Tile's Security Is So Bad It's a Feature for Stalkers

I investigated the security flaws in Tile tracking devices and found that their design choices inadvertently enable stalking. The lack of robust verification allows anyone to track a lost item indefinitely, turning a helpful feature into a dangerous tool for harassment. This systemic vulnerability highlights how poor security practices can have severe real-world consequences for users.

Tile's security is so bad it's a feature for stalkers.
  1. mspecter

    Last author on the paper here (https://arxiv.org/pdf/2510.00350). Happy to answer any questions!

  2. ollien

    It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model.

    > Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag

    Though it makes me wonder... What's the private key? If the public key is attached to the tag, how is the device getting it? I'm guessing it gets shared during pairing.

  3. zidel

    Paper: https://arxiv.org/abs/2510.00350

  4. alt227

    I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?

  5. kefabean

    Does anyone know whether https://mygrid.app/ is trustworthy? Development had been glacial, but looking at their website it seems they finally support degoogled android which is a huge step forwards.

More from this day

2026-07-25