Tile security flaws enable stalking – research paper and community discussion
Tile security flaws enable stalking – research paper and community discussion
Overview
Tile’s security is so weak that it can be used for stalking, as highlighted by a research paper and discussed on Hacker News.
Paper Findings
A paper posted on arXiv (ID 2510.00350) analyzes Tile’s security and concludes that its design allows location tracking without adequate protection. The last author of the paper commented on the HN thread, offering to answer questions.
Last author on the paper here ( https://arxiv.org/pdf/2510.00350 ). Happy to answer any comments!
Community Reaction
Commenters noted that competing trackers from Apple and Google use end‑to‑end encryption to protect location data, while Tile does not appear to employ similar measures.
It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model. > Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag Though it makes me wonder... What's the private key? If the public key is attached to the tag, how is the device getting it? I'm guessing it gets shared during pairing.
Some users pointed out that cheap GPS trackers sold on sites like Temu are explicitly designed for stalking, questioning why an attacker would bother hacking a Tile when purpose‑built devices are readily available.
I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?
Discussion also touched on Tile’s terms of service, which claim to fine stalkers a million dollars, a provision viewed as ineffective or merely a deterrent.
"But, but, the Tile TOS says they'll fine a stalker a million dollars!" Life360 is such a skeevy bullshit company.
Other comments expressed confusion about what Tile is, indicating that the brand is not universally known.
What the hell is Tile?
Implications
The consensus in the thread is that Tile’s lack of strong cryptographic protections makes its devices unsuitable for scenarios where location privacy is critical, and that the ease of misuse outweighs any purported legal deterrents in its terms of service.