RF Privacy — Counter-Sensing Audit
5 emitters tracked · 2 above the sensing-risk floor · posture 55/100
Counter-Sensing Layerscapability vs feasibility
Layers 1 and 5 ship on an ESP32 mesh today. Layer 3 reuses Wavey's baseline expertise. Detecting a well-shielded passive receiver remains an open research problem — the console reports confidence, never omniscience.
Attack Literaturewhat is already published
Passive occupancy detection at 20 m through walls from plaintext beamforming feedback.
Identity inference across 197 subjects at ~99.5% accuracy on commodity hardware.
Keystroke and PIN recovery from CSI perturbation during touchscreen input.
Coarse pose and gait reconstruction from ambient subcarrier amplitude.
WIDS / WIPS Gaplink layer vs people
- Rogue APs and evil twins
- Deauthentication / disassociation floods
- Rogue clients and MAC spoofing
- Channel interference and spectrum abuse
- WPA handshake capture
- Passive CSI harvesting of occupants
- BFI-based identity inference
- Occupancy leakage outside the perimeter
Enterprise WIDS answers "is someone attacking our WiFi?" — not "is someone using our ambient RF to observe people in this room?".
Threat Model
Rogue AP, ESP32 transmitter or SDR emitter. Transmits, so it can be located.
Piggybacks legitimate infrastructure — harvests BFI or ambient CSI without its own transmitter.
Monitor-mode receiver, never transmits. A well-shielded receiver may emit nothing at room scale.
