arXiv · 2506.13052
Buy it Now, Track Me Later: Attacking User Privacy via Wi-Fi AP Online Auctions
Abstract
Static and hard-coded layer-two network identifiers are well known to present security vulnerabilities and endanger user privacy. In this work, we introduce a new privacy attack against Wi-Fi access points listed on secondhand marketplaces. Specifically, we demonstrate the ability to remotely gather a large quantity of layer-two Wi-Fi identifiers by programmatically querying the eBay marketplace and applying state-of-the-art computer vision techniques to extract IEEE 802.11 BSSIDs from the seller's posted images of the hardware. By leveraging data from a global Wi-Fi Positioning System (WPS) that geolocates BSSIDs, we obtain the physical locations of these devices both pre- and post-sale. In addition to validating the degree to which a seller's location matches the location of the device, we examine cases of device movement -- once the device is sold and then subsequently re-used in a new environment. Our work highlights a previously unrecognized privacy vulnerability and suggests, yet again, the strong need to protect layer-two network identifiers.
Explore related subjects
Keep this discovery
Steven Su, Erik Rye, Dave Levin, Robert Beverly. 2025-06-16. Buy it Now, Track Me Later: Attacking User Privacy via Wi-Fi AP Online Auctions. https://arxiv.org/abs/2506.13052
Cite the original work for its findings. Save a collection to share your selection of sources.