- › SignalTrace, an add-on for automated license plate readers, captures the Bluetooth, Wi-Fi, and RFID signals broadcast by devices in a passing vehicle.
- › It converts those into unique identifiers and binds them to the plate, joining two databases that used to be separate.
- › The capture reaches phones, smartwatches, wireless earbuds, fitness trackers, car infotainment, AirTags, and pet trackers.
- › There is no federal statute squarely governing roadside collection of wireless identifiers, no notice, and no way to opt out while driving past.
- › The Supreme Court held in June 2026 that obtaining location data is a Fourth Amendment search, which addresses the government's use and not the commercial collection.
For years the advice given to anyone with a real reason to be careful came down to one sentence. Leave the phone at home.
Domestic violence advocates said it. Journalists said it to sources. Executive protection teams said it before sensitive movements. It was inconvenient and it worked, because the phone was the tracker and everything else you carried was inert.
That sentence stopped being true.
A product called SignalTrace, built by Leonardo as an add-on to the automated license plate readers already mounted on poles and patrol cars, captures the wireless signals your devices broadcast as you drive past. Bluetooth, Wi-Fi, radio frequency identification. It converts them into unique digital fingerprints and ties those fingerprints to the plate of the car they were traveling in. 404 Media reported it first, in June.
The list of what broadcasts is longer than most people think. Your phone. Your smartwatch. Your wireless earbuds. Your fitness tracker. The car’s own infotainment system. An AirTag in the glovebox. The tracker on your dog’s collar. A key fob with a Bluetooth chip in it.
You do not have to unlock anything. You do not have to connect to anything. You drive past a camera and your devices announce themselves, because announcing themselves is what they are built to do.
What Changed Is the Join
Plate readers were already a problem, and we wrote about the litigation building around them a couple of weeks ago. A network of cameras logging where a car was and when is a serious capability on its own.
But a plate is a car. It is not a person. That gap is small and it has been doing real work.
Two people share a vehicle and the plate cannot tell them apart. You borrow your sister’s car. You take a rideshare. You buy the car used and inherit six years of somebody else’s history attached to the plate. Every one of those introduced enough doubt that a plate hit alone rarely proved much about a specific human being.
Fingerprinting the devices closes that gap. The phone in the passenger seat is a person, not a vehicle, and it keeps its identifier when it gets out of the car and walks into a building with its own scanner, or past a different camera in a different city three weeks later.
The two databases used to be separate. Now they have a join key.
Nobody Consented and Nobody Can Decline
No federal statute squarely governs roadside collection of wireless device identifiers. Nothing requires notice. There is no opt-out, because the capture happens as you drive by, and the only way to refuse is to leave every powered object you own at home.
The Supreme Court held in Chatrie in June that obtaining location data constitutes a Fourth Amendment search. That decision matters and it addresses the government compelling data. It does not reach a company that collects signals from public air and sells access, and it does not reach a police department that buys the product rather than demanding the records.
I want to be careful here, because I am not arguing that plate readers should not exist. They solve real cases and I have sat with people who got answers because of one. What I am arguing is narrower and I think it is unavoidable: a capability this comprehensive arrived with no notice requirement, no retention limit, and no mechanism for a person to find out they are in it. Those three absences are choices, and they were made by nobody in particular.
Who This Actually Costs
Security writing tends to describe surveillance as a general condition, which is a way of describing it as nobody’s specific problem. Let me be concrete about who is standing in front of this.
Start with the woman who moved and did not tell anyone where. Her car is new to her, so the plate is clean. Her phone is new too. But she kept the earbuds, and she kept the watch her sister gave her, and both of those have been broadcasting the same identifier since before she left.
Protection details run into a version of it too. Vary the route, change the vehicle, do everything right, and the watch on the principal’s wrist ties the new car to the old one on the first pass.
I find the whistleblower case the hardest to sit with, because he is doing everything he was told. He drives instead of badging in. He does not call anyone. Nobody ever mentioned that the infotainment system in the car has been announcing itself at every intersection since he bought it.
All three did the careful thing. The advice failed them because it was written for a world where one device was the risk.
What Still Works
The honest answer is that less works than did, and I would rather say that than sell you a fix.
Airplane mode is weaker than people assume
On plenty of hardware Bluetooth stays available, and a device that has been paired will still advertise. If the device matters, it needs to be off, and on some hardware it needs to be in a bag that blocks signal.
Randomized addresses help, and only partly
Modern phones rotate their Bluetooth identifiers, which was designed for exactly this. Accessories are worse at it, older devices are worse at it, and a car’s infotainment system is generally the worst of all. The weakest broadcaster in the vehicle sets your exposure.
Audit the car, not only the person
Most people can list their devices and almost nobody can list their car’s. Infotainment, factory telematics, a tire pressure system, whatever tracker was left in a bag in the trunk. That inventory is the actual attack surface and hardly anyone has done it.
Give this to physical security
If you run executive protection, or you employ people whose home addresses are protected, this is now a threat-model input rather than a privacy nicety. The countermeasure is procedural: what gets carried, what gets left, what gets powered off, and who checks.
Ask your vendors what they bought
If your organization operates plate readers on your own property, in a parking structure or a campus, find out whether the system you own has this capability or is being offered it. You may already be collecting more than you intended, which is a liability you did not price.
The Thing I Keep Returning To
The trade we were offered was legible. A camera photographs a plate, a plate belongs to a car, and a car is not a person. Everybody understood the terms well enough to make a decision about them.
Adding the device layer changed the terms and nobody was asked. There was no vote, no notice period, no disclosure at the point of collection. The capability simply became available, got sold to agencies with budgets, and started running.
Go stand next to your car and count the things on you and in it that are broadcasting right now. Most people get to four before they stop being sure.
Grab The Axe runs converged physical and information security assessments for organizations and individuals whose location is a safety matter. Take our free Human Attack Surface Score assessment, or contact us for a full risk assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Author Page →