By tsat03 - edited: March 2

    Hi Experts,

    While revisiting some security aspects in FT, I had an epiphany and stumbled upon a basic question:-

    During M2 exchange from Client/Supplicant to the AP/Authenticator - since the S-Nounce is sent separately (than the WPA key data) - why doesn't the Client encrypt the WPA key data (using the PTK) - just like how the M3 gets encrypted by the AP?



