Header illustration for "Your router already sees you breathe: WiFi presence sensing, now standardised and open source"

"Your router already sees you breathe: WiFi presence sensing, now standardised and open source"

Your router already sees you breathe: WiFi presence sensing, now standardised and open source

For most of this decade, "WiFi sensing" sounded like a research paper topic: the idea that human bodies disturb wireless signals in measurable ways, so a WiFi network could detect presence, motion and even breathing without a camera or a dedicated radar. That has changed on two fronts at once. An open-source project called wifisense-pi published a working build in August 2026 that Hackaday covered, and the IEEE published the 802.11bf WiFi Sensing amendment in September 2025, which will bake the capability into future consumer routers. Presence detection through walls is about to become a feature, not a hack. That is useful if you want to know when to turn the lights on, and uncomfortable if you think about who else can use it. This post covers how the open-source build works, what the standardisation means, and where the Australian law sits.

How the open-source build works

The wifisense-pi project splits the work across two devices, and the split is the instructive part. An ESP32-S3 measures the 2.4 GHz radio channel one hundred times per second, capturing how the channel's characteristics wobble. A Raspberry Pi 4 does the signal processing: separating the slow drifts (temperature, antenna movement, furniture) from the fast, rhythmic disturbance patterns a breathing human produces in the same room or an adjacent one. As the Hackaday write-up puts it, it is not detecting life as such; it is a very sensitive motion detector built on the fact that we fleshy bags of goo disturb WiFi signals with our presence.

The build needs no new radios, no camera, no microphone. The ESP32-S3 is already in thousands of Australian homes inside other gadgets; a spare ESP32 dev board starter kit (A$45.45) plus any SBC you own is the whole hardware list. Nothing transmits anything a regulator would care about: it listens to the ordinary WiFi you already run, which is why it slipped under most people's radar until now.

We have covered a related capability before in the mmWave room scanner, which uses a dedicated 24/60 GHz radar sensor. WiFi sensing is the same idea with cheaper, more ubiquitous hardware and worse precision. mmWave gives you a shape; WiFi gives you a presence pulse.

Standardisation changes the economics

The IEEE 802.11bf amendment, published 26 September 2025, defines how WiFi devices negotiate sensing sessions and report measurements, making the capability an interoperable feature rather than a vendor experiment. The working group's own status page lists it among the standards approved that month. What that means practically: router and device vendors can now ship sensing as a checkbox feature (presence-based lighting, fall detection for aged care, occupancy-driven climate control), and the industry has been explicit about wanting exactly those markets.

Interoperability cuts both ways. A standard API means your smart home works better, and it also means the sensing capability stops being something you opted into by building a project and becomes something your router does by default. Devices that sense are devices that measure you. If that prospect bothers you, the mitigation is the same one we recommend constantly: prefer hardware you control, keep an inventory of what radios are in your house, and reach for a Faraday phone pouch (A$19.90) and other shielding when you want a room to stop talking. Our smart doorbell law guide covers the adjacent problem of neighbours' sensors pointed at your property.

The Australian legal gap

Here is the uncomfortable part: Australian law is built around cameras, listening devices and tracking devices. WiFi presence sensing is none of the three. State surveillance devices acts (the Surveillance Devices Act family across the states and territories, and the federal equivalent for Commonwealth matters) restrict recording private conversations and visual images, and a growing number regulate data-collection by specified devices. But a system that infers "someone is in the next room, breathing at 14 breaths per minute" without capturing an image or a sound largely falls outside those definitions. The OAIC's privacy guidance applies to organisations handling personal information, and the Privacy Act's reform process we covered in the Tranche explainer will eventually tighten the rules around biometric and inferred data, but no bill currently before Parliament specifically names WiFi sensing.

So the honest framing is: the law does not yet clearly restrict this, which is exactly when to think about it hardest. If you deploy one in your own home to detect falls or presence, you are the data subject and the controller, and the only person affected. Installing one to monitor a shared house, a rental you manage, a workplace or an Airbnb without telling the people being sensed is a different matter: it may not be an offence, but it is the same ethical failure the smart doorbell rules now address for cameras, and disclosure is the minimum standard. And pointed at a neighbour's home, deliberately, it is a monitoring capability without any of the legal guardrails a camera would trigger. Do not be the test case that gets the technology banned.

Nothing here is legal advice.

Why defenders should learn it

If you work in security, this is worth an hour of your time for a reason beyond novelty: WiFi sensing is a demonstration that ambient RF leaks far more about a space than most people assume. The same channel-measurement principle behind presence detection shows up in other inference attacks, and the defensive takeaway generalises: your wireless environment is a sensor whether or not you intended it to be one. Building the open-source project yourself is the fastest way to internalise how much information 2.4 GHz gives up, and the project's documentation is good enough to make it a weekend build.

A defensive checklist

If the sensing side of this leaves you uneasy, there is a concrete checklist, and it is mostly inventory work:

  1. Know what radios are in your rooms. Presence sensing needs an 802.11 device doing the measuring. Router, mesh nodes, smart display, robot vacuum: each is a potential sensor. An hour with your router's client list is the highest-value privacy audit in the house.
  2. Prefer dumb where it counts. Bedroom and bathroom sensors should not be network devices at all. The cheapest hardening is not buying the smart version.
  3. Segment and observe. Put IoT devices on their own VLAN or guest network, then watch their traffic. A device that chatters when the room is empty is telling you something worth investigating.
  4. Update the router. 802.11bf features will arrive in firmware. Vendors that publish changelogs let you know when sensing lands; vendors that do not are a reason to choose a different router, which is the thesis of our degoogled phone OS comparison applied to your network gear.

None of this is paranoid. The standard is published, the vendors have product pages drafted, and the open-source build proves the physics. Deciding deliberately what you allow in your own home is simply the same threat modelling we recommend in threat-model-buying-privacy-hardware.

Parts list, AU-priced

Affiliate disclosure: products linked are our own store.

The capability is arriving whether individuals experiment with it or not, via standards and product roadmaps. Understanding it from the builder's side is how you stay ahead of it from the privacy side.

← All posts