Written independently, sold by nobody. ExtenderWorks makes no equipment, stocks none, and answers no calls. There is no box on this site that takes a network key or a card number. Every brand described here is somebody else’s; none of them commissioned, funded or reviewed a word of it. Issued by [OPERATOR NAME] of [TOWN], [COUNTRY].

The process · Article 12

What the WPS button does

The button marked WPS opens a short window during which two units exchange the network name and key without anyone typing either. It is a credential handover and nothing more. Its cousin, the PIN method, carried a design flaw serious enough that the whole mechanism is being withdrawn from the newest security standard.

  • Published by[OPERATOR NAME]
  • Last checked27 September 2026
  • Reading timeAbout 4 minutes
  • ScopeGeneric, not model-specific

The short answer

Wi-Fi Protected Setup is a standard from the Wi-Fi Alliance for joining a device to a network without entering the key. In its push-button form, a button on the router and a button on the extender are each pressed within a short period, the two find each other, and the router hands the extender the network name and key over an encrypted exchange. When the exchange completes, the extender holds exactly what a person would have typed, and behaves from then on as if they had.

What passes between the two units

Two parts take part. The registrar, normally the router, holds the network’s settings and has the authority to hand them out. The enrollee, here the extender, wants them. Once both have signalled willingness, the enrollee attaches to the registrar over a temporary link and the two run an exchange in which each proves to the other that it is the unit whose button was pressed, agree a temporary secret between themselves, and use that secret to encrypt the settings as they pass.

What passes is the network name, the security type and the key. The key is not sent in the clear at any point; it travels inside the exchange’s own encryption. At the end, the enrollee stores the settings in its own memory, drops the temporary link, and joins the network in the ordinary way. What an extender keeps in its own memory describes what happens to the stored copy afterwards.

The two-minute window

The standard sets a walk time of two minutes. When the router’s button is pressed, the router advertises for that period that it will accept an enrollee; when the extender’s button is pressed, the extender looks for a router advertising in that state. The two presses have to fall within the same window, which is why the manuals describe a limited time to get from one unit to the other.

The window is also the method’s weakness. During those two minutes the router will hand its settings to any enrollee that asks, not only the intended one. The standard reduces the risk by refusing to proceed if more than one enrollee presents itself, but the protection is physical: it rests on nobody else having a device in range and a reason to press a button at that moment.

The light that flashes while the window is open and settles once it closes is the pairing-window light described in the article on indicator lights.

The PIN method and its flaw

The same standard offers a second method in which an eight-digit number printed on the enrollee, or shown on a router’s screen, stands in for the button press. The number was meant to prove that the person joining had physical access to the unit.

In 2011 the method was shown to be far weaker than its eight digits suggested. The protocol checked the number in two halves and reported failure separately for each, so an attacker did not need to try all hundred million combinations, only about eleven thousand, and the last digit was a checksum that reduced the count further. On routers that left the method switched on and did not lock it after repeated failures, the network key could be recovered in hours. Many makers subsequently disabled the PIN method by default or removed it; some routers still carry it.

The push-button method does not share the flaw. It has no number to guess. Its exposure is the two-minute window and the physical reach of the signal during it, which is a much smaller thing. The two methods are often lumped together under the same name, and the reputation of one has attached itself to the other.

Why it is being withdrawn

The current security standard for home networks, WPA3, does not include Wi-Fi Protected Setup. Its replacement for the same job is a scheme in which a device is enrolled by scanning a code or by a trusted device vouching for it, without a guessable number and without an open window. Equipment that runs WPA3 exclusively therefore has no WPS button to press, and an extender joining such a network does so by the other routes described in how extender setup works.

Most routers in service still run WPA2, or a transitional mode that accepts both, and on those the button remains. It is a method in retirement rather than one that has gone.

What the button does not do

It does not improve the signal, extend the range, or change where the extender should stand. It does not need to be pressed again after the first pairing, because the extender keeps what it was given. It does not open the router to anyone outside the building, because the exchange runs over the local radio link and nowhere else. And it has no counterpart on the internet: no website, page or caller can perform the exchange on a household’s behalf, because the button is a physical object in the home and the window it opens closes on its own.

The registrar and enrollee roles, the push-button and PIN methods and the two-minute walk time are as specified by the Wi-Fi Alliance for Wi-Fi Protected Setup. The 2011 PIN weakness is a matter of public record, published by its discoverers and acknowledged by the US CERT Coordination Center. The absence of WPS from WPA3 and its replacement by Wi-Fi Easy Connect are as published by the Wi-Fi Alliance. Compared on 27 September 2026.