On Thursday, Jeff Geerling — the engineer behind the popular Geerling Engineering channel — published a demonstration of QuadRF, a handheld phased-array software-defined radio built around a Raspberry Pi 5 and a custom FPGA board. The device, which Geerling estimates can be assembled for roughly $200 in parts, does two things that would have required a six-figure government contract a decade ago: it pinpoints drones in flight by locking onto their video transmission signatures, and it maps WiFi networks through solid walls using picosecond-level timing to measure signal reflections.
The Hacker News thread hit 709 points within hours. The comments split along familiar lines: half marveling at the technical achievement, half worrying about what a bad actor might do with wall-penetrating RF vision.
Both reactions miss the more interesting story. While the Federal Aviation Administration and the Federal Communications Commission have spent years building a regulatory apparatus to control what flies, the ability to see what flies has quietly escaped the regulatory perimeter entirely. QuadRF is not a privacy problem. It is a regulatory asymmetry problem — and the gap is about to get wider than the policy world understands.
The FAA Is Still Arguing About Where Drones Can Fly
On May 6, the FAA published its long-awaited notice of proposed rulemaking to implement Section 2209 of the 2016 FAA Extension, Safety, and Security Act. The rule would let owners of critical infrastructure — power plants, refineries, stadiums — apply for permanent drone flight restrictions over their facilities. The comment period runs through August, and the usual stakeholders are doing the usual dance: industry groups want broader restrictions, commercial drone operators want narrower ones, privacy advocates want something else entirely.
Meanwhile, the FCC is wrestling with spectrum allocation for drone operations and the legal ambiguities around counter-drone technologies. In May, Texas Attorney General Ken Paxton announced an investigation into a drone wholesaler over alleged data-privacy misrepresentations and concealed ties to China — part of what his office described as a broader effort to “protect Texans from foreign adversaries that seek to exploit technology for surveillance and data collection.”
Notice the pattern. Every regulatory intervention assumes the same architecture: drones are operated by someone, and the job of the state is to control that someone — through flight restrictions, spectrum licenses, supply-chain reviews, or consumer-protection lawsuits. Detection is something the authorities do, using tools the rest of us don’t have.
Detection Escaped the Regulatory Perimeter
QuadRF makes that assumption look quaint. For $200 and an afternoon of assembly, anyone can now run a passive RF survey of their airspace and log every drone that passes within range — no transmitter, no license, no interaction with the drone or its operator. The device doesn’t jam, spoof, or interfere. It just listens.
And because it’s passive, it falls into a regulatory near-vacuum. The FCC regulates transmitters. The FAA regulates aircraft. Neither has much to say about a device that merely observes the electromagnetic spectrum from your own backyard.
This is not a loophole someone forgot to close. It’s a category error. The entire drone-regulation project was built on the premise that the operator-detector relationship would remain asymmetric in favor of the operator — that flying a drone would be a public act while detecting one would require specialized, regulated equipment. That premise held for years because phased-array direction-finding was genuinely hard and genuinely expensive. It no longer is.
As one spectrum-policy lawyer put it during a panel at this spring’s IEEE DySPAN conference, “We wrote the rules assuming the only people who could afford phased-array direction-finding were agencies with three-letter acronyms. That assumption expired sometime last Tuesday.”
The Coming Fight Over ‘Passive Surveillance’
If the detection side can’t be regulated through hardware controls — and with open-source designs circulating on GitHub, it can’t — the regulatory response will shift to restricting what you’re allowed to do with the information. Expect proposals to classify systematic RF environment mapping as a form of “passive surveillance” requiring authorization. Expect arguments that logging drone flight paths over private property constitutes unlawful interception of communications. Expect lawsuits testing whether a drone’s video downlink is a “readily accessible” radio transmission under the Wiretap Act.
Some of these arguments have merit. Some are stretches. What unites them is that they all target the use of information, not the possession of a device — a regulatory approach that is notoriously difficult to enforce and even more difficult to square with the First Amendment. You can own the thing. You just can’t act on what it tells you. That is a legally unstable position, and it will not hold.
The alternative — accepting that aerial surveillance detection is now a consumer capability and building policy around that reality — would require acknowledging that the FAA’s decade-long rulemaking process was solving yesterday’s problem. That is not something regulatory agencies are known for doing quickly, or voluntarily.
In the meantime, Jeff Geerling’s YouTube comments section will continue to fill with hobbyists posting screenshots of their neighbors’ WiFi signatures. The drones overhead are no longer invisible. The law just hasn’t figured out what to do about it yet.
Sources
- QuadRF can spot drones and see WiFi through my wall - Jeff Geerling
- QuadRF is a handheld phased array SDR that can see WiFi through …
- QuadRF is a phased array antenna that can see WiFi through walls …
- The Regulation of Private-Sector Drones | American Civil Liberties Union
- Citing National Security Needs, the FCC and FAA Take Steps on UAS Regulation | Insights | Holland & Knight
- Texas Attorney General Announces Investigation into Drone Company over Data Privacy, Surveillance Concerns | Data Privacy Dish