
Your WiFi Can Sense You Breathe: What the Open-Source Lifesign Scanner Means for Privacy
A recent Hackaday write-up covered "wifisense-pi", an open-source project by The Masked Bear that does something that sounds like science fiction: it detects whether a human is present in a room — even a perfectly still one, by picking up the tiny motion of breathing — using nothing but ordinary WiFi signals, and it works through walls. The hardware is unremarkable. An ESP32-S3 samples the 2.4 GHz radio channel one hundred times per second; a Raspberry Pi 4 runs the signal processing; a browser dashboard shows the results live. The project's source code was released on GitHub in August 2026 and is available to anyone. That combination — commodity hardware, published method, free software — is what moves WiFi sensing from academic curiosity to something worth planning for.
The physics, briefly
WiFi receivers constantly measure how their environment distorts radio signals — a dataset called Channel State Information (CSI). Every OFDM transmission is carried on dozens of narrow subcarriers, and the receiver estimates an amplitude and a phase value for each one, sixty-four times per packet on an ESP32. Your body is a moving reflector: chest movement from breathing, and even a heartbeat, perturbs those subcarrier values in patterns signal processing can isolate. A person walking across a room produces a violent signature; a still person breathing produces a ripple of a few hertz that an FFT pulls out of the noise floor.
Espressif ships first-party support for exactly this. Their esp-csi repository provides firmware that streams raw CSI off an ESP32, along with reference implementations of human activity detection, and their engineers have published performance measurements showing usable detection at ranges well beyond a single room. When the chip vendor ships the plumbing as a supported SDK component, the barrier is no longer expertise. It is intent.
Researchers have demonstrated presence detection, breathing and heart-rate estimation, gait recognition and even coarse body-pose reconstruction from CSI using commodity chipsets. The sharpest recent demonstration is adversarial: a University of Twente bachelor's thesis on one-sided CSI-based sensing in through-wall settings showed that low-cost ESP32 devices placed entirely outside a building — receiving only, listening to the occupant's own router traffic — could infer room-level presence through thick residential walls. No device inside, no cooperation from the network owner, no transmitted frame to attribute. That is the scenario that should change how you think about rental properties and shared buildings.
Because the sensor listens to signals that already exist, a device that transmits nothing itself is genuinely hard to detect — there is no scan, no beacon, no suspicious frame to alert on. Most DIY builds do transmit (wifisense-pi needs a stable link to its Pi), but the Twente work shows the fully passive variant is not hypothetical.
What wifisense-pi can and cannot do
Worth being precise about the limits, because the popular retellings overstate them. As the Hackaday coverage notes, a single sensor cannot give you position information — it answers "are there humans in this room?", not "where are they". Multiple people distort the signal more than one, but the project's author reports you cannot reliably separate the individuals. And a large dog reads much like a person of equivalent mass. You can also defeat it, briefly, by holding your breath.
What it is: a very sensitive motion detector that needs no camera, no wearable, and no line of sight. What it is not: an imaging radar. Keeping the capability sized correctly matters for two reasons — alarmism gets dismissed, and the mitigation advice differs depending on whether an attacker needs to be inside your space or can sit outside it.
The defensive read
For Australians, the practical questions are: who would deploy this, and what can be done about it? Realistic threat scenarios include a hidden ESP32-class device planted in a share house, office or rental property to monitor when a person is home or in a specific room; a stalker repurposing IoT hardware; and commercial sensing built into routers and smart devices that occupants never agreed to. The capability also has legitimate, privacy-respecting uses — elder-care fall detection being the classic one — which is why the defensive framing matters more than alarmism. Hospitals and aged-care facilities have been trialling radio-based monitoring precisely because it replaces cameras in bedrooms.
Practical hardening and detection steps:
- Inventory and audit the radios in your space. Unknown ESP32 or SBC-class devices on your network or visible in RF surveys deserve investigation. Periodic WiFi scans (airodump-ng and equivalents on hardware you own) will reveal transmitters; a passive-only sensor will not appear, but most DIY builds do transmit because they need a stable link. A phone-side helper app such as WiFiAnalyzer on Android will show every BSSID in range, and any device beaconing from inside your lounge room that you can't match to something you own is worth pulling the power on.
- Prefer 5 GHz where possible. Wall attenuation is far higher at 5 GHz than 2.4 GHz, which degrades through-wall sensing materially. If you control the network, steering sensitive areas onto 5 GHz-only coverage is a real, if partial, mitigation. The catch: every modern router still serves 2.4 GHz for IoT devices, and it is exactly that band the low-cost sensor samples. Disabling 2.4 GHz in bedrooms is the aggressive version; making your heaviest traffic ride 5 GHz is the sane default.
- Keep the channel busy and noisy. The Twente thesis's clearest result is that sensing through walls degrades sharply when the channel carries other traffic — co-channel interference and channel-hopping mask the small human-motion signature in the CSI. Leaving a low-bandwidth background transfer running is not encryption, but it raises the attacker's error rate at zero cost.
- Lock down physical access. The most realistic attack needs a device inside or adjacent to the space. In rentals and share houses, check for unfamiliar powered devices — USB power banks plugged in with nothing attached are the classic tell, since an ESP32 draws its power from exactly that form factor. ACMA rules mean hidden devices transmitting on Australian spectrum are also a regulatory matter, and covert surveillance of people's homes raises state and territory surveillance-device law issues — this is not legal advice, but covert monitoring may be unlawful in several circumstances, and tenants should treat an unexpected radio as a matter for police, not a confrontation.
- If you build with CSI, build ethically. If you are experimenting with this technique — and it is a genuinely interesting project for anyone comfortable with an ESP32 and a Pi — document consent, keep the sensing scope to spaces and people who agreed to it, and start from our guide to lawful ESP32 security research. The same hardware that respects consent also demonstrates to a court that you knew what it could do.
One more angle that rarely gets said out loud: this cuts both ways for people fleeing violence. A stalker's hidden device is easier to find if you know to look, and knowing that "no cameras" is no longer "no sensors" is the difference between a sweep that finds something and one that doesn't.
The lifesign scanner is best understood as a public service announcement in code: the physics is decades old, the tooling is now a weekend project, and privacy planning for homes, clinics and workplaces should assume that presence in a room is observable through walls without a camera.
This post is general information, not legal advice.