EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium
A wireless network administrator is deploying a new WPA3-enabled network. They are considering the security implications of client compatibility. Which of the following WPA3 features provides protection against passive offline dictionary attacks, even if an attacker captures the initial handshake, and is a mandatory component for WPA3-Personal networks?
- AOpportunistic Wireless Encryption (OWE)
- BEnhanced Open security
- CSimultaneous Authentication of Equals (SAE)
- D192-bit cryptographic strength
Show answer & explanationAnswer & explanation
Correct answer: C. Simultaneous Authentication of Equals (SAE)
Simultaneous Authentication of Equals (SAE), also known as Dragonfly Key Exchange, is a mandatory component of WPA3-Personal. It provides a secure key establishment protocol that makes passive offline dictionary attacks ineffective by ensuring forward secrecy and resistance to side-channel attacks.
Why the other options are wrong
- A. OWE is for Enhanced Open networks, providing encryption without authentication, not for WPA3-Personal's authentication and key exchange.
- B. Enhanced Open is a separate security mode (OWE) that provides unauthenticated encryption, not the primary protection for WPA3-Personal's key exchange.
- D. 192-bit cryptographic strength is a feature of WPA3-Enterprise, not the specific mechanism protecting WPA3-Personal against offline dictionary attacks.
WPA3-Personal SAE
Simultaneous Authentication of Equals (SAE) is the key exchange protocol used in WPA3-Personal, replacing the WPA2 4-way handshake, to provide stronger security against offline dictionary attacks.
- Mandatory for WPA3-Personal networks.
- Provides forward secrecy and resistance to side-channel attacks.
- Makes passive offline dictionary attacks significantly harder or impossible.
Memory trick: SAE secures the WPA3 handshake, no more easy dictionary guesses.