SSID
About 4 min read
Last updated: 2026-09-02
What Is SSID
SSID (Service Set Identifier) is the name that identifies a Wi-Fi network. When you open the Wi-Fi settings on your phone or computer, the network names you see are SSIDs.
An SSID is a string of up to 32 bytes, periodically broadcast by the access point (router) in beacon frames. Devices receive these beacons and display available networks.
A single router can host multiple SSIDs. Home routers are often configured with a separate SSID per frequency band, while enterprise environments separate guest and corporate SSIDs for network segmentation.
Stealth SSID - Effectiveness and Limitations
Stealth SSID (disabling SSID broadcast) means the router leaves the SSID out of its beacon frames, so the network name does not appear in device Wi-Fi lists. While it seems like a security improvement, its actual effectiveness is limited.
- Readable from the frames of connecting devices: A device that has saved a hidden SSID checks whether it is present using a directed probe request that names that SSID. The association request a device sends when it connects also contains the SSID of the target network. Both can be read simply by receiving the radio signal, so the SSID becomes known as soon as even one device connects.
- Network analysis tools detect it: Tools like Wireshark and Kismet easily reveal networks with a hidden SSID. Hiding only makes the network harder to see, not invisible.
- Reduced usability: New devices must have the SSID entered manually, adding operational friction.
Hiding the SSID only omits the network name from beacons; it plays no part in encryption or access control. What actually protects the contents of your traffic is the encryption method (WPA3, or at least WPA2) and a long passphrase that is hard to guess.
Evil Twin Attacks
An Evil Twin attack involves setting up a rogue access point with the same SSID as a legitimate network to trick users into connecting. A typical attack proceeds as follows.
- The attacker sets up an access point with the same SSID as a public Wi-Fi network in a cafe or airport (e.g.,
Free_WiFi). Because a device tries to connect automatically when it finds an SSID matching a saved network, a rogue access point with a stronger signal can be the one it picks. On a network encrypted with a passphrase, an attacker who does not know the passphrase cannot complete the connection, but that constraint does not apply to Wi-Fi whose password is posted in the shop, or to networks with no encryption at all. - All traffic from connected users passes through the attacker, who can steal passwords and credit card details from unencrypted HTTP traffic.
- Some attacks display a fake captive portal (login screen) prompting users to enter an email address and password.
Useful habits against Evil Twin attacks include using a VPN on public Wi-Fi, visiting only HTTPS sites, and disabling auto-connect so that you confirm the network each time. With the 802.1X authentication (WPA-Enterprise) used in enterprise environments, authentication with a rogue access point that lacks a legitimate certificate does not succeed, provided the device is configured to validate the authentication server's certificate. Conversely, a device with certificate validation turned off hands its credentials to a fake authentication server, so that certificate validation setting is a prerequisite.
Safe SSID Naming Practices
- Avoid personal information: Names like
Tanaka_HomeorRoom301reveal the owner or location to potential attackers. - Change default SSIDs: Factory defaults like
NETGEAR-5G-1234reveal the router manufacturer and model, enabling targeted attacks against known vulnerabilities. In addition, WPA2 personal mode uses the SSID as a salt in the calculation that derives the key from the passphrase, so an SSID left at its factory value, or a very common SSID, makes analysis with precomputed key tables easier to carry out. Always change it. - Skip provocative names:
HackMeIfYouCanonly attracts unwanted attention with no benefit. - Distinguish bands: Making the band explicit, as in
MyNetwork_2GandMyNetwork_5G, makes it easier to choose which one to join. Routers with band steering switch the connection automatically, so a single unified SSID also works.
More important than SSID naming is enabling WPA3 (or at minimum WPA2) encryption with a long password that is hard to guess. MAC address filtering is not a boundary for access, because a MAC address can be rewritten on the device side and can be read as the destination of a frame even when the traffic is encrypted. Keep it to organizing devices operationally, and do not treat it as a substitute for encryption or a passphrase.
Common Misconceptions
- Hiding the SSID makes Wi-Fi secure
- A stealth SSID is a setting that merely omits the network name from beacons. A device that has saved the network sends a directed probe request naming the SSID, and the association request it sends when connecting also contains the SSID, so the name becomes known simply by receiving the radio signal. What protects traffic is the encryption method and the strength of the passphrase; hiding the SSID is not a meaningful defense.
- Networks with the same SSID are the same network
- SSID is just a name - multiple access points can share the same SSID. Evil Twin attacks exploit this. A matching SSID does not guarantee you are connected to the legitimate access point.