No promiscuous capture
Supported first-party firmware operates as an associated Wi-Fi station and does not enable Wi-Fi promiscuous mode. A deployment must join a network; protected networks require valid credentials.
Wi-Fi sensing avoids collecting images or audio, but presence and movement data can still expose people’s routines. Use ESPectre only with proper authority, clear notice, and a proportionate purpose.
ESPectre deliberately keeps the supported sensing path associated with a Wi-Fi network and limits normal operation to derived motion information.
Supported first-party firmware operates as an associated Wi-Fi station and does not enable Wi-Fi promiscuous mode. A deployment must join a network; protected networks require valid credentials.
Normal sensing frontends process CSI on the ESP32 and expose derived movement, motion state, and limited diagnostics. Raw CSI export belongs to the separate, explicit Streamer research workflow.
Canonical MQTT sensing messages omit raw CSI, Wi-Fi names, BSSIDs, local IP and MAC addresses, packet captures, and serial logs. The device ID is a stable SHA-256-derived pseudonym instead of the raw MAC, but messages still include that linkable ID, user-provided labels, movement data, and operational diagnostics.
The hosted portal connects from HTTPS to the selected ESPectre device's cleartext local WebSocket. Chrome 147 added Local Network Access permission checks for WebSockets and prompts before a public site can reach a local address. Allow that permission only when you intend to manage a device on the current network.
ws:// path under their mixed-content policies. Edge and mobile Chrome remain unclaimed until their physical browser runs are recorded. An unclaimed browser is not assumed compatible merely because it shares an engine with Chrome.localhost, 127.0.0.1, or [::1] hosts; host lookalikes remain rejected.espectre-devices-<24 hex>.local; compatible Native firmware answers that IPv4 A question without registering or retaining the nonce, then performs one bounded DNS-SD browse and returns validated Native, Streamer, ESPHome, and Matter endpoints at their advertised ports. The former static bootstrap name is not used as a fallback. After selection, the portal negotiates the device's exact Direct capabilities and hides unsupported configuration and runtime actions. It does not scan address ranges, keep a peer inventory, or send device IDs, IPs, hostnames, local URLs, nonces, or discovery payloads to analytics. From a repository checkout, ./espectre devices remains the deterministic host discovery path.Browser policy references: Chrome 147 Local Network Access, Mozilla's mixed-content WebSocket decision, and WebKit's mixed-content WebSocket decision.
Before deploying ESPectre, consider the people, place, purpose, and data path involved.
ESPectre rejects covert surveillance, stalking, coercion, discrimination, monitoring without legitimate authority, using occupancy patterns to facilitate intrusion, and any other illegal or unethical use of Wi-Fi sensing.
If you believe ESPectre or related Wi-Fi sensing is being used to harm people or violate the law, report the concern to us and, when appropriate, to the competent law enforcement, regulatory, or data protection authority. Contact local emergency services when someone may be in immediate danger.
Do not obtain evidence unlawfully or publish credentials, private telemetry, personal data, or details that could put someone at further risk. Reporting to the project does not replace reporting to the competent authorities.
Do not disclose suspected vulnerabilities in public issues. Use GitHub’s private reporting flow, or email the security address if you cannot use GitHub Security Advisories.
Share the affected version, a clear description, reproduction steps, potential impact, and any suggested mitigation. Do not include credentials or other people’s data.
Open private reporting ↗Use email when GitHub private reporting is unavailable. Give us reasonable time to assess and coordinate a fix before public disclosure.
security@espectre.dev