A BSSID, or basic service set identifier, is the 48-bit address that identifies a single wireless network operated by a single access point. In an infrastructure network it is the media access control (MAC) address of the radio inside the router, written as twelve hexadecimal digits, and it sits in the header of every beacon and management frame the access point transmits. Client devices need it to know which hardware they are addressing. Reading it requires no connection, no password and no permission from the owner.
That last property carries the field outside networking. A domestic router stays in one place for years while announcing a globally unique number roughly ten times a second. Anything in radio range can log the number and the strength of the signal it arrived on. Matched against a database mapping numbers to coordinates, a handful of nearby identifiers resolves to a building. Regulators have stopped treating the value as network plumbing and started treating it as precise location data.
How the identifier is formed
The 48 bits are not arbitrary. The first three octets form an organisationally unique identifier assigned by the IEEE to a manufacturer, which leaves the address space in dense contiguous blocks. The second-lowest bit of the first octet, the universal or local bit, marks whether the IEEE issued the address or the device generated it.
One radio can advertise several networks at once. A guest network and a staff network on the same hardware are separate basic service sets with separate identifiers, and most vendors derive the extra values by incrementing the final octet. The 802.11 standard formalises the arrangement through a multiple BSSID element, where one beacon carries a transmitted identifier and receivers derive the rest of the set from it. In an independent basic service set, the peer-to-peer mode with no access point, the value is a locally administered address built from a random number.
Turning a list of radios into a coordinate
Wi-Fi positioning exists because satellite fixes fail indoors, drain batteries and take time. A handset scans, collects the identifiers it can hear with each signal strength reading, and sends the list to a server holding a table of identifiers and coordinates built from devices that reported the same identifiers while holding a satellite fix.
Two designs diverged. Google's service calculates server-side and returns only a position, behind an API key and a per-query charge. Apple's returns the coordinates of the queried identifier plus, opportunistically, several hundred nearby ones, leaving the handset to compute its position and cache the rest for the next street. Research measuring that interface found accuracy values typically between 20 and 30 metres, and around thirty days between an access point appearing and becoming a usable landmark.
Advertising measurement inherits the physics. Industry guidance on footfall attribution places Wi-Fi derived location at 30 to 100 metres, better suited to indoor micro-location than satellite fixes, which degrade under a roof. The W3C Geolocation API lists Wi-Fi positioning among the underlying sources a browser may draw on without telling the page which one it used.
How it reaches advertising systems
No version of OpenRTB defines a field for it. The Device object records a connection type, and the Geo object carries latitude, longitude, an accuracy value and a type code distinguishing satellite fixes from IP inference. Resolution happens before the auction: a software development kit inside an application reads the surrounding radios and converts them to coordinates, which enter the bid stream as ordinary geographic data, indistinguishable from a satellite fix.
Enforcement has repeatedly landed on that conversion step. The Federal Trade Commission alleged in 2016 that InMobi read network names, identifiers and signal strengths nearby, fed them into its own geocoder database and inferred device location even where a user had refused the location permission. OpenX settled with the Commission on December 15, 2021 over collecting the same values from Android users who had opted out, for a civil penalty of $7.5 million with $2 million payable. OpenX states that Google alerted it in October 2018 and that "OpenX never used the BSSID to derive location", according to its blog.
Operating systems then closed the easy route. Android 8.0 required location permission for scan results, Android 9 throttled scanning to four requests per two minutes in the foreground, and Android 10 additionally requires location services switched on; denied those conditions, the platform returns a masked 02:00:00:00:00:00. Apple has required location authorisation since iOS 13, and Windows gates the field behind consent.
Origin and evolution
Skyhook Wireless, founded in Boston in 2003 by Ted Morgan and Michael Shean, built the first commercial database by wardriving across North America and Europe with laptops and antennas. By the time Apple shipped the technique on the original iPhone, the company claimed more than 23 million mapped access points. Apple moved to its own database with iPhone OS 3.2 in April 2010.
Collection at scale produced the first scandal that year. Street View vehicles had recorded network identification data from early 2008 until March 2010, and captured payload traffic from unencrypted networks as well. The Federal Communications Commission fined Google $25,000 in 2012 for obstructing its inquiry, 38 states and the District of Columbia settled for $7 million on March 12, 2013, and a private action closed at $13 million in 2019.
An opt-out followed, of a peculiar kind. After a Dutch data protection ruling in August 2011 obliged Google to offer one, the company announced on November 15, 2011 that owners could exclude an access point by appending the string _nomap to the network name. Peter Fleischer, then global privacy counsel, wrote that the method "provides the right balance of simplicity as well as protection against abuse", according to the announcement. Apple adopted the convention in March 2024, thirteen years later.
Why it matters for the marketing community
The field now appears by name in American enforcement orders. The stipulated order closing the Commission's Kochava case, signed on May 4, 2026, defines precise location data to include location inferred from network names, identifiers and Bluetooth receivers, excluding only data no finer than a 1,850 foot radius. The January 2024 order against InMarket Media used the same definition and required an assessment programme confirming that applications carrying its library had obtained informed consent. Draft federal legislation follows, with the SECURE Data Act treating precise geolocation as sensitive data at a radius of 1,750 feet.
Buyers reach for the signal because the alternatives are weak. FreeWheel argued in February 2026 that IP-based targeting can miss 87% of households, and Adstra and InterMedia Advertising found in July 2026 that 23% of residential addresses reached the intended geographic target.
Consent obligations follow the data rather than the vendor. Orders against tracking SDK suppliers push verification back to whoever collected the signal, making the buy-side question not whether a location segment is accurate but where the permission behind it was captured. The Commission has separately warned that hashing an identifier does not make it anonymous, and the resulting datasets are documented as reaching immigration enforcement.
Limitations and disputes
Mapping databases go stale. Routers are replaced, moved and carried on holiday, and a travel router at a new location keeps the identity it had at the old one. The opt-out compounds the problem by requiring the owner to rename the network, forcing every saved device in the household to be reconfigured, and by binding only the operators who choose to honour a string in a name they do not control.
The design's failure mode was demonstrated publicly. Erik Rye and Dave Levin of the University of Maryland reported in 2024 that Apple's unauthenticated interface answered addresses generated at random inside allocated manufacturer blocks. Roughly three million queries returned close to 490 million geolocations, and a year of collection covered more than two billion access points, enough to track Starlink terminals in Ukraine and the disappearance of networks across Gaza. SpaceX randomised the identifiers on its terminals; Apple added the opt-out.
Not the same as
An SSID is the network name, up to 32 octets, chosen by the owner and shared by every access point in an extended service set. Forty access points in an office share one name and carry forty distinct addresses.
A MAC address on a client device serves the same purpose from the other side of the link, but phones have randomised theirs for years, a defence access points mostly lack.
An IP address identifies a connection rather than a radio, is assigned by an operator, and changes without the hardware moving.
GPS coordinates are a measurement of where a device is. A router identifier is a reference to a place already measured by somebody else, which is why it works indoors and why it can be wrong for years without anyone noticing.
Recent developments
Connected television has become the growth surface. Gamers Nexus published packet captures on September 12, 2026 showing an LG set sending the signal strength of a nearby access point to an Alphonso server while connected over HDMI and used as a computer monitor, alongside city, coordinates, time zone and nearest major road, twenty times a minute. The researcher known as uturn expects an identifier plus a signal reading to yield near pinpoint location, against the five-mile accuracy the set received. The preceding investigation documented the same model reading neighbouring network names and access point addresses on hardware with no satellite receiver. LG says the claims are untrue, and none of it has been tested in court.
A 2025 paper extracted identifiers from photographs in online hardware auctions, geolocating routers before their new owners had switched them on.
Timeline
- 2003: Skyhook Wireless is founded in Boston and begins mapping access points by wardriving
- January 2008: Apple ships Wi-Fi positioning on the iPhone using Skyhook's database, then reported at more than 23 million access points
- Early 2008 to March 2010: Google Street View vehicles collect network identification data and unencrypted payload traffic
- April 2010: Apple switches to its own location database with iPhone OS 3.2
- August 2011: The Dutch data protection authority obliges Google to offer an opt-out for router data
- November 15, 2011: Google introduces the _nomap suffix and asks other providers to honour it
- April 2012: The FCC fines Google $25,000 over its conduct during the Street View inquiry
- March 12, 2013: Google settles with 38 states and the District of Columbia for $7 million
- June 2016: The FTC settles with InMobi over inferring location from nearby networks despite denied permissions
- 2017 to 2019: Android 8.0, 9 and 10 progressively gate scan results behind location permission, throttling and a system setting
- October 2018: Google notifies OpenX that its Android library is collecting router identifiers
- September 2019: iOS 13 requires location authorisation to read network identifiers
- December 15, 2021: OpenX settles with the FTC for a $7.5 million civil penalty, $2 million payable
- January 2024: The FTC moves to bar InMarket Media from selling precise location data
- March 2024: Apple adds support for the _nomap opt-out
- May 2024: Rye and Levin publish an attack recovering more than two billion access point locations from Apple's positioning interface
- June 2025: Researchers geolocate routers using identifiers read from online auction photographs
- May 4, 2026: The FTC's Kochava order defines precise location to include location inferred from network identifiers
- September 12, 2026: Packet captures show an LG television reporting access point signal strength to its advertising subsidiary
Related PPC Land coverage
- LG TV sent street-level location to its ad arm 20 times a minute over HDMI - Packet captures showing router identifiers and signal strength leaving a set used only as a monitor.
- One LG TV mapped 38 devices on the network it was plugged into - The investigation that documented neighbouring network names supplying geolocation without a satellite receiver.
- Explaining OpenX - The December 2021 FTC settlement covering router identifier collection from opted-out Android users.
- FTC closes Kochava location data case with strict consent rules - The order text defining precise location data to include inference from Wi-Fi identifiers.
- FTC to ban InMarket Media from selling or licensing any precise location data - The January 2024 action and its SDK supplier assessment requirement.
- Explaining tracking SDK - How third-party libraries collect device and network signals, and the consent rules attached to them.
- Explaining bidstream - What travels in a bid request once location has been resolved to coordinates.
- Explaining footfall attribution - Accuracy ranges by location source and how OpenRTB carries geographic data.
- Explaining device graph - The household resolution problem and published accuracy figures for IP-based alternatives.
- W3C updates Geolocation API standard - Browser-side location, its permission model and the sources implementations draw on.
- House Republicans unveil SECURE Data Act to replace US state privacy laws - Federal treatment of precise geolocation as sensitive data at a 1,750 foot radius.
- FTC warns: hashed data not anonymous - Why hashing an identifier does not remove it from the definition of personal data.
- ICE wants ad tech companies to help with surveillance investigations - Where advertising location products meet government demand.
Summary
Who. Access point manufacturers assign the values; Apple, Google and formerly Skyhook operate the databases mapping them to coordinates; application developers and SDK suppliers collect them; data brokers and demand-side platforms transact on the location derived from them; the Federal Trade Commission and state regulators police the consent behind it.
What. The 48-bit hardware address identifying one wireless network at one access point, broadcast continuously in 802.11 management frames and usable as a geographic landmark because it is unique, stable and tied to a fixed building.
When. Defined in the original 802.11 standard, commercialised for positioning from 2003, mapped at global scale from 2008, restricted by mobile operating systems between 2017 and 2019, and written into United States enforcement orders from 2021 onward.
Where. In the air around every router, in the positioning databases operated by the two dominant handset platforms, inside mobile SDKs and smart television firmware, and, once converted to coordinates, in bid requests.
Why. Satellite positioning fails indoors and IP addresses resolve poorly to households, so an identifier that any nearby device can read without permission became the most practical way to locate a person precisely. That same property is why it is now regulated as sensitive data rather than as network configuration.
Discussion