Live data from Hacker News

Tile's security is so bad it's a feature for stalkers

blog.adafruit.com

31–40 of 51 posts

Re: Tile's security is so bad it's a feature for stalkers

#31

Last author on the paper here ( https://arxiv.org/pdf/2510.00350 ). Happy to answer any questions!

Thanks! Have you considered evaluating the “AppClose” platform in a similar fashion? It is used in family / civil cases to my knowledge. Perhaps another worthwhile avenue of study, perhaps not. Thank you for your time.

Re: Tile's security is so bad it's a feature for stalkers

#32
post #12

I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?

Suppose the person you want to stalk has bought a Tile that they use for themselves, not knowing that these devices are insecure. If you scan for that device, you can follow that person without even having to plant a device on them. You don't have to hack their Tile.

Re: Tile's security is so bad it's a feature for stalkers

#33

Last author on the paper here ( https://arxiv.org/pdf/2510.00350 ). Happy to answer any questions!

Thanks! Have you considered evaluating the “AppClose” platform in a similar fashion? It is used in family / civil cases to my knowledge. Perhaps another worthwhile avenue of study, perhaps not. Thank you for your time.

Interesting! Hadn't heard of it.

Re: Tile's security is so bad it's a feature for stalkers

#34
post #10

This explains why I'm seeing commercials for Life360 now for the first time ever: They've developed a new revenue stream by selling everybody's location to advertisers. Now deleted from my family's phones.

Whats the connection between an advertiser knowing your location, and ads from Life360?

Life360 increases their marketing budget when they have a profitable way to sell user data so they can get the devices into the hands of more target users.

Re: Tile's security is so bad it's a feature for stalkers

#35
post #29

Earlier quoted context omitted.

You went straight to conspiracy?

The title obviously has a slant, because the text of the article doesn't support it. So, yeah, I'm saying the title has a specific goal in mind.

The text seems to support it to me, but more importantly "saying the title has a specific goal" isn't answering the question. Yes the title is calling out the company. What takes you from there to some kind of broader campaign.

Re: Tile's security is so bad it's a feature for stalkers

#36

Last author on the paper here ( https://arxiv.org/pdf/2510.00350 ). Happy to answer any questions!

Also, I'm just the professor, the grad students on it are the real heroes: Akshaya Kumar [1] and Anna Raymaker [2].

[1] https://akumar805.github.io/

[2] https://annaraymaker.dad/

Re: Tile's security is so bad it's a feature for stalkers

#37
post #12

I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?

In that case you have to plant the transponder yourself.

In the case of Tile, everyone using Tile has tagged themselves (unknowingly) for you.

The consumer who didn't know they tagged themselves would understandably have a complaint.

Re: Tile's security is so bad it's a feature for stalkers

#38
post #12

I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?

Criminals, particularly heavily disordered ones like stalkers, are usually not the smartest people in the world. So increasing the barrier of entry just a little bit might substantially decrease their practical access to this type of technology.

[deleted]

Re: Tile's security is so bad it's a feature for stalkers

#39
post #23

It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model. > Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag Though it makes me wonder... What's the private key? If the public key is attached to the tag, how…

AFAIK, there's a pre-shared key exchanged during pairing, and you then calculate keypairs based on (key, timestamp).

Rotating your keypairs in that way prevents attackers from identifying you across time. E.G. if they link a particular keypair to you — let's say at an Airport security gate — that doesn't let them know you've entered a lawyer's office a week later, because that's done under a different, unrelated public key.

Re: Tile's security is so bad it's a feature for stalkers

#40

BBP;DR (Broken Bot Protection; Didn't Read) Loops forever at blog.adafruit.com Performing security verification This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

> Loops forever

And so it should, given:

> while the website verifies you are not a bot.

is impossible to complete.

Post reply on HN