On the router's security settings page there is a list of options that reads like a code: WPA2-PSK, WPA3-SAE, WPA2/WPA3-Personal, and sometimes an older WPA entry.

Most people pick whatever is preselected and move on. That is not wrong, but there is one real difference among those options that is worth understanding before deciding.

The weakness that got fixed

To see what changed, a short explanation of how devices connect is needed.

When a device joins a Wi-Fi network, it and the router exchange a few messages to prove they both know the password. With WPA2, that exchange can be recorded by anyone within range.

The recording itself contains no password. The problem is that it can be taken away and used to test millions of guesses, with no need to be near your network again, and with your router never knowing it happened.

A short password, or one made of common words, falls within minutes that way.

This is what WPA3 changes. The way connecting works was redesigned so the recording is no longer useful for guessing offline. Every guess has to be tried against the router, one at a time, and that makes bulk guessing impractical, even for a password that is not especially strong.

A short comparison

WPA2WPA3
Offline password guessingPossibleImpractical
Old recordings readable
if the password leaks
YesNo
Open networks without a passwordNo protectionStill encrypted
Device supportAlmost everythingGenerally 2019 onwards

The second row gets overlooked but matters. With WPA2, someone recording traffic today who only obtains the password a year later can still open that old recording. WPA3 closes that possibility.

The third row applies to open Wi-Fi in public places. Under WPA3, traffic stays encrypted even without a password, a meaningful improvement, though it does not remove all the risks covered in the guide to using public Wi-Fi safely.

Which to choose

If all your devices are reasonably new

Choose WPA3 on its own. Phones, laptops, and tablets from 2019 onwards generally support it.

If you have older devices, especially smart devices

Choose WPA2/WPA3 mixed mode. New devices use WPA3, older ones stay on WPA2. For most homes, this is the right answer.

If your router does not offer WPA3

Stay on WPA2 and make sure the password is long. That is adequate, do not replace a router purely over this.

What not to choose

Any option labelled WPA on its own, or WEP if it is still listed. Both were broken long ago, and choosing them leaves your network effectively open.

On mixed mode

Mixed mode is sometimes dismissed as half-hearted. It is not, it does not weaken the devices using WPA3.

What matters is understanding its limit: WPA3's protection applies only to the devices actually using it. An older smart device connected over WPA2 carries exactly the same weakness it had before.

For that reason, as long as older devices remain on the network, password strength still decides the outcome. Moving to WPA3 is not a reason to keep a short password, how to choose one is in the guide to changing your Wi-Fi password.

When devices stop connecting

This is the most common complaint after switching to WPA3, and the symptoms are confusing because there is often no clear message.

  • The network does not appear at all on certain devices, usually ones that do not recognise WPA3.
  • Connection fails repeatedly even though the password is correct.
  • Smart devices stop responding after the router is reconfigured. Cameras, smart plugs, and sensors are affected most, guide to smart device security.

The fix is to switch to mixed mode. If problems persist, some older devices also cannot handle one network name spanning two bands, the considerations are in the guide to setting up a new router.

What WPA3 does not solve

This part matters so that expectations sit in the right place. WPA3 improves how devices prove they know the password. It does not touch any of the following:

RiskSolved by WPA3?
The Wi-Fi password being shared aroundNo
The router admin page still on its factory passwordNo
Outdated router firmwareNo
Smart devices that are never updatedNo
Password guessing from a recordingYes

The first four rows account for far more real-world trouble than the last one. A more useful order of work is in the guide to securing a home router, and the signs of a network already compromised are in the guide to spotting a compromised Wi-Fi network.

On sensitive activity

One point worth correcting: whether it is safe to open a banking app is not decided by WPA2 or WPA3.

Traffic to an app like that is already encrypted in its own right, regardless of the Wi-Fi security in use. What actually decides the matter is covered in the guide to mobile banking security on Wi-Fi.

In short: if your router supports WPA3, use mixed mode. If it does not, WPA2 with a long password is perfectly adequate, and replacing a router purely for this is not urgent spending.

Frequently asked questions

What does WPA3 actually fix compared with WPA2?

The main weakness: with WPA2, someone can record the connection process and then guess the password repeatedly without being anywhere near your network. WPA3 changes how connecting works, so every guess has to be tried against the network itself, which makes bulk guessing impractical.

Is WPA2 no longer safe to use?

It still is, as long as the password is long and not easy to guess. WPA2 with a twelve-character random password remains perfectly adequate for a home. What makes it fragile is not the protocol but a short, guessable password.

Why do older devices stop connecting after switching to WPA3?

Because devices made before roughly 2019 generally do not recognise WPA3 at all. Some give no clear error, the network simply does not appear, or connection fails repeatedly.

Is WPA2/WPA3 mixed mode safe?

Yes, and for most homes it is the sensible choice. New devices use WPA3, older ones stay on WPA2. The catch is that WPA3's protection only applies to devices actually using it, so password strength still matters.