Wi-fi routers can now id you through walls with 99% accuracy—no phone required

Your home router just became a biometric scanner. A team at Germany’s Karlsruhe Institute of Technology has turned everyday Wi-Fi packets into a passive, wall-piercing facial-recognition-grade system that spots individuals with 99 % precision—no cameras, no wearables, no consent.

Radio graffiti

The trick hides inside BFI (Beamforming Feedback Information), the housekeeping frames 802.11 routers fire hundreds of times per second to keep phones, TVs and toasters locked on the strongest path. Those frames travel unencrypted, ricochet off torsos and limbs, and return to the antenna carrying micro-signatures of gait, shoulder width, even the swing of an arm. Feed the reflections into a convolutional net pre-trained on 197 volunteers and the network spits out a match in under two seconds—angle, posture and clothing changes be damned.

Unlike LIDAR rigs or CSI-based schemes that demanded pricey silicon and channel-state dumps, this pipeline runs on firmware you could push to a $30 TP-Link. The researchers used a single off-the-shelf access point for both transmission and capture, proving the barrier to stalker-grade deployment is now a firmware update.

The air is the camera

The air is the camera

Switching off your phone is useless. Any active Wi-Fi device—someone else’s tablet, the smart fridge, the café’s POS—keeps the illumination going. A mall hallway, open-plan office, hospital ward: wherever packets fly, the medium itself sketches silhouettes in 2.4 and 5 GHz charcoal. CCTV cameras at least announce their presence with domes and red LEDs; this medium is invisible, omnipresent and already installed.

Felix Morsbach, co-author, calls it an infrastructure of suspicion: surveillance that never blinks and never asks for a warrant. The group’s field tests reached 99.02 % accuracy across a full week of volunteers entering, leaving, even crawling under desks. Once the model memorizes you, it can pick you out of a crowd of fifty faster than a bouncer checking IDs.

The standard that forgot privacy

The standard that forgot privacy

The root wound is protocol-level: BFI frames are mandated by 802.11ac/ax and travel in the clear to keep latency low. The upcoming 802.11bf amendment—slated for 2025—could seal that leak, but the draft text still treats encryption as optional. Professor Thorsten Strufe, cybersecurity chair at KIT, is lobbying for mandatory BFI encryption, hardware-level authentication, and a hard ban on using control frames for biometric fingerprinting. “The physics won’t un-invent itself,” he told me over Signal. “Either we retrofit the standard or we accept naked packets as permanent ID cards.”

Meanwhile, startups are already shopping cloud-side “presence analytics” to retailers, promising footfall heatmaps without beacons. Add this paper’s code—released as open source—and those same dashboards can tether every blip to a real-world identity. No GDPR checkbox required.

Close the window or live naked

Close the window or live naked

The team’s takeaway is blunt: the exploit vector is not a bug, it’s the spec. Patching it means re-engineering a protocol baked into four billion devices. The alternative is a radio-frequency panopticon where anonymity ends at the threshold of the nearest café Wi-Fi.

Strufe’s final slide at last week’s IEEE briefing showed a single line of shell code that dumps raw BFI into a pcap. Under it, a caption: “Privacy sold separately.” The audience—mostly engineers—laughed, then went quiet. The laugh was the last privacy we have left.