You might be a Wardriver if

MrBill, CoD_Segfault

RF Village @ DEF CON 33 · Day 1 · RF Village

Overview

The "You might be a Wardriver if" talk, presented by CoDSegfault and MrBill at RF Village, offers a humorous yet insightful glimpse into the subculture of modern war driving. Far from a traditional technical deep dive into new vulnerabilities or exploit methodologies, this presentation serves as a cultural exploration, defining the dedicated war driver through a series of relatable, often self-deprecating, anecdotes and shared experiences. It highlights the passion, commitment, and sometimes obsessive behaviors that characterize individuals deeply involved in mapping wireless networks.

Watch on YouTube

Visual summary for You might be a Wardriver if by MrBill, CoD_Segfault
Visual summary for You might be a Wardriver if by MrBill, CoD_Segfault

Key moments

  1. 0:00 Speakers introduce themselves and war driving experience
  2. 2:40 Defining what a 'war driver' is
  3. 4:45 When your car roof is covered in antennas
  4. 5:10 The elusive 8mm wrench for SMA connectors
  5. 5:50 Hardmounted power distribution block in your trunk
  6. 7:25 Always taking the scenic route for war driving
  7. 8:00 Discovering no GPS data after a long run
  8. 8:50 Tip: Mapping new construction for Wiggle points

You might be a Wardriver if

Speakers: MrBill; CoD_Segfault

Conference: RF Village

YouTube: https://www.youtube.com/watch?v=PsfM_ZDgffU

Overview

The "You might be a Wardriver if" talk, presented by CoD_Segfault and MrBill at RF Village, offers a humorous yet insightful glimpse into the subculture of modern war driving. Far from a traditional technical deep dive into new vulnerabilities or exploit methodologies, this presentation serves as a cultural exploration, defining the dedicated war driver through a series of relatable, often self-deprecating, anecdotes and shared experiences. It highlights the passion, commitment, and sometimes obsessive behaviors that characterize individuals deeply involved in mapping wireless networks.

CoD_Segfault, known for his "back-to-back third place worldwide board drive" and extensive use of microcontrollers and Android phones for war driving, brings a seasoned, competitive perspective. MrBill, a self-proclaimed "war driving cheerleader" and founder of the "Hard Hat Brigade" Wiggle group, complements this with an emphasis on community and encouragement. Together, they paint a vivid picture of the modern war driving enthusiast, from the technical intricacies of their setups to the social dynamics of their competitive yet collaborative community.

This talk matters because it demystifies the war driving community, showcasing the evolution of a once-niche activity into a sophisticated hobby complete with global leaderboards, specialized hardware, and a vibrant social fabric. By illustrating the lengths to which individuals go to map wireless networks, it implicitly underscores the pervasive nature of Wi-Fi signals and, by extension, the critical importance of robust network security practices. It's a testament to human curiosity and the drive to explore, even if that exploration involves meticulously mapping every Wi-Fi access point in a 50-mile radius.

Background

▶ Watch: Speakers introduce themselves and war driving experience (0:00)

War driving, a portmanteau of "war dialing" and "driving," originated in the early 2000s with the widespread adoption of Wi-Fi. Initially, it involved driving around with a laptop and a Wi-Fi adapter to detect and map wireless networks, often with the intent of finding open or poorly secured access points. While the early days were characterized by simple setups, the practice has evolved significantly, transforming into a sophisticated hobby and competitive sport. Both CoD_Segfault and MrBill recount their early experiences, with MrBill noting his initial foray around 2003 before a decade-and-a-half hiatus, and CoD_Segfault having seriously returned to it "four, five years ago or so."

The modern war driving landscape is heavily influenced by platforms like Wigle.net (often referred to as "Wiggle" in the talk), which serves as a global database and leaderboard for mapped wireless networks. This platform transforms the act of scanning into a competitive pursuit, offering "free internet points" and "clout" within dedicated communities. The motivation for war drivers has shifted from merely finding free internet to achieving high rankings, contributing to comprehensive global maps, and engaging with a like-minded community. MrBill explicitly states his return to war driving was motivated by these points and clout, and he actively encourages others through his "Hard Hat Brigade" Wiggle group, which aims for "worldwide dominance of the leaderboard."

Technologically, the field has progressed from laptops to more compact and specialized equipment. CoD_Segfault highlights his reliance on microcontrollers and Android phones for his war driving operations. He also mentions his work with the BW16 open project, specifically for Realtek dual-band chips, to improve their integration with the war driver.uk project. This indicates a move towards custom, often open-source, hardware and software solutions that are more efficient and adaptable for mobile scanning. The emphasis on specific chipsets and projects demonstrates the community's dedication to optimizing data collection and compatibility. The challenges faced by early war drivers, such as finding Wi-Fi adapters capable of monitor mode and dealing with driver compatibility issues, are still relevant, as evidenced by MrBill's anecdote about Amazon returns. This background sets the stage for understanding the unique blend of technical acumen, dedication, and community spirit that defines the modern war driver.

Key Findings

▶ Watch: When your car roof is covered in antennas (4:45)

While the talk "You might be a Wardriver if" isn't structured around traditional security research findings, it presents a unique ethnographic study of the war driving community. The "findings" are, in essence, a collection of shared behaviors, technical quirks, and cultural norms that define a serious war driver. These observations reveal the depth of commitment and the unique challenges faced by individuals dedicated to mapping the wireless world.

One prominent "finding" is the sheer accumulation and prioritization of specialized equipment. Speakers describe finding "four antennas I didn't recognize" in their car, illustrating how antennas become ubiquitous. This extends to the roof of a car resembling a "Christmas tree" of antennas, requiring significant resources and even structural integrity. The necessity of an 8mm wrench for tightening SMA connectors further highlights the specific, often overlooked, tooling required. Power management is another critical area; serious war drivers often install power distribution blocks in their trunks, sometimes even incorporating dual batteries, solar panels, or requiring a second alternator to sustain their power-hungry setups. This level of hardware investment and modification is a clear indicator of dedication.

Beyond hardware, the talk uncovers idiosyncratic personal habits and decision-making. War drivers adapt their attire to "accommodate multiple cell phones," indicating the multi-device setups often employed. The "always take the scenic route" mantra reflects a prioritization of network mapping over conventional travel efficiency. The frustration of completing "a run for hours and then... find out that you have no GPS data in your logs" underscores the critical role of accurate location data for platforms like Wigle.net and the profound disappointment when technical glitches erase valuable efforts.

The competitive and collaborative community dynamics are also a significant "finding." While war drivers often operate solo to maximize their individual points, the talk reveals a nuanced social code. Agreements exist, such as "main streets near each other's houses are fair game" but with some areas "blocked off." The anecdote about "Grimace" and the new subdivision, where a speaker "lied" about having mapped it, illustrates the cutthroat nature of claiming new territory (which often yields many new access points) for points. Yet, there's also a spirit of shared knowledge, particularly regarding "which adapters work and which don't," preventing others from making costly hardware mistakes.

Finally, the talk highlights the pervasive integration of war driving into daily life. The discovery of "random Wi-Fi microcontrollers in your bathroom" or "war driving kits in every car that you own" (even family cars) exemplifies how the hobby permeates every aspect of a war driver's existence. The development of direct relationships with suppliers, where "AliExpress sellers start offering you discounts to volume of purchase" for items like ESP32s, showcases the scale of hardware acquisition. These findings, while presented humorously, collectively paint a picture of a deeply committed, technically proficient, and uniquely habituated individual for whom war driving is not just a pastime but a significant part of their identity.

Technical Deep Dive

▶ Watch: Hardmounted power distribution block in your trunk (5:50)

While the talk primarily uses humor to describe the war driver's lifestyle, it implicitly details a sophisticated technical ecosystem and operational workflow. The underlying technical deep dive for a serious war driver revolves around efficient, pervasive, and accurate wireless network detection and logging.

At the core of a modern war driving setup is the hardware for signal acquisition. This typically involves multiple Wi-Fi antennas, often mounted externally on vehicles for optimal signal reception across various frequencies. The mention of an 8mm wrench specifically for SMA connectors highlights the common antenna interface and the need for secure, reliable connections. Given the diverse range of Wi-Fi standards (802.11a/b/g/n/ac/ax), war drivers often employ multiple adapters or dual-band chips to capture signals across both 2.4 GHz and 5 GHz spectrums. CoD_Segfault's work with the BW16 open project for Realtek dual-band chips demonstrates a specific focus on optimizing hardware performance and compatibility, likely to ensure these chips can reliably enter monitor mode—a crucial capability for passively listening to all Wi-Fi traffic and identifying access points without associating with them.

Power management is a significant technical challenge. Running multiple Wi-Fi adapters, GPS receivers, microcontrollers, and Android phones concurrently demands substantial power. The solutions described—power distribution blocks, dual batteries, solar panels, and even a second alternator—point to advanced automotive electrical modifications. These are not trivial installations and require an understanding of vehicle electrical systems to prevent draining the primary battery or overloading circuits. The implication is that war drivers often engineer dedicated power solutions to sustain operations for extended periods, potentially hours-long "runs."

Data collection and processing are handled by a combination of devices. Android phones are frequently used, serving as the central hub for running applications like the official Wigle.net client. These phones not only record Wi-Fi data but also capture crucial GPS data for accurate location tagging. The frustration of "no GPS data in your logs" emphasizes the absolute necessity of accurate geographic coordinates for mapping and leaderboard contributions. Beyond phones, microcontrollers such as the ESP32 (mentioned in the context of AliExpress bulk purchases) are integral. These small, low-power devices can be configured with Wi-Fi modules to passively scan for networks, offloading this task from phones or laptops. They can then relay data, perhaps via Bluetooth or Wi-Fi, to a central logging device or store it internally for later upload. The "mini war driver" project mentioned by CoD_Segfault likely refers to such microcontroller-based, compact scanning units.

Software and platform integration tie everything together. Wigle.net is the de facto standard for uploading collected data, which includes SSID, BSSID (MAC address), encryption type, signal strength, and GPS coordinates. The war driver.uk project mentioned alongside the BW16 project suggests other community-driven software tools or platforms that complement or integrate with Wigle.net, perhaps offering specialized analysis or mapping features. The ability of Wi-Fi adapters to enter monitor mode is a critical software/driver requirement, as it allows for passive scanning without actively connecting to networks, thus maximizing the number of detected access points. The difficulty in finding adapters with "the right drivers" for monitor mode, leading to numerous Amazon returns, highlights a common technical hurdle that war drivers must overcome. This involves driver research, potentially custom driver compilation, and careful hardware selection to ensure full functionality.

In essence, a war driver's technical setup is a mobile, distributed sensor network. It combines robust antenna systems, custom power solutions, embedded computing (microcontrollers), and off-the-shelf mobile devices, all orchestrated to efficiently and accurately map the invisible landscape of wireless signals, with Wigle.net serving as the ultimate repository and competitive arena for their efforts.

Demo / Proof of Concept

▶ Watch: Always taking the scenic route for war driving (7:25)

This particular talk, "You might be a Wardriver if," did not feature a traditional technical demonstration or a proof of concept in the sense of exploiting a vulnerability or showcasing a new tool in action. Instead, the entire presentation served as an interactive "proof of concept" of the shared experiences and cultural identity within the war driving community.

The speakers engaged the audience directly, turning each "you might be a war driver if" statement into a call for participation. For instance, after describing finding "antennas in your car that you never remember owning," they prompted, "Raise your hand if that's happened to you." This interactive format, repeated throughout the talk, served as a communal validation, demonstrating that these seemingly peculiar habits and technical challenges are widely understood and experienced by those deeply involved in war driving. The collective raising of hands, the laughter, and the shared recognition were the "proof of concept" that the "war driver" identity is real, distinct, and deeply felt by many in the audience.

The talk's humorous tone and anecdotal style were, in themselves, a demonstration of the community's camaraderie and self-awareness. It showcased that despite the competitive nature of point-scoring on platforms like Wigle.net, there's a strong underlying sense of shared passion and mutual understanding among war drivers. The "demo" was the live, collective affirmation of the war driver's unique world.

Defensive Implications

▶ Watch: Tip: Mapping new construction for Wiggle points (8:50)

While "You might be a Wardriver if" is a lighthearted talk about the habits of war drivers, its underlying message carries significant defensive implications for individuals and organizations alike. The very existence and dedication of the war driving community underscore the inherent visibility of wireless networks and the ease with which their presence and basic configurations can be mapped from public spaces.

Firstly, the talk highlights that Wi-Fi networks are not secret. The fact that dedicated hobbyists are driving around with sophisticated setups to map every single access point means that any Wi-Fi network broadcasting from a building is publicly discoverable. This includes corporate networks, home networks, and even "hidden" SSIDs. The notion of a "hidden" SSID providing security through obscurity is debunked by war driving, as these networks still broadcast probe responses and can be easily identified by tools capable of monitor mode.

Secondly, the emphasis on collecting GPS data for every access point means that the physical location of Wi-Fi infrastructure is readily mapped and often publicly available on platforms like Wigle.net. This information, while seemingly innocuous, can reveal patterns of network deployment, identify branches or remote offices, and even highlight areas of dense network activity that might be of interest to malicious actors. An attacker could use this data to plan physical reconnaissance, identify potential targets, or understand the geographic distribution of an organization's wireless footprint.

From a defensive standpoint, the following actions are crucial:

  1. Assume Visibility: Organizations and individuals must operate under the assumption that all their wireless networks are visible and their approximate locations are known to anyone driving by. This means security cannot rely on obscurity.
  2. Strong Encryption and Authentication: The fundamental defense remains robust encryption (WPA2-Enterprise or WPA3-Enterprise for organizations; WPA2-Personal with strong, unique passphrases or WPA3-Personal for homes). Implementing 802.1X authentication for corporate networks adds another layer of defense by requiring user or machine credentials before network access is granted.
  3. Network Segmentation: Wireless networks should be carefully segmented from sensitive internal networks. Guest Wi-Fi should be entirely separate, and employee Wi-Fi should be on a different VLAN with strict firewall rules limiting access to critical resources. This minimizes the impact if an attacker gains access to the wireless network.
  4. Regular Audits and Configuration Review: Periodically audit Wi-Fi configurations for default settings, weak passwords, outdated encryption protocols, and unnecessary SSIDs. Ensure firmware is up to date on all access points and routers. Disable Wi-Fi Protected Setup (WPS) where possible.
  5. Physical Security of Access Points: While war driving is external, the information gathered can inform internal physical attacks. Ensure access points are secured against tampering and placed in locations that are not easily accessible to unauthorized individuals.
  6. IoT Device Security: Given the proliferation of Wi-Fi microcontrollers and IoT devices, ensure these are on isolated networks and do not expose sensitive internal systems. Their Wi-Fi presence will also be mapped.
  7. Awareness Training: Educate employees about Wi-Fi security best practices, including avoiding connecting to unknown networks and the risks associated with public Wi-Fi.

In conclusion, the war driver's dedication to mapping the wireless world serves as a constant, passive audit of global Wi-Fi deployment. This "free internet points" game inadvertently provides a powerful reminder that robust, layered security is paramount for any wireless network, as its mere existence is likely already logged and mapped.

Key Takeaways

  • War driving has evolved from a niche activity into a sophisticated hobby and competitive sport, driven by platforms like Wigle.net and a dedicated global community.
  • Serious war drivers exhibit profound dedication, investing significant time and money into specialized hardware, including numerous antennas, custom power distribution systems (dual batteries, solar panels, second alternators), and microcontrollers like ESP32s.
  • The pursuit requires specific technical knowledge, such as understanding SMA connectors, selecting Wi-Fi adapters capable of monitor mode, and dealing with driver compatibility challenges.
  • Accurate GPS data logging is critical for successful war driving, as it underpins the mapping and competitive aspects of platforms like Wigle.net, and its absence can negate hours of effort.
  • The war driving community, while competitive (e.g., claiming new construction, "lying" to friends for points), also fosters collaboration, sharing knowledge about effective hardware and software solutions.
  • From a defensive perspective, the ease with which war drivers map Wi-Fi networks underscores that all wireless networks are inherently visible and locatable. This necessitates robust security measures, including strong encryption (WPA3), network segmentation, regular audits, and an assumption that network presence is public knowledge.

About the Speaker(s)

CoD_Segfault is a highly experienced and competitive war driver, recognized for achieving "back-to-back third place worldwide board drive" in war driving competitions. His approach to war driving is deeply technical, primarily utilizing microcontrollers and Android phones for his operations. He has contributed significantly to the war driving community by working on the BW16 open project to integrate Realtek dual-band chips more effectively with the war driver.uk project, demonstrating a commitment to optimizing hardware and software for efficient data collection. CoD_Segfault describes himself as "always war driving," even having Wigle running on his phone continuously, highlighting his pervasive dedication to the hobby.

MrBill began his war driving journey around 2003 but took a "decade and a half off" before returning to the scene. His resurgence in war driving was motivated by the pursuit of "free internet points and like clout with certain groups of people." MrBill positions himself as more of a "war driving cheerleader," actively encouraging others and having founded the "Hard Hat Brigade" Wiggle group, which aims for "worldwide dominance of the leaderboard" in group standings. While he humbly notes his lower ranking compared to CoD_Segfault, he remains a passionate advocate for the war driving community, focusing on camaraderie and shared enjoyment.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A self-aware community culture talk that knows exactly what it is — no pretense of being a technical research drop. Judged as a hobbyist/community session at an RF Village side stage, it delivers what it promises: a humorous ethnographic portrait of wardriving culture that resonates with practitioners and gently evangelizes the hobby to newcomers. It won't advance the field, but it doesn't try to.

Heather Calloway (CISO) — PASS

A hobbyist culture talk about wardriving — entertaining for its audience at RF Village, entirely outside the lane of governance, institutional risk, or defender operations. The defensive implications section is boilerplate that any security awareness handout could have generated.

→ Top-rated talks at RF Village @ DEF CON 33

All talks from RF Village @ DEF CON 33