<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.3.8) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

]>


<rfc ipr="trust200902" docName="draft-relunsec-wifi-yubikey-00" category="info">
  <front>
    <title abbrev="WiFi Phishing Resistance">Phishing-Resistant Multi-Factor Authentication for Wi-Fi Networks</title>

    <author initials="" surname="RelunSec" fullname="RelunSec">
      <organization>Security Researcher part of InsiteTech.jp</organization>
      <address>
        <email>relunsec@insitetech.jp</email>
      </address>
    </author>

    <date year="2026" month="June" day="07"/>

    
    
    

    <abstract>


<?line 13?>
<t>This document proposes a phishing-resistant authentication mechanism for home Wi-Fi networks using hardware security keys (e.g., YubiKey) alongside traditional passwords to mitigate Evil Twin attacks.</t>



    </abstract>



  </front>

  <middle>


<?line 16?>

<section anchor="the-current-security-problem-with-wifi"><name>The Current security problem with WiFi</name>
<t>i'm RelunSec a security researcher, my mission is to improve WIFI security</t>

<t>We faced a lot of problems, because of those evil twin attacks against WIFI
home networks, those are used to obtain victims wifi passwords, that why i'm a security researcher, i'm here to propose that</t>

</section>
<section anchor="the-proposal"><name>The Proposal</name>
<t>the thing is WIFI will support phishing resistant methods like yubikey alongside passwords</t>

</section>
<section anchor="motivation"><name>Motivation</name>
<t>i wanted to propose that to improve WIFi network security, after that proposal
even attackers used evil twin and phished victim wifi passwords they need a yubikey to authenticate to the network.
a yubikey cannot be phished, like with websites yubikeys cannot be pished and phishing resistant methods</t>

</section>
<section anchor="backwards-compability"><name>Backwards compability</name>
<t>yubikey support is an available option, will be not mandatory
passwords will be the first method and then will prompt you to insert a yubikey, after inserting it the WIFI connection will successed else fails
if not enabled will be the current behavior.</t>

</section>
<section anchor="how-users-can-enable-it"><name>How users can enable it</name>
<t>1- Future routers will have yubikey support option, you go to the router interface and register the yubikey
2- Then you activate yubikey option
3- reboot the router
4- all devices will be disconnected, to connect enter your normal password and then insert your yubikey
5- Now you are connected safely to your wifi network, there a no worry anymore about evil twin attacks</t>

</section>
<section anchor="security-considerations"><name>Security Considerations</name>
<t>This document describes a security enhancement. The use of hardware-based 
multi-factor authentication (MFA) significantly reduces the risk of 
credential theft via Evil Twin attacks. By requiring a physical presence 
gesture (such as a YubiKey tap), even a compromised password is 
insufficient for an attacker to gain access to the network.</t>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>
<t>This document has no IANA actions.</t>

</section>


  </middle>

  <back>








  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA31VwW7cNhC98ysG6CE2sFps3fbQPcUJatQobASpgaBHShpJ
rCVSJald6O/7hhK1GyftxVhT5Mx7b97MFEWhook9H+lTZ0JnbFt85mBC1DbS
09RHUzzoKjpP91Ps2EZT6WicpQZHX/DR0DPHs/OvQemy9Hw64hinORzlcBWr
2lVWD8hVe93EwnM/2cBVcTaNKeapNK88F4eDQgpunZ+PZGzjlBn9kaKfQrw7
HH493CmlgcX5oyIqaIn4WWL9yRWOiJxvj4R/Jm/iLABY+6pjT6P2kVxDjzaY
yC9cdfu/x/SEB236I2VI7026EdcbqigK0mWIHlqoF1AjcJkG6EGjd6MLHEjT
mCX0m4T6a9UGBNTWhCHp17mBVxHtKiJNQUTrtK/P2jOFzALSBLrhfbvf0V+Q
6g+eb0n3zrbB1Ax5dG0khe7BMgQEqwNFRwNOW+hJv51MTy9nY0nHqKvXsF9o
Daaue1bqB3rpmD5O3gurLS/olT0PdDaxS5VV5t2wyQ3S202/6byjYUbcEISy
STDMgEAnsH18eNyeKPWFqdEV14jTu1SaNV/YUcmVngLLIaqNHywM4hUD0q1G
oWKKqpKaWcfd+kY0RJBaMLgy4jqdTBXNEEhcd9FKHuhI524mIfgfvOQTfrCE
Wwuf3mX5PqUz3StUHR+klOCfSJ9N31OYxtHBg9kpdHHKwECMmvXoAlqb4arA
G1BJ9eSiOSVHKUNnvF4IXiN6I/rmsI3XjtCD6Il0ecy4+cRZXvZhke5Kd1sv
0HG6yPhGRUQDasupopkEkFy1QdJO5FkB7dXlZqWthQ1Kzll2ixzJfGcupSdD
vh2ury+YNnzflVaU+wBiaCwgrdww6tL04sOcP5cHNdNge8JM0HAjuVG03i01
RDrJOiCZxmCc1YV9/i70GuNDTp2AiQLLDag9jJFmN6UqYeAg56ZCLsxyniwU
U8Rko8pZy1UaJqujqopDKlMfpJtMH5RpEkS2gr7+Cla1NnjJnT4Z5/eiyu/u
LKX2SdL1GbKqHwt6mOIEv3s3RfmeQuHlxaJZs6yRsGpdLvLyDlzwVzo9KeG5
RWWS97Y46q6QDrLpPaas+PuSZAmufirwtnQuXsVWP2M0A1QNm0KJjWxtwqqV
2Ahw1v9AT1IjjYdIfrgamJcyrTVJlzLAXwp6hk4JHxTZglPQDffJ5ul+6ojV
3DJVZFxopCIceLS0nQcnRyXgfzvTpBzb6vrorDS/T60e3iyemkPlTZk2zzas
2HayauXCPk2kdYLmhVKUWryihrTam2W1v1lSN08P97cUTGvBBIaIvQzBehJ1
k+4mvEpMVeFU3kFCnDcRM0F/Z8/QB3n/z2S8mFnW5BwQV/oAoxVoSbUcks1u
YOeOtFBalxxFPd7uaJlLqWnRPEY4bFWDKAoFmxqgNaKM7FZ9GWNSGVkUsJW0
yjfzB4o/3j/f/7/aHUChhumiTv2XF2iJJOpfMR8zZ0kJAAA=

-->

</rfc>

