Wi-Fi Mapping and “Wardriving”

Collected once, searchable by anyone, forever.

Law Firm Cybersecurity · Chapter 14~5 min read

Someone drives slowly past your office with a laptop and an antenna on the passenger seat. They don't stop, don't get out, don't touch anything. They're just listening — logging every wireless signal in range: your office wifi, the guest network, the Bluetooth devices, the printers announcing themselves. Then they upload it all to a public map that anyone can search.

This is wardriving, and much of what they collect ends up on public, searchable maps of the world's wireless networks — so an attacker doesn't even have to visit. They can look your office up.

What the airwaves give away

Wireless networks broadcast. That's how they work — and it means a network's name and identifiers are readable to anyone in range without connecting to anything. Wardrivers collect these details and upload them to public platforms that map wireless signals by location; WiGLE is a well-known searchable engine for exactly this, letting anyone query Wi-Fi, Bluetooth, and cell data by network name, identifier, or location.1

What that discloses about a firm:

  • Network names that leak information. Device and network names — an SSID or a Bluetooth device announcing itself as "Smith-Law-Firm" or "Company HP Printer" — hand over exactly what they say.2 A network named after the firm ties the wireless map straight to the office. A device named for its function advertises what it is.
  • Location. Because these networks get mapped to coordinates, a firm's wireless footprint can be located and looked up on a public map.1
  • A foothold, if the network is weak. If a wardriver finds a vulnerable or poorly secured network, that's a path in — to access data, or to move onto the systems that matter.3 And the guest network, the "temporary" setup, and the never-changed default are where weakness hides.
FIGURE 1 — THE STREET COLLECTS, THE MAP REMEMBERS

Collected from the curb

  • "SmithLaw-Office" SSID
  • "SmithLaw-Guest"
  • "HP LaserJet — Reception"
  • A smart-TV beacon
  • Signal strength pinning the suite

On the public map

  • The same signals, plotted as searchable pins at the firm's address
  • Queryable by name, identifier, or location
  • By anyone, indefinitely
Collected once, searchable by anyone, forever.

Why this matters more than it seems

Wardriving sounds exotic, but the result — searchable public maps of wireless networks keyed to location and name — is ordinary and permanent. A firm whose wifi is named after itself, whose guest network is weakly secured, or whose Bluetooth devices announce their function is contributing to that map.

What actually fixes this

1. Don't name your network after the firm. An SSID that doesn't identify the firm breaks the easy tie between a mapped signal and your office. Small change, real benefit.

2. Secure the wireless properly. Strong modern encryption (WPA3 where available), a long non-default passphrase, and the router's own admin password changed from the factory default. The default-password problem from Chapter 11 applies to the router most of all — it's the front door to the whole network.

3. Separate guest wifi completely. Guests, and any personal devices, belong on a network segment with no path to the systems that hold client data. A guest network should reach the internet and nothing else.

4. Rename or quiet chatty devices. Bluetooth and networked devices that announce their function ("…HP Printer") should be renamed to something neutral where possible.

5. Require a VPN for anything sensitive over wireless. Especially on any network the firm doesn't fully control — and, per Chapter 5, especially for remote and mobile work. A VPN protects the traffic even when the network can't be trusted.

6. Look yourself up. The firm's own wireless footprint can be checked on the public maps. Seeing what's already there — the same self-audit instinct as the rest of this guide — tells you what to fix.

This is the final chapter, so it's also the place to make the guide' whole point once more: nearly everything in these fourteen chapters is something an outsider can already see, map, or look up about your firm. Security starts with looking at yourself the way they do — and then closing what you find.

Request a wireless-footprint check

The last "here's what's already public about you" check in the guide — and the natural place to make the whole set an ongoing monitored service rather than one-off scans.

Your firm's wireless checklist

Spencer McLennan
Spencer McLennan is the founder and lead webmaster of LegalWebmasters, and has handled websites, hosting, and security for law firms and professional practices across the United States and Canada since 2007. He holds an MBA, a PCM from the American Marketing Association, and is a graduate student in intelligence studies. He writes the Law Firm Cybersecurity and Law Firm SEO & Design guides. Connect on LinkedIn.

Footnotes

  1. Rae Baker, Deep Dive: Exploring the Real-World Value of Open Source Intelligence 418 (Wiley 2023).
  2. Id. at 412.
  3. Id. at 411.

Trusted by professionals like you.

Crease Harman LLP Borders Law Group David Aujla, Immigration Lawyer