Tile's security is so bad it's a feature for stalkers

sambellll 154 points 43 comments July 25, 2026
blog.adafruit.com · View on Hacker News

Discussion Highlights (10 comments)

dreamcompiler

This explains why I'm seeing commercials for Life360 now for the first time ever: They've developed a new revenue stream by selling everybody's location to advertisers. Now deleted from my family's phones.

zidel

Paper: https://arxiv.org/abs/2510.00350

kefabean

Does anyone know whether https://mygrid.app/ is trustworthy? Development had been glacial, but looking at their website it seems they finally support degoogled android which is a huge step forwards.

octoberfranklin

BBP;DR (Broken Bot Protection; Didn't Read) Loops forever at blog.adafruit.com Performing security verification This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

kotaKat

"But, but, the Tile TOS says they'll fine a stalker a million dollars!" Life360 is such a skeevy bullshit company.

mawadev

What the hell is Tile?

alt227

I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?

user00005

It isn't that difficult to just not lose things. People love to over complicate their lives with technology, giving up money and privacy in the process.

mspecter

Last author on the paper here ( https://arxiv.org/pdf/2510.00350 ). Happy to answer any questions!

ollien

It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model. > Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag Though it makes me wonder... What's the private key? If the public key is attached to the tag, how is the device getting it? I'm guessing it gets shared during pairing.

Semantic search powered by Rivestack pgvector
14,850 stories · 138,743 chunks indexed