A USB Wi-Fi card on a Mac, with no driver.
RadAir now drives an ALFA AWUS036AXML — a MediaTek MT7921AU Wi-Fi and Bluetooth card — directly from its own process. The card listens in monitor mode and never transmits. This note says what that took, what it changes for the console, what it heard in one office test, and what has not been verified.
What was done
macOS has no driver for this chip, and RadAir does not need one. A helper bundled with the application claims the card as a plain USB device over libusb, uploads the chip's firmware, and talks to it directly. No kernel extension, no DriverKit, no virtual machine, no root. The control sequences are ported from the Linux mt76 and btmtk drivers. The firmware is MediaTek's and is fetched separately; RadAir does not ship it.
The card has two halves, and both are driven. The WLAN half runs in monitor mode, receive only. The Bluetooth half is brought up the same way — firmware download, enable, then ordinary HCI — and reports itself as Bluetooth 5.3 with LE Coded PHY.
What the card hears
The Wi-Fi half sweeps all 13 channels of 2.4 GHz and 24 channels of 5 GHz at 20 MHz, 250 ms on each. One full pass takes about 20 s, and roughly half of that is the chip switching channels rather than listening. Each access point is reported from its own channel, as announced in its beacon, with its SSID — hidden networks are kept, as hidden — BSSID, a level from the chip's RCPI, security and PHY generation. The observations land in the same session journal, map and tables as the built-in card's, marked with the receiver that heard them.
The Bluetooth half runs a passive extended LE scan on the 1M and Coded (Long Range) PHYs, alongside the Wi-Fi sweep without slowing it. In the office it collected 273 advertising reports from 17 devices in 15 s, none of them on Coded PHY. Ordinary BLE devices from the card are deliberately not added as observations — the Mac's own Bluetooth already lists them. The card's Bluetooth is there for Remote ID and Long Range.
Why it matters for RadAir
The console can now listen without transmitting on Wi-Fi. The built-in card scans through CoreWLAN, and every such scan sends probe requests and briefly interrupts the Mac's own Wi-Fi link. With the USB card running, RadAir pauses the built-in scan by default — always, only when the card is not running, or never, as the operator chooses — and the pause is written into the journal as a stop, not a gap.
It also reaches more of the 2.4 and 5 GHz layer. This is protocol-level reception — decoded frames, not spectrum energy — so it complements the RTL-SDR, whose tuner stops at 1.766 GHz, without replacing what a wideband receiver would do there. An analogue video link or a non-Wi-Fi control link on 2.4 or 5.8 GHz is still out of reach.
And Remote ID now arrives on four transports instead of one: BLE legacy advertising through the Mac's Bluetooth as before, and through the card Wi-Fi Beacon, Wi-Fi NAN service discovery and Bluetooth 5 Long Range advertising. NAN discovery lives on channel 6, which is why the sweep goes back there three extra times per pass. All four paths feed one decoder and one tracker. None of them has yet received a real Remote ID transmitter — they are exercised against synthetic frames in the test suite, and no drone broadcasting Remote ID has been in range.
Measured in the office
Same place, same two minutes, the USB card with a small stock antenna — the two-lead dual-band antenna that ships with desktop motherboards, on both of the card's connectors — against the MacBook's built-in Wi-Fi through CoreWLAN. An earlier version of this note said the card had no antenna; it had this one. Levels are as each chip reports them, uncalibrated.
| USB card, small stock antenna | Built-in Wi-Fi | |
|---|---|---|
| BSSIDs heard | 24 | 16 |
| Heard by both | 16 — every BSSID the built-in card heard | |
| Heard only by this receiver | 8 — among them 4 hidden BSSIDs of a mesh at −37 to −75 dBm and 4 networks at −98 to −100 dBm | 0 |
| Median level, card − built-in | −1.5 dB on 2.4 GHz · −0.5 dB on 5 GHz, over the shared BSSIDs | |
| Transmits while scanning | Nothing | Probe requests on every scan |
One built-in reading was excluded: −47 dBm for a BSSID whose sibling BSSIDs read −74, which is the Mac reporting its own association link rather than a beacon. One room and one pair of receivers is a comparison, not a characterisation.
Comparing antennas
A small stock antenna is a floor, not a configuration. A first try with a better antenna on a single lead showed why the comparison has to be like for like: the card has two receive chains, and an antenna on one of them gives up the second chain. RadAir now has a built-in antenna test: N full sweeps per antenna set while parked, compared network by network on the networks both runs heard, as a median of B − A per band. An optional repeat of the first set measures how much the same set drifts on its own; a difference within that drift, or within 1 dB, is reported as no difference. Under five shared networks there is no verdict, and a run that moved more than 30 m is flagged. It has not yet been used in the field.
What is not verified yet
- Remote ID on air. All four transports are implemented and tested on synthetic frames; none has received a real transmitter.
- 6 GHz. The chip supports it and the band is selectable, but no 6 GHz network was in range. Channel 149 and the 6 GHz channels stayed silent in the office; whether nothing transmits there or a regulatory-domain command is missing is not yet known.
- Client devices. Monitor mode exists now, but station capture is not built. RadAir still observes access points only, so a camera attached to a router as an ordinary client remains invisible.
- Long Range in practice. The Coded PHY scan runs; in the office test it received no Coded PHY report.
- Breadth. One adapter, one Mac, one office comparison. 20 MHz channels only. The antenna test has not yet been run in the field.
- Levels. Relative and uncalibrated, as everywhere else in RadAir.