Buy it Now, Track Me Later: Attacking User Privacy via Wi-Fi AP Online Auctions


Steven Su, Erik Rye, Dave Levin, and Robert Beverly
Proceedings of the Privacy Enhancing Technologies (PETS 2025) Symposium,
Washington, DC, Jul 2025 (to appear).

Static and hard-coded layer-two network identifiers are well known to present security vulnerabilities and endanger user privacy. In this work, we introduce a new privacy attack against Wi-Fi access points listed on secondhand marketplaces. Specifically, we demonstrate the ability to remotely gather a large quantity of layer-two Wi-Fi identifiers by programmatically querying the eBay marketplace and applying state-of-the-art computer vision techniques to extract IEEE 802.11 BSSIDs from the seller’s posted images of the hardware. By leveraging data from a global Wi-Fi Positioning System (WPS) that geolocates BSSIDs, we obtain the physical locations of these devices both pre- and post-sale. In addition to validating the degree to which a seller’s location matches the location of the device, we examine cases of device movement—once the device is sold and then subsequently re-used in a new environment. Our work highlights a previously unrecognized privacy vulnerability and suggests, yet again, the strong need to protect layer-two network identifiers.

[PDF]

[ Return to publications ]