Live data from Hacker News

Tile's security is so bad it's a feature for stalkers

blog.adafruit.com

21–30 of 51 posts

Re: Tile's security is so bad it's a feature for stalkers

#21
post #12

I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?

Criminals, particularly heavily disordered ones like stalkers, are usually not the smartest people in the world. So increasing the barrier of entry just a little bit might substantially decrease their practical access to this type of technology.

Re: Tile's security is so bad it's a feature for stalkers

#23
It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model.

> Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag

Though it makes me wonder... What's the private key? If the public key is attached to the tag, how is the device getting it? I'm guessing it gets shared during pairing.

Re: Tile's security is so bad it's a feature for stalkers

#24

It isn't that difficult to just not lose things. People love to over complicate their lives with technology, giving up money and privacy in the process.

There are plenty of times when you have to trust someone(s) else with your belongings, sometimes for a very long time - say, airline baggage, bus luggage compartment, hotel left luggage, or gym lockers - and it's useful to have a tracker (ideally a more secure one, e.g. AirTag) in case anything goes wrong.

And even if you're the type of person who never lets their bags leave their sight, nobody is immune to their keys slipping out of their pocket in a taxi.

Re: Tile's security is so bad it's a feature for stalkers

#25

BBP;DR (Broken Bot Protection; Didn't Read) Loops forever at blog.adafruit.com Performing security verification This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

I never understood this. You can pass turnstile challenges on tor browser in a linux/windows VM, of all things. What unusual browser config are people using to trigger a block?

Re: Tile's security is so bad it's a feature for stalkers

#26
post #12

I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?

Criminals, particularly heavily disordered ones like stalkers, are usually not the smartest people in the world. So increasing the barrier of entry just a little bit might substantially decrease their practical access to this type of technology.

[dead]

Re: Tile's security is so bad it's a feature for stalkers

#27
post #25

BBP;DR (Broken Bot Protection; Didn't Read) Loops forever at blog.adafruit.com Performing security verification This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

I never understood this. You can pass turnstile challenges on tor browser in a linux/windows VM, of all things. What unusual browser config are people using to trigger a block?

I use a DPRK VPN

Re: Tile's security is so bad it's a feature for stalkers

#28
post #23

It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model. > Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag Though it makes me wonder... What's the private key? If the public key is attached to the tag, how…

In general, yes! We did some follow on work explaining how all of this works, depending on the provider: https://petsymposium.org/popets/2026/popets-2026-0113.pdf

Re: Tile's security is so bad it's a feature for stalkers

#29
post #15

Earlier quoted context omitted.

Because it serves a nefarious purpose: to smear the company that makes these devices. I would not be surprised if this is part of some kind of campaign designed to restrict or damage someone.

You went straight to conspiracy?

The title obviously has a slant, because the text of the article doesn't support it. So, yeah, I'm saying the title has a specific goal in mind.

Re: Tile's security is so bad it's a feature for stalkers

#30
post #23

It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model. > Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag Though it makes me wonder... What's the private key? If the public key is attached to the tag, how…

In general, yes! We did some follow on work explaining how all of this works, depending on the provider: https://petsymposium.org/popets/2026/popets-2026-0113.pdf

Very cool! I only skimmed Section 4 a bit, but that's really cool!

I was going to ask how the web UIs possibly work if the location is indistinguishable, but I went to the Google Find Hub, and it appears you can't view the location for tags unless you enter your phone's pin code / pattern lock. This must either communicate with the phone or the keys are stored on Google's end.

EDIT: I turned my phone off, and I can still get the location of my keys... surely this doesn't mean the key is stored on their end? Wouldn't be very good E2EE in that case :)

Post reply on HN