Live data from Hacker News

Tile's security is so bad it's a feature for stalkers

blog.adafruit.com

41–50 of 51 posts

Re: Tile's security is so bad it's a feature for stalkers

#41
post #30

Earlier quoted context omitted.

In general, yes! We did some follow on work explaining how all of this works, depending on the provider: https://petsymposium.org/popets/2026/popets-2026-0113.pdf

Very cool! I only skimmed Section 4 a bit, but that's really cool! I was going to ask how the web UIs possibly work if the location is indistinguishable, but I went to the Google Find Hub, and it appears you can't view the location for tags unless you enter your phone's pin code / pattern lock. This must either communicate with the phone or the keys are stored on Google's end. EDIT: I turned my phone off, and I can s…

The encryption key is derived from your PIN, it doesn't need to access the phone to do a new derivation.

Re: Tile's security is so bad it's a feature for stalkers

#42
post #29

Earlier quoted context omitted.

You went straight to conspiracy?

The title obviously has a slant, because the text of the article doesn't support it. So, yeah, I'm saying the title has a specific goal in mind.

I read the article. It absolutely does support the title. Unless you someone consider finger printable devices sending unencrypted location data somehow doesn't enable stalking

Re: Tile's security is so bad it's a feature for stalkers

#43
post #27
post #25

Earlier quoted context omitted.

I never understood this. You can pass turnstile challenges on tor browser in a linux/windows VM, of all things. What unusual browser config are people using to trigger a block?

I use a DPRK VPN

Is it actually in DPRK, or an unscrupulous operator that hosts the server outside DPRK, but hosts a puts fake information in the whois/geofeed?

Re: Tile's security is so bad it's a feature for stalkers

#45
post #42
post #29

Earlier quoted context omitted.

The title obviously has a slant, because the text of the article doesn't support it. So, yeah, I'm saying the title has a specific goal in mind.

I read the article. It absolutely does support the title. Unless you someone consider finger printable devices sending unencrypted location data somehow doesn't enable stalking

The article just say it's insecure, the title says that such security is a "feature for stalkers". I'm sorry, I don't see how insecurity makes it better for stalkers.

Re: Tile's security is so bad it's a feature for stalkers

#46
post #24

It isn't that difficult to just not lose things. People love to over complicate their lives with technology, giving up money and privacy in the process.

There are plenty of times when you have to trust someone(s) else with your belongings, sometimes for a very long time - say, airline baggage, bus luggage compartment, hotel left luggage, or gym lockers - and it's useful to have a tracker (ideally a more secure one, e.g. AirTag) in case anything goes wrong. And even if you're the type of person who never lets their bags leave their sight, nobody is immune to their key…

I'm arguing the tradeoff of possible convenience isn't worth it.

Tile is owned by Life360. The original article talks about Life360 selling your data to advertisers. Let's look at what the Tile app wants to collect from you: photos and videos, location, app activity, messages, personal info. They say 'no data is shared with third parties'. Does that include the parent company Life360 that does sell data with third parties?

https://play.google.com/store/apps/datasafety?id=com.thetile...

Re: Tile's security is so bad it's a feature for stalkers

#47
post #25

BBP;DR (Broken Bot Protection; Didn't Read) Loops forever at blog.adafruit.com Performing security verification This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

I never understood this. You can pass turnstile challenges on tor browser in a linux/windows VM, of all things. What unusual browser config are people using to trigger a block?

I frequently see the problem on Android running Brave with default filters. Unsure on cause - I just give up.

Re: Tile's security is so bad it's a feature for stalkers

#48
post #6

This explains why I'm seeing commercials for Life360 now for the first time ever: They've developed a new revenue stream by selling everybody's location to advertisers. Now deleted from my family's phones.

That was always the revenue stream, the devices were just a way to get you to give it to them. It's been a minute since I was current on who gets what in the HMD world but I think that data ultimately flows to Placer.ai

Not always. In the beginning it was supposed to be a freemium product, with all the revenue coming from subscriptions.

Re: Tile's security is so bad it's a feature for stalkers

#49
post #13
post #11

What the hell is Tile?

Thats what google is for.

It's a flat plate of material, typically a ceramic square with decorative finish, arranged in regular patterns as a floor or wall surface in rooms expected to be exposed to water, where it is bonded to a substrate with cementitious adhesive.

Re: Tile's security is so bad it's a feature for stalkers

#50
post #24

Earlier quoted context omitted.

There are plenty of times when you have to trust someone(s) else with your belongings, sometimes for a very long time - say, airline baggage, bus luggage compartment, hotel left luggage, or gym lockers - and it's useful to have a tracker (ideally a more secure one, e.g. AirTag) in case anything goes wrong. And even if you're the type of person who never lets their bags leave their sight, nobody is immune to their key…

I'm arguing the tradeoff of possible convenience isn't worth it. Tile is owned by Life360. The original article talks about Life360 selling your data to advertisers. Let's look at what the Tile app wants to collect from you: photos and videos, location, app activity, messages, personal info. They say 'no data is shared with third parties'. Does that include the parent company Life360 that does sell data with third pa…

Then use a better, more private tracker.
Post reply on HN