25.5 Securing Your Own Wi-Fi
He sagla shiklyacha khara upyog – swatahcha ani students cha Wi-Fi surakshit karne:
| Step | Why |
|---|---|
| Use WPA3, or WPA2-AES if WPA3 is unavailable | WEP/WPA and TKIP are broken |
| A long, random passphrase (16+ chars) | Defeats offline handshake cracking |
| Turn WPS off | The WPS PIN can be brute-forced |
| Change the router admin password and update firmware | Default admin logins are public knowledge |
| Use a guest network for visitors and IoT | Keeps your main devices separate |
| He SSID naming: avoid your name/flat number | Less targeting; hiding SSID is weak, not real security |
| Enable Protected Management Frames (802.11w) | Reduces deauth attacks |
| Check connected devices in the router now and then | Spot anything you do not recognise |
Why this matters for security
Your Wi-Fi is the front door to every device in your home or shop. A weak passphrase or an old protocol lets an attacker onto the same network as your phones, laptops and cameras. Strong Wi-Fi is one of the highest-value, lowest-effort protections there is.
Ravindra Bagale's Tip
WPS (to "push button to connect" wala) suvidhecha vatato, pan tyacha 8-digit PIN brute-force hoto – mhanun WPS band kara. Ani router cha firmware update kara – juna firmware madhe known bugs astat. He don goshti khup lok visartat.
Lab
On your own router: set WPA2/WPA3, a 16+ character passphrase, turn WPS off, change the admin password, update the firmware, and enable a guest network. Write a short before/after note of what you changed.