Buy it Now, Track Me Later: Attacking User Privacy via Wi-Fi AP Online Auctions
Steven Su, Erik Rye, Dave Levin, Robert Beverly

TL;DR
This paper reveals a novel privacy vulnerability where Wi-Fi BSSIDs can be remotely extracted from online marketplace images and geolocated, exposing user location data and device movement.
Contribution
The study introduces a new attack method combining computer vision and geolocation to identify Wi-Fi device locations from online listings, highlighting privacy risks.
Findings
Wi-Fi BSSIDs can be extracted from images on online marketplaces.
Geolocation of devices reveals seller and device movement.
Privacy vulnerabilities in layer-two network identifiers are significant.
Abstract
Static and hard-coded layer-two network identifiers are well known to present security vulnerabilities and endanger user privacy. In this work, we introduce a new privacy attack against Wi-Fi access points listed on secondhand marketplaces. Specifically, we demonstrate the ability to remotely gather a large quantity of layer-two Wi-Fi identifiers by programmatically querying the eBay marketplace and applying state-of-the-art computer vision techniques to extract IEEE 802.11 BSSIDs from the seller's posted images of the hardware. By leveraging data from a global Wi-Fi Positioning System (WPS) that geolocates BSSIDs, we obtain the physical locations of these devices both pre- and post-sale. In addition to validating the degree to which a seller's location matches the location of the device, we examine cases of device movement -- once the device is sold and then subsequently re-used in a…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Privacy, Security, and Data Protection · Wireless Networks and Protocols
