Flipper Zero GPS module for wardriving

Is Wardriving Legal in the US? What the Law Actually Says (2026)

Wardriving sits in a legal grey area in most people's minds, but US courts and statutes have actually drawn a fairly clear line. It's not where most people guess.

Quick answerIn the United States, passive wardriving is generally legal: logging the SSID, BSSID, channel, encryption type and GPS location that Wi-Fi access points broadcast in the open — the data behind mapping projects like WiGLE — is not banned by any federal statute. The line you cannot cross is connecting to a network you don't own or capturing the traffic flowing over it. That's where the Computer Fraud and Abuse Act (CFAA) and the Wiretap Act take over. This is general information, not legal advice.

"Is wardriving illegal?" is the wrong question, because wardriving isn't one activity. Driving around while a scanner logs the beacon frames every router shouts into the air is legally very different from joining an open network or grabbing the packets on it. US law treats those as separate acts, and the penalties live entirely on one side of the line.

Activity US legal status (general) Statute in play
Logging SSID / BSSID / GPS from public beacon frames Generally legal None prohibits it; FCC Part 15 spectrum
Uploading that metadata to WiGLE Generally legal None prohibits it
Connecting to / authenticating to someone else's network Illegal without authorization CFAA (18 U.S.C. § 1030) + state law
Cracking a Wi-Fi password (WPA handshake, etc.) Illegal without authorization CFAA + state law
Capturing the content of traffic on an unencrypted network Illegal Wiretap Act (18 U.S.C. § 2511)

What "wardriving" means legally

In its narrow, defensible sense, wardriving is passive reception. A Wi-Fi access point continuously transmits beacon frames — broadcast management packets that announce the network's SSID (name), BSSID (MAC address), supported channels and security type — so that nearby devices can find it. A wardriving rig just listens, timestamps what it hears, and tags it with a GPS fix. It never transmits a request to any network, never associates, and never touches the data payload.

That distinction is the whole legal story. Passive listening to public broadcasts is treated very differently from initiating contact with, or reading traffic on, a network that isn't yours.

The federal picture: no statute bans passive wardriving

There is no US federal law that specifically makes wardriving illegal. Collecting the presence, location and metadata of Wi-Fi networks — and building or contributing to a computer-generated map from it — is not prohibited by any federal statute. Wi-Fi runs on unlicensed spectrum under the FCC's Part 15 rules, which allow receiving these emissions, and no federal statute forbids passively scanning for network presence. Enforcement actions against pure detection are rare to nonexistent.

The federal law people fear is the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030. The CFAA criminalizes intentionally accessing a computer "without authorization" or in excess of authorization. The key word is access. Passively logging a beacon frame is not accessing the network — you never enter it. The moment you associate, authenticate, or otherwise reach into a network you have no permission to use, you've crossed into CFAA territory. Intent and action, not the act of scanning, are what trigger liability.

The bright line: Joffe v. Google and the Wiretap Act

The most important US case for wardrivers isn't a wardriving prosecution — it's Joffe v. Google, Inc., 729 F.3d 1262 (9th Cir. 2013). Google's Street View cars, while photographing streets, also collected fragments of payload data — actual content, including emails and passwords — from unencrypted home Wi-Fi networks.

The Ninth Circuit held that intercepting the content of unencrypted Wi-Fi communications violates the Wiretap Act (18 U.S.C. § 2511). The court rejected Google's argument that unencrypted Wi-Fi was a "radio communication" readily accessible to the general public, reasoning that the exemption is aimed at traditional (auditory) radio broadcasts, and that the mere availability of gear able to receive Wi-Fi doesn't make those networks "readily accessible to the general public." The Supreme Court declined to hear the appeal in 2014, leaving the ruling in force.

The practical takeaway is the line the case draws. Google got into trouble for capturing the content of traffic (payload). It is not the same as logging the SSID and BSSID a router broadcasts to announce itself — the metadata that WiGLE-style mapping relies on. Passive collection of publicly broadcast beacon information stays on the legal side; grabbing what people are actually sending over their networks does not.

The one-sentence rule: collect what the network announces (metadata), never what the network carries (content) — and never join a network you weren't invited onto.

State computer-crime laws

Every US state has its own computer-crime statute, and they follow the same logic as the CFAA: they punish unauthorized access, not passive reception. California's Comprehensive Computer Data Access and Fraud Act, Penal Code § 502, for example, criminalizes knowingly accessing or taking data from a computer, system or network without permission — a "wobbler" that can be charged as a misdemeanor or felony. None of these statutes target the act of listening to public beacon frames; they target getting into a system you have no right to enter.

Because the details vary state to state — and because how you use collected data can change the analysis — check your own state's computer-crime law before you go out, and don't treat any single article (including this one) as a substitute for a lawyer.

How to stay clearly on the legal side

  • Passive only. Configure your tools to receive beacon frames. Don't send probe floods, deauth frames, or association attempts at networks you don't own.
  • Metadata, not content. Log SSID, BSSID, channel, encryption type and GPS. Never capture or store the payload of anyone else's traffic.
  • Never connect. Don't join open networks, don't try passwords, don't run a handshake capture against a network you have no written permission to test.
  • No jamming, ever. Transmitting to disrupt Wi-Fi or any licensed/unlicensed service is separately illegal in the US and is not wardriving.
  • Test only what's yours. If you want to go beyond passive mapping into actual security testing, do it on your own gear or with explicit, written authorization.
  • Know your state. State computer-crime laws stack on top of federal law.

Build a passive-only wardriving rig

Wardriving that stays on the legal side is a receive-and-log job: a Wi-Fi scanner plus a GPS fix for each observation. These are the parts that do exactly that — no transmitting required.

Flipper Zero GPS Module WiFi Devboard 5Ghost BW16 (5GHz)

Frequently asked questions

Is wardriving illegal in the United States?
Not by itself. There is no US federal statute that makes passive wardriving — logging the SSID, BSSID and GPS of Wi-Fi networks from their public beacon frames — illegal. It becomes illegal when you connect to a network without authorization or capture the content of its traffic. This is general information, not legal advice.
Does wardriving violate the CFAA?
Passive scanning doesn't, because the Computer Fraud and Abuse Act (18 U.S.C. § 1030) punishes unauthorized access to a computer or network, and passively logging a broadcast beacon isn't access. Connecting, authenticating, or cracking a password to get onto a network you don't own is what triggers the CFAA.
Is it legal to upload wardriving data to WiGLE?
Uploading network metadata — SSID, BSSID, encryption type and GPS location observed from public beacon frames — to a mapping database like WiGLE is generally treated as legal in the US. The metadata is broadcast openly by the access points. What's not legal is collecting or sharing the actual content of traffic on those networks.
What does Joffe v. Google mean for wardrivers?
In Joffe v. Google, Inc., 729 F.3d 1262 (9th Cir. 2013), the Ninth Circuit held that capturing the payload (content) of unencrypted Wi-Fi networks violates the Wiretap Act; the Supreme Court declined to hear the appeal in 2014. The lesson for wardrivers is the line it draws: logging the metadata a router broadcasts is different from capturing what people send over the network. Stay on the metadata side.
Can I get in trouble for wardriving?
You can if you go beyond passive listening. Connecting to networks without permission, cracking Wi-Fi passwords, capturing traffic content, or jamming can violate the CFAA, the Wiretap Act, and state computer-crime laws such as California Penal Code § 502. Pure passive mapping has rarely, if ever, been the basis for a US prosecution.
Is scanning the same as connecting to open Wi-Fi?
No. Scanning is passively receiving the beacon frames a network broadcasts to announce itself. Connecting means associating with and using the network. Joining an open network you don't own — even without a password — can be treated as unauthorized access under the CFAA and state law, while passive scanning is not.

Sources & further reading: Computer Fraud and Abuse Act, 18 U.S.C. § 1030 (Cornell LII) · Wiretap Act, 18 U.S.C. § 2511 (Cornell LII) · Joffe v. Google, Inc., 729 F.3d 1262 (9th Cir. 2013) (Ninth Circuit opinion) · EFF: What the Google Street View Decision Means for Researchers · California Penal Code § 502 (FindLaw).

Back to blog