No promiscuous capture
Our firmware works as a normal Wi-Fi client and never listens to other people's traffic (promiscuous mode). It must join a network, and protected networks need the password.
Wi-Fi sensing avoids collecting images or audio, but presence and movement data can still expose people’s routines. Use ESPectre only with proper authority, clear notice, and a proportionate purpose.
ESPectre only senses while connected to a Wi-Fi network, and normally shares only motion information.
Our firmware works as a normal Wi-Fi client and never listens to other people's traffic (promiscuous mode). It must join a network, and protected networks need the password.
The firmware processes CSI on the ESP32 and shares only movement, motion state, and a few diagnostics. Raw CSI is available only on request, for research, over one local connection (GET /espectre/v1/csi).
MQTT messages contain no raw CSI, Wi-Fi names, access point addresses, IP or MAC addresses, packet captures, or serial logs. The device ID is derived from the MAC with SHA-256, so it hides the MAC but never changes. Messages still include that ID, the labels you set, movement data, and diagnostics.
This website talks to your device directly from the browser. Chrome asks for permission before a website can reach a device on your local network: allow it only when you want to manage a device on this network. If Chrome says access is denied, turn on Local network access in the site settings; on systems with their own local network privacy setting (such as macOS), Chrome must be allowed there too.
localhost, 127.0.0.1, or [::1] on any port, and nothing else.espectre-devices-<24 hex>.local. An ESPectre device answers without storing the name, searches the network once for other ESPectre devices, and sends back their addresses. The setup guide explains how it works../espectre devices lists devices from your computer instead of the browser.Browser policy reference: Chrome 147 Local Network Access.
Before deploying ESPectre, consider the people, place, purpose, and data path involved.
ESPectre rejects covert surveillance, stalking, coercion, discrimination, monitoring without legitimate authority, using occupancy patterns to facilitate intrusion, and any other illegal or unethical use of Wi-Fi sensing.
If you believe ESPectre or related Wi-Fi sensing is being used to harm people or violate the law, report the concern to us and, when appropriate, to the competent law enforcement, regulatory, or data protection authority. Contact local emergency services when someone may be in immediate danger.
Do not obtain evidence unlawfully or publish credentials, private telemetry, personal data, or details that could put someone at further risk. Reporting to the project does not replace reporting to the competent authorities.
Do not disclose suspected vulnerabilities in public issues. Use GitHub’s private reporting flow, or email the security address if you cannot use GitHub Security Advisories.
Share the affected version, a clear description, reproduction steps, potential impact, and any suggested mitigation. Do not include credentials or other people’s data.
Open private reporting ↗Use email when GitHub private reporting is unavailable. Give us reasonable time to assess and coordinate a fix before public disclosure.
security@espectre.dev