A city AP still has WPS enabled 'for easy onboarding' on a staff SSID. Why do authorized assessors typically flag that setting?
Select an answer to reveal the explanation.
Short Explanation
Easy onboarding is nice until WPS becomes the side door into the Wi-Fi password. PIN weaknesses are why assessors wave the red flag. Convenience on a staff SSID is still attack surface.
Full Explanation
Wi-Fi Protected Setup was meant to simplify consumer onboarding, but known PIN-space and implementation issues can lead to recovery of the WPA passphrase on vulnerable APs. Leaving WPS enabled therefore enlarges the offensive assessment surface beyond the PSK alone. WPS is not Bluetooth-only, not an automatic WPA3-Enterprise upgrade, and not a beacon publisher of the PSK.