Normally people think of WiFi authentication as the client proving to the AP that it knows the pre-shared key. But does the AP also prove to the client that it knows the pre-shared key?
Is it fundamentally impossible for a connection to be negotiated in WPA2-PSK if either of the parties doesn't know the pre-shared key, or is it up to each party to decide whether to connect regardless?
(I'm just wondering about the possibility of Wi-Fi-based Smart Unlock in Android, which is claimed by many people to be insecure because it's spoofable - but I was under the impression that it's impossible to spoof an authenticated connection unless you have the PSK)