, WPA, and WPA2 (TKIP) for good.

Wi-Fi Security: Should You Use WPA2-AES, WPA2-TKIP, or Both? (2024)

FAQs

Wi-Fi Security: Should You Use WPA2-AES, WPA2-TKIP, or Both? ›

TKIP is no longer considered secure and is now deprecated. In other words, you shouldn't be using it. AES is a more secure encryption protocol introduced with WPA2. AES isn't some creaky standard developed specifically for Wi-Fi networks, either.

Should I use TKIP or AES or both? ›

TKIP is a lower end encryption protocol (WEP2) and AES is a higher end (WPA2/802.11i) encryption protocol. AES is preferred. This is what the encryption standards are for WEP2 (TKIP) and WPA2/802.11i (AES). It will attempt to use AES if available and fall back to TKIP if not.

Should I use WPA AES or WPA2 AES? ›

WPA2 ensures that data sent or received over your wireless network is encrypted, and only people with your network password have access to it. A benefit of the WPA2 system was that it introduced the Advanced Encryption System (AES) to replace the more vulnerable TKIP system used in the original WPA protocol.

Which Wi-Fi security option is best? ›

The best Wi-Fi security option for your router is WPA2-AES. You might see WPA2-TKIP as an option, but it's not as secure. WPA2-TKIP is, however, the second-most secure — followed by WPA, and then WEP.

How do I know if my Wi-Fi is AES or TKIP? ›

To check the encryption type:
  1. Open the Settings app on your mobile device.
  2. Access the Wi-Fi connection settings.
  3. Find your wireless network on the list of available networks.
  4. Tap the network name or info button to pull up the network configuration.
  5. Check the network configuration for the security type.
Feb 22, 2023

Which Wi-Fi authentication method should I use? ›

When choosing from among WEP, WPA, WPA2 and WPA3 wireless security protocols, experts agree WPA3 is best for Wi-Fi security. As the most up-to-date wireless encryption protocol, WPA3 is the most secure choice. Some wireless APs do not support WPA3, however.

Which AES mode should I use? ›

You can use CBC mode or CTR mode. However, these modes are not providing any authentication. You should use authenticated encryption mode as AES-GCM.

Should I use both WPA and WPA2? ›

WPA2 is backwards compatible with WPA, which functions with older software versions. WPA and WPA2 can enhance router security when used together.

Is AES Secure enough? ›

Is AES-256 Encryption Crackable? AES-256 encryption is virtually uncrackable using any brute-force method. It would take millions of years to break it using the current computing technology and capabilities. However, no encryption standard or system is completely secure.

Should I use AES? ›

The National Institute of Standards and Technology (NIST) recommends using AES to meet Health Insurance Portability and Accountability Act (HIPAA) regulations. Banks and other financial institutions rely on AES encryption to protect their customers' personal and transactional information.

Which Wi-Fi standard is the most secure? ›

WI-FI PROTECTED ACCESS 3 (WPA3)

Wi-Fi Protected Access 3 (WPA3) is the latest and most secure WiFi security protocol.

Which of the following is the best form of Wi-Fi security to use today? ›

Wi-Fi security protocols

The prevalent Wi-Fi security methods include WEP, WPA, WPA2, and WPA3 protocols. However, WEP and WPA are older, outdated models with significant security weaknesses. WPA2 and WPA3 are the most up-to-date and secure.

Does hiding your SSID keep hackers from connecting to your network? ›

The primary benefit of hiding your SSID is that it reduces the likelihood of an attack by keeping hackers and nosy neighbors from even knowing your network is there. It makes your network less of a “low hanging fruit” by making it more difficult to find.

Is TKIP or AES the best Wi-Fi security? ›

TKIP also turned out to be insecure, so a new standard called WPA2 was created, which uses AES, or Advanced Encryption Standard. AES is much more secure because it uses longer encryption keys and has been on almost all new Wi-Fi routers sold in the last few years.

How do I change my router from WPA2 to AES or WPA3? ›

7 Steps to Configure Your Router for WPA2
  1. Log Into Your Router Console.
  2. Navigate to the Router Security Panel.
  3. Select Encryption Option.
  4. Set Your Network Password.
  5. Save Changes.
  6. Reboot.
  7. Log In.
Mar 3, 2023

Is WPA2 no longer secure? ›

Most Wi-Fi devices use WPA2 as it is widely adopted. It offers Advanced Encryption Standard (AES) to protect your data and privacy. However, it is still vulnerable, and hackers can get access to the network and attack connected devices.

Is TKIP obsolete? ›

TKIP was resolved to be deprecated by the IEEE in January 2009.

Should I use WPA2 or WPA3 or both? ›

Set to WPA3 Personal for better security, or set to WPA2/WPA3 Transitional for compatibility with older devices. The security setting defines the type of authentication and encryption used by your router, and the level of privacy protection for data transmitted over its network.

What are the disadvantages of TKIP? ›

Weak Security WPA/WPA2 (TKIP) is not considered secure. If this is your Wi-Fi network, configure the router to use WPA2 (AES) or WPA3 security type.

Is TKIP slower than AES? ›

That's because of the conception that a Wi-Fi connection is faster when it uses TKIP instead of AES, or that AES has other connectivity issues. The reality is that WPA2-AES is the stronger and usually faster Wi-Fi connection.

Top Articles
8 Ways to Clean Up Social Media in Your Job Search
A Beginner's Guide to Helium (HNT)
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Duane Harber

Last Updated:

Views: 6174

Rating: 4 / 5 (51 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Duane Harber

Birthday: 1999-10-17

Address: Apt. 404 9899 Magnolia Roads, Port Royceville, ID 78186

Phone: +186911129794335

Job: Human Hospitality Planner

Hobby: Listening to music, Orienteering, Knapping, Dance, Mountain biking, Fishing, Pottery

Introduction: My name is Duane Harber, I am a modern, clever, handsome, fair, agreeable, inexpensive, beautiful person who loves writing and wants to share my knowledge and understanding with you.