Internet-Draft WiFi Phishing Resistance June 2026
RelunSec Expires 9 December 2026 [Page]
Workgroup:
Network Working Group
Internet-Draft:
draft-relunsec-wifi-yubikey-00
Published:
Intended Status:
Informational
Expires:
Author:
RelunSec
Security Researcher part of InsiteTech.jp

Phishing-Resistant Multi-Factor Authentication for Wi-Fi Networks

Abstract

This document proposes a phishing-resistant authentication mechanism for home Wi-Fi networks using hardware security keys (e.g., YubiKey) alongside traditional passwords to mitigate Evil Twin attacks.

Status of This Memo

This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.

Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.

Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."

This Internet-Draft will expire on 9 December 2026.

Table of Contents

1. The Current security problem with WiFi

i'm RelunSec a security researcher, my mission is to improve WIFI security

We faced a lot of problems, because of those evil twin attacks against WIFI home networks, those are used to obtain victims wifi passwords, that why i'm a security researcher, i'm here to propose that

2. The Proposal

the thing is WIFI will support phishing resistant methods like yubikey alongside passwords

3. Motivation

i wanted to propose that to improve WIFi network security, after that proposal even attackers used evil twin and phished victim wifi passwords they need a yubikey to authenticate to the network. a yubikey cannot be phished, like with websites yubikeys cannot be pished and phishing resistant methods

4. Backwards compability

yubikey support is an available option, will be not mandatory passwords will be the first method and then will prompt you to insert a yubikey, after inserting it the WIFI connection will successed else fails if not enabled will be the current behavior.

5. How users can enable it

1- Future routers will have yubikey support option, you go to the router interface and register the yubikey 2- Then you activate yubikey option 3- reboot the router 4- all devices will be disconnected, to connect enter your normal password and then insert your yubikey 5- Now you are connected safely to your wifi network, there a no worry anymore about evil twin attacks

6. Security Considerations

This document describes a security enhancement. The use of hardware-based multi-factor authentication (MFA) significantly reduces the risk of credential theft via Evil Twin attacks. By requiring a physical presence gesture (such as a YubiKey tap), even a compromised password is insufficient for an attacker to gain access to the network.

7. IANA Considerations

This document has no IANA actions.

Author's Address

RelunSec
Security Researcher part of InsiteTech.jp