An ncurses picker for raw wpa_supplicant. Launch, scan, arrow to a network, connect. No NetworkManager, no iwd, no dependencies beyond ncursesw -- it speaks the daemon's control protocol directly over its Unix datagram socket.
Born out of the discovery that every existing Wi-Fi TUI sits on a network-management daemon and raw wpa_supplicant has none.
OTHER NETWORK MANAGERS CONNECT YOU POLITELY, LIKE CLERKS. WIFISH IS THE FIRST AND ONLY WI-FI PICKER WITH A FULLY INTEGRATED TAUNTING ENGINE!
- ROTATING COMBAT TAUNTS ON EVERY SCAN AND EVERY ASSOCIATION ATTEMPT!
- AUTHENTICATION FAILURES MET WITH THE CONTEMPT THEY DESERVE! ("HOW APPROPRIATE, YOU AUTHENTICATE LIKE A COW!")
- FLEEING THE PASSPHRASE PROMPT GOES ON YOUR PERMANENT RECORD, SIR ROBIN!
- DETERMINISTIC ROTATION! NO RNG! EVERY INSULT GETS ITS TURN AND A SESSION REPLAYS BYTE-IDENTICALLY! THE VERIFICATION DOCTRINE APPLIES TO TRASH TALK!
- ZERO CONFIGURATION! ZERO OPT-OUT! YOU WILL BE TAUNTED, AND YOU WILL BE BETTER FOR IT!
ASK YOUR DOCTOR IF WIFISH IS RIGHT FOR YOU! OFFERED IN LOVING MEMORY OF THE SCUMM BAR! NO ACTUAL PIRATES WERE QUOTED! THE HOMAGE IS ORIGINAL AND THE SWORDFIGHTING IS ALL YOURS!
wifish COMPLETED on MeleeIsland
────────────────────────────────────────────────────────────────────────────────
ssid sec band signal
MeleeIsland wpa 2.4/5 100% -37 dBm
ScummBar wpa 2.4 60% -70 dBm
LeChucksRevenge wpa 2.4 44% -78 dBm
BigWhoop-Guest open 2.4 26% -87 dBm
────────────────────────────────────────────────────────────────────────────────
scan complete -- 4 foes revealed
────────────────────────────────────────────────────────────────────────────────
S scan Enter details C connect A enable all Esc/Q quit
The selected row renders reverse-video in the flesh, and Enter frames the network's individual radios in a centered popup. Any resemblance to actual networks, living or unplugged, is purely coincidental.
wpa_supplicant with the control interface enabled and writable by your group:
ctrl_interface=DIR=/run/wpa_supplicant GROUP=wheel
update_config=1
meson setup build
ninja -C build
./build/wifish # first non-p2p interface, TUI
./build/wifish -i wlan0 # explicit interface
./build/wifish --dump # scan and print, no TUI (oracle/debugging)
Keys (either case): S scan, arrows or j/k move, Enter per-BSSID
details in a centered popup, C connect -- from the list or from the
popup -- asking for a passphrase only when the network needs one, A
re-enable all saved networks (connecting disables the others, on
purpose), Esc/Q quit. While the popup is up all other keys are
inert except for navigation: Left/Right or h/l selects a radio;
Up/Down or j/k scrolls its details. PageUp/PageDown and Home/End
also scroll. Enter/Esc/Q closes it. C still connects to the network;
it does not pin the connection to the displayed radio.
The popup identifies each radio independently, using its cached
BSS <BSSID> advertisement from wpa_supplicant. No association, packet
capture, online lookup, or additional library is needed. Details are fetched
when you first view a radio and refreshed when you reopen the popup.
It shows:
- Likely device type, vendor, advertised model/model number, and inferred OS family when an advertised phone/tablet identity supports it. Otherwise these fields remain unknown; firmware versions are not inferred.
- Readable advertised security, ciphers, WPS presence, management-frame protection, and the newest advertised n/ac/ax/be capability.
- A trust preference, identification confidence, and the evidence used.
Trust follows the owner's preference for institutional networks over
personal hotspots. Phone/tablet identities and the common AndroidAP name
prefix suggest Low - personal hotspot. An airport word in the SSID
suggests Preferred - institutional network, with greater confidence
when an infrastructure vendor or WPS device category corroborates it.
Generic infrastructure and ambiguous public hotspots remain unclassified.
Phone evidence takes precedence over an airport name. Apple AirPort hardware
is recognized separately from the airport-name hint.
Confidence describes the identification: advertised phone or infrastructure categories/models rank above MAC-vendor and name hints. An Apple vendor advertisement together with a locally administered MAC suggests an Apple personal hotspot at medium confidence unless WPS identifies infrastructure or an AirPort model. This is a heuristic, not a promise to recognize every iPhone or Android release. Network names, device attributes and MACs can all be copied; the trust label is a best-effort preference, not authentication or a security guarantee. Encryption is reported separately and does not promote a network.
Vendor lookup optionally reads the installed IEEE-format database at
/usr/share/hwdata/oui.txt or /usr/share/ieee-data/oui.txt. Its existing
package supplies updates; wifish does not download or maintain a copy.
Missing databases are harmless. Locally administered addresses are never
looked up as manufacturer prefixes; vendor/WPS advertisements can still
identify them. The allocation owner is not necessarily the retail brand.
Decoder references: wpa_supplicant control interface, WPS attributes, and 802.11 fields. The Apple heuristic is informed by the vendor-advertisement observations in ACSAC 2016 research; an Apple vendor identifier alone is deliberately insufficient.
Scope, deliberately: open and WPA-PSK networks only. No EAP/enterprise, no hidden SSIDs, no saved-network editing -- wpa_cli exists.
ninja -C build test runs the reply parsers against pinned wire
formats, including RSN/WPS decoding, malformed and fragmented information
elements, and ambiguous device identities. A scripted ncurses popup test
uses a synthetic control socket to check independent radio identities,
caching, scrolling, resize, unavailable details, and passphrase cancellation.
./build/wifish --dump diffs against wpa_cli scan_results,
the reference implementation on every box this runs on.