Better alternative to WPS, which is insecure, a strong random password thats less than 63 chars

This article has a procedure for using /dev/urandom to generate a small file of random bits. https://security.stackexchange.com/questions/15653/recommend-length-for-wi-fi-psk

It doesnt have to be 63 characters long, it can be shorter, as long as its random and is at least a minimum size, which is discussed.


This is a 2012 article about WPS’s security problems.
https://dankaminsky.com/2012/01/26/wps2/

Not really relevant, all the insecure stuff is not implemented in RouterOS. We don’t have WPS PIN. Only button.

But the button how is work?
I want to test, I put a WPA password on a wireless card.
The WPS option is set tu push-button.
I press the WPS button on the hAP ac2, but I can’t connect to the wireless my phone ask for the password.
But the WPS procedure is for connecting without WPA password, for ex, i forget or i whant to hack :slight_smile:

On the wiki page isn’t explaned:
https://wiki.mikrotik.com/wiki/Manual:Interface/Wireless#WPS

But I found something better:
https://wiki.mikrotik.com/wiki/Manual:Quickset
WPS accept: Use this button to grant access to a specific device that supports the WPS connection mode. Useful for printers and other peripherals where typing a password is difficult. First start WPS mode in your client device, then once click the WPS button here to allow said device. Button works for a few seconds and operates on a per-client basis.