HN Debrief

Tile's security is so bad it's a feature for stalkers

  • Privacy
  • Security
  • Hardware
  • Consumer Tech

The linked post points to a research paper arguing that Tile’s design makes user tracking far easier than it should be. Tile tags and the app ecosystem around them leak stable identifiers and unencrypted location information, which lets an attacker recognize a specific tag over time and use other people’s phones to learn where that tag has been. The sharp point is that a stalker may not need to hide anything on a victim. If the victim already carries a Tile on their keys or bag, the device effectively tags them for anyone who knows how to query the network.

If you ship products that broadcast identifiers into a shared detection network, treat stalking and secondary-use tracking as core design threats, not edge cases. For buyers, older cross-platform trackers like Tile now look meaningfully riskier than systems that rotate keys and hide location data from the provider.

Discussion mood

Strongly negative. Most people treated the paper as confirmation that Tile and Life360 made obvious privacy and safety mistakes, with extra anger aimed at location-data monetization and the idea that users can be tracked by devices they bought for themselves.

Key insights

  1. 01

    Why Tile is worse than a GPS bug

    The danger is not that Tile beats purpose-built stalkerware on raw capability. It beats it on convenience, battery life, and social camouflage. A GPS tracker has to be planted, powered, and paid for. Tile piggybacks on a public network of nearby phones, works for months on a coin cell, and may already be attached to the victim’s own keys. That turns a niche attack into a cheap lookup problem.

    When you assess abuse risk, compare against the attacker’s full workflow, not just the hardware spec. Any product that lets an adversary reuse the victim’s own device will be adopted faster than a custom surveillance gadget.

      Attribution:
    • Karliss #1
    • duxup #1
    • mplewis #1
  2. 02

    Apple and Google solved the obvious privacy layer

    The useful contrast was not brand loyalty. It was architecture. Apple and Google were described as rotating keypairs over time and encrypting location reports to a key only the owner can derive or hold. That blocks the provider, casual observers, and anyone who learns one identifier at one place from linking the same tag a week later somewhere else. Tile’s design looks bad precisely because better patterns are already shipping at scale.

    If your product depends on crowd-located beacons, rotating identifiers and owner-only decryption are table stakes. If a vendor cannot explain that model clearly, assume linkability is part of the product.

      Attribution:
    • mspecter #1
    • izacus #1
    • miki123211 #1
  3. 03

    Location-data monetization poisoned trust

    The security issue landed harder because people already distrust Life360’s business model. Comments tied the sudden push for Life360 ads to the company’s ability to profit from location data, and one commenter claimed that flow reaches Placer.ai. Even if that specific downstream claim is only a commenter allegation, the broader point stands: once a company is seen as turning movement data into ad inventory, every security shortcut looks intentional.

    For consumer products, data monetization changes how every privacy bug will be interpreted. If your revenue story touches user location, expect far less benefit of the doubt and much higher reputational blast radius when flaws surface.

      Attribution:
    • PLenz #1
    • dreamcompiler #1
    • mplewis #1

Against the grain

  1. 01

    Dedicated stalker devices already exist

    The skeptical view is that insecure Tiles are a sideshow because anyone serious about stalking can buy off-the-shelf GPS trackers designed for covert use. From that angle, the paper overstates novelty and confuses a general surveillance problem with a Tile-specific one.

    Do not let a vivid abuse case substitute for comparative risk analysis. Ask whether a flaw creates a new attacker population or just duplicates what determined attackers can already do.

      Attribution:
    • alt227 #1
  2. 02

    Trackers still solve real loss problems

    The anti-tracker posture ran into a practical rebuttal. People lose control of bags in airports, hotels, buses, and gyms, and keys fall out of pockets no matter how disciplined you are. The better conclusion is not to avoid trackers entirely. It is to prefer systems with stronger anti-linkability and encryption.

    If you need item finders for travel or logistics, choose on privacy architecture first and convenience second. “Just don’t lose things” is not an operational plan.

      Attribution:
    • user00005 #1
    • rafram #1

In plain english

coin cell
A small round battery often used in watches, key fobs, and compact trackers.
end-to-end encryption
A design where data is encrypted so that only the intended recipient can read it, not the service provider carrying or storing it.
linkability
The ability to tell that separate observations or identifiers belong to the same person or device over time.
stalkerware
Software or hardware used to secretly monitor or track another person without their consent.
threat model
A clear description of what kinds of attackers, attacks, and harms a system is designed to defend against.

Reference links

Research papers

People and projects

  • Akshaya Kumar homepage
    Homepage of one of the grad students credited for the research.
  • Anna Raymaker homepage
    Homepage of one of the grad students credited for the research.
  • MyGrid
    Alternative tracker app someone asked about in relation to trust and support for degoogled Android.

Companies and services mentioned

  • Placer.ai
    Named in a commenter claim about where location data may ultimately flow.