bristol.wireless is a long-form cybersecurity research project by CSSLTD. We drive, walk and cycle every postcode in Bristol — passively recording the city's wireless surface, then turning the data into open maps, public reports and security insights for the businesses that operate inside it.
Every router, doorbell, printer and pair of headphones in Bristol broadcasts its presence hundreds of times per minute. Together they form a vast, public layer of infrastructure that nobody is responsible for — and almost nobody is studying.
bristol.wireless is a multi-year cybersecurity research project running across the city of Bristol. Working from a custom-built mobile sensor platform, we passively record the wireless beacons broadcast into public space — the same signals every phone in your pocket already sees, every second of every day.
From that raw signal we build something the city has never had before: an open, postcode-level picture of its wireless health. Where is encryption strong? Where is it weak? Where are vendor defaults still in place a decade after the headlines? Which streets light up with rogue access points after dark?
The output is a public atlas, a research log, and a series of tools — each one a separate module on this site. Some are already live. Some are in the field. Some are queued for later in the season. None of them exist anywhere else in the UK.
The project is run independently by CSSLTD, an owner-operated cybersecurity practice based in the South West. Everything here is non-commercial, published openly, and bound by a strict code of ethics.
We listen to what is already being broadcast. We never associate, probe, deauthenticate or attempt to access any network.
Findings are published at street, postcode or district level. No single home or device is ever named, plotted or exposed.
We work from roads, pavements and public transit. Private property, residential interiors and venues that ask us not to: off-limits.
Every dataset, model and insight is published openly. Bristol businesses can request a free read-out of their own footprint, any time.
Each module below is a self-contained piece of the project — its own data set, its own interface, its own publication track. Tap through to see what's live, what's in beta, and what's coming next.
An interactive map of Bristol overlaid with every wireless observation from the project's field sessions. Filter by encryption type, vendor, district, time of day. Watch the heatmap evolve as new postcodes come online. Click any district for a full read-out.
A one-look report of how your postcode compares to the rest of the city. Network count, encryption mix, default-SSID rate, vendor diversity — distilled into a single grade. Built for the curious resident, the local business owner, and the council planner alike.
When the rig is on the road, this is what it sees. A live, anonymised stream of observed networks scrolling through the dashboard — encryption tier, signal class, and a one-word category tag generated by a language model on the back end.
Not every observation is interesting — but a few are. The anomaly log is the editorial output of the project: a written case file every time the sensor catches something unusual. Twin access points, default-credential giveaways, devices broadcasting their own model number in plaintext. Each case dissected, anonymised, and published.
A high-street café broadcasting an open guest network — also broadcast, from a different vendor, fifteen metres away.
WEP-protected access point observed on a residential street; encryption considered broken since 2007.
Cluster of six routers across one street, all on factory-default SSIDs and presumed factory passwords.
One year. Forty-seven postcodes. One long-form documentary series following the field season from first calibration to final atlas. Part technical, part travelogue, part argument about what cities should know about themselves. Released chapter by chapter across the year.
If your business has been observed during a field session, you can request a free, one-page report of how your wireless footprint looks from the public street. Encryption tier, password-strength indicators we can infer, vendor defaults, any anomalies in the immediate vicinity. No login. No selling. No catch.
Everything the project publishes can be traced back to a documented capture, a documented filter, and a documented model. The method is the product.
Flipper Zero paired with an ESP32-C5 wireless co-processor and a dedicated GPS unit, operated in monitor mode from a vehicle, bicycle or on foot.
Only public beacon frames — the same signals your phone passively sees — are recorded. No probing, no association, no traffic interception.
Sessions export to the open WiGLE schema for interoperability with the global wardriving research community.
Before any data hits the analysis stage, an automated filter removes SSIDs containing names, phone numbers, addresses or other personal identifiers.
A language model classifies SSID patterns, clusters vendor signatures, drafts case-file summaries and writes weekly briefs — all from anonymised input.
Data is aggregated to street or postcode level before publication. Raw captures never leave the secured analysis environment.
Passive observation of publicly broadcast beacons only. We never associate with, attempt to access, or interfere with any network.
All maps, reports and visuals are aggregated to street or postcode level. No BSSID is ever paired with a specific GPS coordinate in any public output.
Names, phone numbers, addresses or other identifiers found inside SSIDs are filtered before the data enters any analysis or display pipeline.
Any business or property owner can request exclusion. Their observations are purged from working datasets and excluded from all future field sessions.
If a field session uncovers something genuinely dangerous, the affected party is notified privately before — and often instead of — any publication.
A short Sunday-evening dispatch with the week's most interesting observation, one map, one anomaly, and the next field session on the calendar. No sales. No spam. Unsubscribe anywhere.