bristol.wireless
A CSSLTD research initiative
Live · Mapping in progress Field season 01 · 2026 Bristol, UK · BS1 — BS16

Mapping the invisible
infrastructure of a city —
one beacon at a time.

bristol.wireless is a long-form cybersecurity research project by CSSLTD. We drive, walk and cycle every postcode in Bristol — passively recording the city's wireless surface, then turning the data into open maps, public reports and security insights for the businesses that operate inside it.

Networks observed
0
Kilometres driven
0km
Postcodes covered
0/ 47
Last field session
Calibration phase
01 / PROJECT

A city has a second skin — invisible, constant, and almost entirely unmapped.

Every router, doorbell, printer and pair of headphones in Bristol broadcasts its presence hundreds of times per minute. Together they form a vast, public layer of infrastructure that nobody is responsible for — and almost nobody is studying.

bristol.wireless is a multi-year cybersecurity research project running across the city of Bristol. Working from a custom-built mobile sensor platform, we passively record the wireless beacons broadcast into public space — the same signals every phone in your pocket already sees, every second of every day.

From that raw signal we build something the city has never had before: an open, postcode-level picture of its wireless health. Where is encryption strong? Where is it weak? Where are vendor defaults still in place a decade after the headlines? Which streets light up with rogue access points after dark?

The output is a public atlas, a research log, and a series of tools — each one a separate module on this site. Some are already live. Some are in the field. Some are queued for later in the season. None of them exist anywhere else in the UK.

The project is run independently by CSSLTD, an owner-operated cybersecurity practice based in the South West. Everything here is non-commercial, published openly, and bound by a strict code of ethics.

The four operating principles

01

Passive only.

We listen to what is already being broadcast. We never associate, probe, deauthenticate or attempt to access any network.

02

Aggregate, never individual.

Findings are published at street, postcode or district level. No single home or device is ever named, plotted or exposed.

03

Public space, public data.

We work from roads, pavements and public transit. Private property, residential interiors and venues that ask us not to: off-limits.

04

Useful to the city.

Every dataset, model and insight is published openly. Bristol businesses can request a free read-out of their own footprint, any time.

02 / MODULES

Six modules. One atlas.

Each module below is a self-contained piece of the project — its own data set, its own interface, its own publication track. Tap through to see what's live, what's in beta, and what's coming next.

Module 01 Beta — public Q2 2026 Open data

The Bristol Atlas — a living heatmap of the city's wireless skin.

An interactive map of Bristol overlaid with every wireless observation from the project's field sessions. Filter by encryption type, vendor, district, time of day. Watch the heatmap evolve as new postcodes come online. Click any district for a full read-out.

  • Postcode-level heatmap of network density and encryption health.
  • Time-slider: watch the atlas grow week by week through the field season.
  • Filters for vendor (OUI), encryption tier, band (2.4 / 5 / 6 GHz), and 802.11 standard.
  • Downloadable open-data exports, anonymised to street resolution.
  • Custom dark-mode cartography styled for the project — no Google base tiles.
bristol.wireless / atlas
CLIFTON · BS8
CENTRE · BS1
BEDMINSTER · BS3
STOKES CROFT · BS2
BRISLINGTON · BS4
Density
low
high
Live preview
Module 02 Live Try below

Type your postcode. Get your Wireless Score.

A one-look report of how your postcode compares to the rest of the city. Network count, encryption mix, default-SSID rate, vendor diversity — distilled into a single grade. Built for the curious resident, the local business owner, and the council planner alike.

  • Letter grade (A→F) blending density, encryption strength and vendor-default exposure.
  • Side-by-side comparison with the city average and your nearest neighbours.
  • Shareable graphic for social — a private postcode badge.
  • Free PDF report for any business inside the surveyed area.
  • Quarterly refresh as new field data lands.
bristol.wireless / score
Score
B+
Networks observed
412
WPA3 adoption
38%
Vendor defaults
14%
B+ Above-average encryption health for the BS8 catchment, with a notable concentration of legacy WPA2 in the residential streets north of the bridge.
Module 03 Beta Streaming

The field feed — what the city is broadcasting, right now.

When the rig is on the road, this is what it sees. A live, anonymised stream of observed networks scrolling through the dashboard — encryption tier, signal class, and a one-word category tag generated by a language model on the back end.

  • Real-time stream during active field sessions, archived afterwards.
  • Auto-tagged categories: residential, business, IoT, transport, default-vendor, anomaly.
  • Per-session summary written by an LLM at the end of every drive.
  • SSIDs containing personal identifiers are filtered out before display.
  • Embed-ready widget for partner sites and city dashboards.
bristol.wireless / feed · live
Module 04 Q3 2026 Research log

The anomaly log — a curated diary of what shouldn't be there.

Not every observation is interesting — but a few are. The anomaly log is the editorial output of the project: a written case file every time the sensor catches something unusual. Twin access points, default-credential giveaways, devices broadcasting their own model number in plaintext. Each case dissected, anonymised, and published.

  • Hand-curated case files — roughly one a fortnight during field season.
  • Plain-language explainer of what was observed and why it matters.
  • All identifying details obfuscated before any case is published.
  • A long-form RSS for security professionals; a TikTok summary for everyone else.
  • Open invitation for researchers to contribute via the disclosure inbox.
bristol.wireless / anomaly
Case 014 · Twin APBS1 · 02:14
Two access points, one SSID, two vendors.

A high-street café broadcasting an open guest network — also broadcast, from a different vendor, fifteen metres away.

Case 013 · Legacy WEPBS3 · 19:40
A 2008-vintage encryption standard, still live in 2026.

WEP-protected access point observed on a residential street; encryption considered broken since 2007.

Case 012 · Default SSIDBS8 · 11:08
Vendor model + last-4-of-MAC, still on the box defaults.

Cluster of six routers across one street, all on factory-default SSIDs and presumed factory passwords.

Module 05 Q4 2026 Long-form film

The Bristol Cipher — a documentary in episodes.

One year. Forty-seven postcodes. One long-form documentary series following the field season from first calibration to final atlas. Part technical, part travelogue, part argument about what cities should know about themselves. Released chapter by chapter across the year.

  • Six episodes, 12–18 minutes each, shot on location across the city.
  • Bristol-specific story: Clifton vs Easton vs Harbourside vs Bedminster.
  • Cinematic dark-cyber visual language — radar sweeps, terminal overlays, drone B-roll.
  • Released free on YouTube, with a longer cut available to project subscribers.
  • Companion zine in print — a hand-bound atlas, limited run.
bristol.wireless / cipher
Module 06 Live For Bristol businesses

Free wireless read-out for any Bristol business.

If your business has been observed during a field session, you can request a free, one-page report of how your wireless footprint looks from the public street. Encryption tier, password-strength indicators we can infer, vendor defaults, any anomalies in the immediate vicinity. No login. No selling. No catch.

  • One-page PDF, hand-prepared per request, free to any Bristol business.
  • Includes a plain-language risk read-out and three prioritised fixes.
  • Optional follow-up: a paid, in-depth wireless audit by the CSSLTD team.
  • All data destroyed after delivery unless you opt in to keep it on file.
  • Available for any business within a surveyed postcode.
bristol.wireless / audit / sample
Encryption tier
WPA3 · OK
Guest network
Open · review
SSID exposure
Generic · OK
Vendor default
Detected
802.11 standard
ax · OK
Nearby twin SSID
1 within 30m
Band coverage
2.4 / 5 · OK
Signal bleed
~20m past door
03 / METHOD

A purpose-built rig. A strict protocol. A reproducible pipeline.

Everything the project publishes can be traced back to a documented capture, a documented filter, and a documented model. The method is the product.

SENSOR
01

Mobile capture rig

Flipper Zero paired with an ESP32-C5 wireless co-processor and a dedicated GPS unit, operated in monitor mode from a vehicle, bicycle or on foot.

CAPTURE
02

Passive beacon listening

Only public beacon frames — the same signals your phone passively sees — are recorded. No probing, no association, no traffic interception.

FORMAT
03

WiGLE-compatible output

Sessions export to the open WiGLE schema for interoperability with the global wardriving research community.

FILTER
04

Identity stripping

Before any data hits the analysis stage, an automated filter removes SSIDs containing names, phone numbers, addresses or other personal identifiers.

MODEL
05

LLM-assisted analysis

A language model classifies SSID patterns, clusters vendor signatures, drafts case-file summaries and writes weekly briefs — all from anonymised input.

RELEASE
06

Public, postcode-resolution data

Data is aggregated to street or postcode level before publication. Raw captures never leave the secured analysis environment.

04 / Ethics

This project is a research initiative — not an exposé. It runs by rules tighter than UK law requires.

  • UK Computer Misuse Act compliant.

    Passive observation of publicly broadcast beacons only. We never associate with, attempt to access, or interfere with any network.

  • No individual networks ever published.

    All maps, reports and visuals are aggregated to street or postcode level. No BSSID is ever paired with a specific GPS coordinate in any public output.

  • Personally identifying SSIDs are stripped.

    Names, phone numbers, addresses or other identifiers found inside SSIDs are filtered before the data enters any analysis or display pipeline.

  • Opt-out is honoured immediately.

    Any business or property owner can request exclusion. Their observations are purged from working datasets and excluded from all future field sessions.

  • Coordinated disclosure on anomalies.

    If a field session uncovers something genuinely dangerous, the affected party is notified privately before — and often instead of — any publication.

05 / Signal

Get the field log.
One brief. Every Sunday. Free.

A short Sunday-evening dispatch with the week's most interesting observation, one map, one anomaly, and the next field session on the calendar. No sales. No spam. Unsubscribe anywhere.

Encrypted in transit · No third-party trackers · Bristol-based
▸ Signal locked in. You're on the field log.