KIT researchers demonstrated WiFi routers can identify individuals with near-perfect accuracy. 197 test subjects, no special hardware or line of sight required.
Key facts
- 197 test subjects in the KIT study.
- Near 100% identification accuracy.
- No special hardware or line of sight needed.
- Exploits unencrypted beamforming feedback in WiFi.
Researchers at the Karlsruhe Institute of Technology (KIT) in Germany demonstrated that ordinary WiFi routers can identify individuals with near-perfect accuracy by reading unencrypted beamforming feedback that every connected device already broadcasts [According to @kimmonismus]. The system requires no phone, no special hardware, and no line of sight. 197 test subjects yielded nearly 100% identification rate.
The unique take here is that the surveillance infrastructure is already installed in every café, airport, and office—the only question is who starts reading the signals first. This isn't a future threat; it's a present capability that exploits a fundamental design choice in WiFi protocols.
Beamforming feedback is part of the IEEE 802.11ac/ax standards, designed to optimize signal direction. The feedback contains unique multipath signatures that vary per device and environment, essentially a physical-layer fingerprint. KIT's work shows these signatures are stable enough for individual identification.
Implications
This technique works passively—no active probing required. It can identify devices even when MAC addresses are randomized, because the beamforming feedback is tied to the hardware. The implication is that any WiFi network can become a surveillance system without modification.
Key Facts

- 197 test subjects used in the study.
- Near 100% identification accuracy.
- No special hardware required.
- Works without line of sight.
- Exploits unencrypted beamforming feedback.
What to Watch

Watch for regulatory responses from the German Federal Office for Information Security (BSI) or the EU's Article 29 Working Party on whether beamforming feedback qualifies as personal data under GDPR. Also watch for WiFi chipset vendors (Qualcomm, Broadcom, Intel) to announce encryption of beamforming feedback in future firmware updates.
What to watch
Watch for regulatory responses from Germany's BSI or EU data protection authorities on whether beamforming feedback qualifies as personal data under GDPR. Also watch for WiFi chipset vendors to announce encryption of beamforming feedback in firmware updates.









