Wi-Fi security flaws could let drones, attackers target you through walls

A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
(Image credit: Shutterstock / jijomathaidesigners)

A drone that leverages a widespread security flaw to detect Wi-Fi networks from inside buildings has been developed by the University of Waterloo (UOW) in Canada, raising fears about similar devices being used to conduct criminal activity.

In a press release, the university reported on developments first published in a paper by Dr. Ali Abedi, adjunct professor of computer science at UOW, and Deepak Vasisht, Assistant Professor in Computer Science at the University of Illinois Urbana-Champaign, titled “Non-cooperative wi-fi localization & its privacy implications”.

The device, known as the Wi-Peep, is a modified consumer drone that sends messages to connected devices as it flies, and can track their location “within a meter” by leveraging a known vulnerability known as “polite WiFi”. Ignoring the cost of a drone, the device reportedly costs $20 in parts, making it easy to assemble for criminals such as thieves.

Polite WiFi’s implications

Polite WiFi means that smart devices will respond to connection requests even when they’re password protected and the connection is refused. The Wi-Peep is able to track devices so closely by continuously sending contact messages to all devices in range. 

In a statement, Abedi contextualized the threat similar devices pose to security in the home and beyond.

““Using similar technology, one could track the movements of security guards inside a bank by following the location of their phones or smartwatches,” he said.

“Likewise, a thief could identify the location and type of smart devices in a home, including security cameras, laptops, and smart TVs, to find a good candidate for a break-in.”

“In addition, the device’s operation via drone means that it can be used quickly and remotely without much chance of the user being detected.”

The Wi-Peep was assembled to test the theory that these kinds of attacks would be possible after the identification of the Polite Wi-Fi loophole. In his statement, Abedi advocated for an extensive fix, “so that our devices do not respond to strangers”.

He also suggested that, until then, Wi-Fi chip manufacturers could introduce randomized response times so as to decrease the accuracy in device location reporting by devices such as the Wi-Peep.

Before any fix is issued, businesses and homeowners ought to be concerned about the proliferation of Internet of Things (IoT) devices, and the growing accepted wisdom that any and all devices, from cars, to fridges, to barbecues, benefit from internet connectivity.

Luke Hughes
Staff Writer

 Luke Hughes holds the role of Staff Writer at TechRadar Pro, producing news, features and deals content across topics ranging from computing to cloud services, cybersecurity, data privacy and business software.

Read more
A hacker wearing a hoodie sitting at a computer, his face hidden.
I just learned something awful about my home Wi-Fi setup thanks to iFixit’s ‘worst of CES 2025’ awards
Abstract image of cyber security in action.
TikTok’s American ownership rule ignores bigger IoT threat
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Find My app logo displayed on an iPhone 11 screen
This Find My exploit lets hackers track any Bluetooth device – here’s how you can stay safe
China
Chinese hackers develop effective new hacking technique to go after business networks
DJI Flip drone in flight, snowy mountain backdrop, person piloting using the RC2 controller in foreground
DJI is trusting users to fly their drones safely, and it's as bad an idea as it sounds
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge leak hints at a 2K display and a titanium frame
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited