WiFi Security: 4-Way Handshakes & PMKID Explained

Office WiFi is one of the most common — and most overlooked — ways small businesses get breached.

WiFi Security

WiFi Security: 4-Way Handshakes & PMKID Explained

Office WiFi is one of the most common — and most overlooked — ways small businesses get breached.

Most small business WiFi runs on WPA2-Personal with a single shared password used by staff, guests, and even point-of-sale devices. That convenience is exactly what makes it a target. Here’s how these attacks actually work, in plain language.

The 4-Way Handshake

When a device connects to a WPA2 or WPA3-Personal network, the access point and the device perform a “4-way handshake” — an exchange of four messages that proves both sides know the WiFi password and derives a unique encryption key for that session, without ever sending the password itself over the air.

The problem: an attacker within range can passively capture that handshake, or force it to happen on demand by sending a “deauthentication” frame that kicks a connected device off the network. The moment it reconnects, the attacker captures the handshake. From there, the password is cracked offline — away from your network, with no further contact with your router — by testing password guesses until one produces a matching handshake.

PMKID: An Easier Target

PMKID is a value some routers include in the very first message they send when a device begins to connect — originally added to speed up reconnections when roaming between access points. The catch is that an attacker doesn’t need to wait for a legitimate device to connect, and doesn’t need to send any deauthentication frames at all.

A single request to the access point can be enough to receive a frame containing the PMKID, which — like a captured handshake — can then be cracked offline. That makes PMKID-based attacks faster, quieter, and harder to notice than traditional handshake capture, because there’s no disruptive deauth traffic to spot.

The Common Thread: Password Strength

Both attacks end the same way — an offline guessing attack against your WiFi password. A short, common, or predictable passphrase (a business name, an address, “password123”) can fall in minutes on ordinary hardware. A long, random passphrase can make that guessing attack impractical, even with the handshake or PMKID in hand.

How We Help

WPA3-SAE

Move eligible networks to a standard designed to resist offline password-guessing attacks.

Strong Passphrases

Replace weak, shared passphrases with long, random, high-entropy ones.

Network Segmentation

Separate SSIDs/VLANs for staff, guests, and POS or IoT devices.

802.1X Authentication

Move staff WiFi to enterprise authentication with unique per-user credentials where feasible.

Disable WPS

Disable WPS and keep access point firmware current.

Rogue AP Monitoring

Monitor for rogue access points and unusual deauthentication activity.