TL;DR
Wired Equivalent Privacy (WEP) was the first wireless security protocol introduced under the Institute of Electical and Electronics Engineers (IEEE) 802.11 standard in 1997, designed to encrypt Wi-Fi transmissions using a static 64-bit or 128-bit key. Despite its early adoption, WEP's reliance on a single shared static key made it critically vulnerable — a determined attacker can crack a WEP-protected network in under a minute. It was officially retired in 2004 and has since been replaced by the far more secure Wi-Fi Protected Access (WPA) and Wi-Fi Protected Access 2 (WPA2) protocols, which use dynamic keys and stronger encryption standards. WEP should not be used to protect any modern Wi-Fi network.
What is WEP?
WEP, or wired equivalent privacy, is a security algorithm presented by the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard as part of the IEEE 802.11 internet standard designed to keep traffic sent through wireless networks more secure that was ratified in 1997.
WEP was created to secure and ensure data confidentiality at the same level that a traditional wired network offered. Wireless connections transmit data through radio waves, which can be intercepted. WEP was designed to encrypt this data so that even if it were to be intercepted, such as through a man-in-the-middle (MitM) attack, the threat actor would not be able to decipher its contents.
WEP uses a static key of 10 or 26 hexadecimal digits to encrypt data. In the late 1990s and early 2000s, it was widely used and often the primary security choice router configuration tool offered to users.
Wired equivalent privacy has since been superseded by WPA and then WPA2, which was designed to address the security vulnerabilities that WEP presented. WPA uses a dynamic key and message integrity checks to ensure a higher level of cybersecurity.
WPA2 is an upgraded version of WPA. It is based on the robust security network (RSN) mechanism and can be even more secure than WPA.
WPE is a retired security protocol that has been deemed insecure. It has been replaced, first by first WPA and then by WPA2.
How were WEP key sizes determined?
Due to U.S. government-imposed restrictions on the exportation of cryptographic technology, WEP key sizes were initially limited to a 40-bit key (called WEP-40) for the 64-bit WEP protocol. As these restrictions were lifted, the extended 128-bit WEP protocol using the 104-bit key (WEP-104) was introduced. WEP uses the Rivest Cipher 4 (RC4) stream cipher for confidentiality and the Cyclic Redundancy Check (CRC-32) checksum for integrity.
What characters make up a WEP key?
The 64-bit WEP key uses a string of 10 hexadecimal (base 16) alphanumeric characters with each character representing 4 bits, while the 128-bit WEP key uses a string of 26 hexadecimal alphanumeric characters. These characters are either numbers between 0 and 9 or letters between A and F.
How does WEP's static key work?
Using WEP, all traffic is encrypted as a single key, meaning that it uses a static key. This key is used to connect computers to a wireless-security-enabled network. Computers connected to this network can exchange encrypted messages.
How does WEP compare to WPA and WPA2?
With WEP, all traffic (regardless of the device) is encrypted with the same static single key. As technology has advanced, bad actors have learned how to decrypt this single key; therefore, they have access to all of the confidential transmissions.
Similarly, anyone connected to the secure network would have access to the single key and therefore be able to read the transmissions regardless of if they were authorized or intended to do so. As a result, WEP was officially retired in 2004 after the Wi-Fi Alliance introduced WPA (Wi-Fi protected access) and then WPA2.
| Protocol | Year Introduced | Key Type | Key Size | Encryption Standard | Status |
|---|---|---|---|---|---|
| WEP | 1997 | Static | 64-bit or 128-bit | RC4 stream cipher / CRC-32 | Retired (2004) |
| WPA | 2003 | Dynamic (TKIP) | 256-bit | TKIP + message integrity checks | Superseded by WPA2 |
| WPA2 | 2004 | Dynamic | 256-bit (AES) | Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) / Advanced Encryption Standard (AES) | Current standard |
How does WPA improve on WEP?
WPA was introduced to replace WEP in 2003. Instead of authorizing all users with the same key, WPA instead uses the Temporal Key Integrity Protocol (TKIP) to dynamically alter the key. Threat actors were no longer able to match the static single key as they could with WEP since the key was now more dynamic and changing.
WPA was created as an interim solution, as an extension of WEP under the IEEE 802.11i standard. WPA also increased the key size to 256-bit and included message integrity checks to ensure that data packets had not been captured or altered by threat actors.
What further improvements does WPA2 offer?
WPA was also exploited and replaced by WPA2 in 2004. WPA2 operates on two modes. The personal mode or pre-shared key (WPA2-PSK) uses a shared passcode for access. It is typically used in home environments. The enterprise mode (WPA2-Extensible Authentication Protocol (EAP)) is designed for organizational or business use. WPA2 is based on the RSN mechanism.
Both modes of WPA2 use the counter mode cipher block chaining message authentication protocol (CCMP), which is based on the advanced encryption standard (AES) that offers verification for both message authenticity and integrity. AES replaces TKIP, and CCMP is a much stronger protocol that makes it more difficult for threat actors to guess the encryption pattern.
What are the benefits of WEP?
Wired equivalent privacy is meant to protect Wi-Fi transmissions by encrypting the data so outsiders who are not inside the encrypted network will not be able to read the messages or data contained within. WEP is better than no security at all, and it is still used on older devices that do not support WPA or WPA2.
What does WEP encryption actually protect?
WEP encrypts data to and from the access point with a static key. Anyone who is connected to the secured network has access to this key and therefore the decrypted transmission.
What are the main critiques of WEP?
Wired equivalent privacy is a retired Wi-Fi security algorithm that has been deemed unsafe and easy for threat actors to crack. For this reason, it is almost never recommended to use WEP to secure Wi-Fi networks or transmissions.
Because WEP is an out-of-date Wi-Fi encryption method, it has the following drawbacks:
- Threat actors are able to easily guess the static key and therefore gain access to the confidential messages. A threat actor can listen in to transmissions and collect data packets. With these details, they are able to decrypt the encryption key.
- A static key is used, which means that every connected device on the network has access to all of the confidential message contents. Once connected to the WEP-secured Wi-Fi network, the user is granted authorization through the static and single key.
- WEP only supports 64-bit or 128-bit encryption key sizes, which can be more easily decrypted than the larger 256-bit encryption key.
- WEP is limited to the use of hexadecimal characters, which only allow for numbers 0–9 and the letters A–F. The key length is therefore not very secure. Standard computers have the ability to hack these keys.
How quickly can a WEP network be compromised?
A WEP-protected network can be cracked in under a minute, especially if the network sees a lot of traffic. Threat actors are then able to intercept a large number of data packets. WEP has been demonstrated to be extremely insecure and should not be used to protect Wi-Fi networks.
Frequently asked questions
Why was Wired Equivalent Privacy (WEP) considered insecure?
WEP relied on a single static key shared across all devices on the network. Because the key never changed, threat actors could collect enough data packets to decrypt it — often in under a minute on a busy network. The limited key sizes (64-bit or 128-bit) and restriction to hexadecimal characters further reduced the complexity needed to crack it.
What replaced Wired Equivalent Privacy (WEP), and why is the replacement more secure?
WEP was replaced first by Wi-Fi Protected Access (WPA) in 2003 and then by WPA2 in 2004. WPA introduced the Temporal Key Integrity Protocol (TKIP), which dynamically changes the encryption key rather than using a single static one. WPA2 went further by adopting the Advanced Encryption Standard (AES) and the CCMP protocol, making it significantly harder for attackers to guess or replicate the encryption pattern.
Can Wired Equivalent Privacy (WEP) still be used on older devices?
While WEP is technically still functional on older hardware that does not support WPA or WPA2, it is strongly discouraged. WEP has been officially retired since 2004 and is widely regarded as providing negligible security. Any device limited to WEP should be considered a security risk on the network.
What is the difference between WPA2 personal mode and enterprise mode?
WPA2 operates in two modes. The personal mode (WPA2-PSK) uses a shared passcode and is typically suited for home environments. The enterprise mode (WPA2-EAP) is designed for organizational or business use and requires a more robust authentication infrastructure. Both modes use Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) based on Advanced Encryption Standard (AES) for encryption.
What type of encryption does Wired Equivalent Privacy (WEP) use?
WEP uses the Rivest Cipher 4 (RC4) stream cipher for data confidentiality and the Cyclic Redundancy Check (CRC-32) checksum for integrity verification. The encryption key is either 40-bit (for the 64-bit WEP protocol) or 104-bit (for the 128-bit WEP protocol), composed entirely of hexadecimal characters — numbers 0–9 and letters A–F.
Why were Wired Equivalent Privacy (WEP) key sizes initially so small?
Early WEP key sizes were constrained by U.S. government export restrictions on cryptographic technology, which limited keys to 40 bits. Once those restrictions were lifted, the extended 128-bit WEP protocol with a 104-bit key was introduced, though even this larger key size proved insufficient against modern attack methods.
References
WEP: The "Wired Equivalent Privacy" Algorithm. (November 1994). Institute of Electrical and Electronics Engineers (IEEE).
RC4 Encryption Algorithm Stream Ciphers Defined. (2022). Okta.
CRC32. (2022). The PHP Group.
Wi-Fi Alliance. (2022). Wi-Fi Alliance.
802.11i Overview. (February 2005). Institute of Electrical and Electronics Engineers (IEEE).