QUOTE(blacktubi @ Feb 27 2020, 08:14 PM)
WPA3 is it is not backwards compatible. Many devices you own now are not going to get WPA3 update. I am speaking of old Android phones, IoT devices and etc. Running WPA3+WPA2 mixed mode don't give you more security as well.
This new vulnerability is
really minor and it only affect Broadcom routers. Knowing ASUS, they will be patched soon.
Details:
https://nvd.nist.gov/vuln/detail/CVE-2019-15126TLDR: Minor vulnerability, attackers won't gain access to your network. Minor packet leakage when disassoctiation is triggered. Impractical to be weaponized for malicious use.
All the phones in my house are probably gonna be Android 10 later this year. I'm going to use forced WPA3 if the router is going to support it. No more old Android phones here, other devices are all cabled except a printer which I don't really need to connect to network.
EDIT: But even in transition mode, there's still some benefit for WPA3 devices according to wi-fi.org
QUOTE
In addition, even after this attack is successful and the attacker determines the password, the clients that connect with WPA3-Personal will still benefit from the forward-secrecy that SAE affords—that is, the traffic encryption keys will still remain unknown even if the password is known.
This post has been edited by AV_2018: Feb 27 2020, 09:58 PM