κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / Tile Tracking Tags Can Be Exploited by Tech-Savvy Stalkers, Researchers Say
άμυνα
.

Tile Tracking Tags Can Be Exploited by Tech-Savvy Stalkers, Researchers Say

29/09/2025

A team of researchers found that, by not encrypting the data broadcast by Tile tags, users could be vulnerable to having their location information exposed to malicious actors.Courtesy of Life360Tile trackers, used to locate everything from lost keys to stolen pets, are used by more than 88 million people worldwide, according to Tile’s parent company, Life360. But researchers who examined the tracking technology have found design flaws that would let stalkers—or potentially the manufacturer itself—track the location of Tile users and their devices, contrary to claims the company has made about the security and privacy of its devices.The researchers—Akshaya Kumar, Anna Raymaker, and Michael Specter of Georgia Institute of Technology—found that each tag broadcasts an unencrypted MAC address and unique ID that can be picked up by other Bluetooth devices or radio-frequency antennas in a tag’s vicinity to track the movements of the tag and its owner. The location of a tag, its MAC address, and unique ID also get sent unencrypted to Tile’s servers, where the researchers believe this information is stored in cleartext, giving Tile the ability to track the location of tags and their owners, even though the company claims it does not have this capability.The researchers say this would give Tile the ability to conduct “mass surveillance” on its users and potentially provide that information to law enforcement and others.The researchers also found that Tile’s anti-stalking protection can be easily undermined if a stalker enables an anti-theft feature that Tile offers with its tags. Additionally, someone could falsely frame a Tile owner for stalking by recording the unencrypted broadcasts their Tile device makes and replaying these broadcasts in the vicinity of another Tile user, making it seem like the former is stalking the latter.The researchers reported their findings to Tile’s parent company, Life360, last November, but they say the company stopped communicating with them in February. WIRED sent Life360 an email asking for a response to the issues raised by the researchers, but a spokesperson sent a reply that did not explicitly address the problems. The email said only that the company had “made a number of improvements” since receiving the researchers’ report, without specifying what those were.Tile sells stand-alone tags, but its tracking technology is also embedded in laptops, headphones, smartwatches, and other products made by companies like Dell, Bose, and Fitbit. The researchers reverse engineered Tile’s protocol and Android mobile app used with the Tile Mate, the company’s most popular tracker tag. They say their findings may not apply to other models of Tile tags or the Tile technology used in products made by third parties.How Tile Tags WorkTile trackers operate similarly to tracking tags made by Apple, Google, and Samsung. But Tile’s system differs in important ways. Like the others, Tile tags are battery-powered and use Bluetooth to broadcast their location to a user’s phone. Users can slip a tag into a briefcase, luggage, or vehicle, or attach it to keys, a phone, laptop, or even a pet collar to track the location of these items.Each Tile tag broadcasts the tag’s MAC address and a unique ID, which changes periodically. If an item paired with the tag goes missing the owner, using their Tile app, can instruct the tag to emit a sound to locate it. For items farther away, the system relies on the network of phones belonging to other Tile users. These also pick up the broadcast of any Tile device near them. And since 2021, Ring cameras, Echo devices, and Tile tags have been integrated into Amazon’s Sidewalk network, meaning Ring and Echo devices can pick up the location of Tile tags as well.Each time these devices pick up the broadcast from a Tile tag, the location, MAC address, and unique ID of that tag get sent to a Tile server where it’s stored in a database, the researchers found. The owner of a lost tag and item can then use their Tile app to query the database for their latest location. The problem, according to the researchers, lies in how Tile has implemented this system.Tile claims that user information transmitted across its network can’t be seen by anyone. “You are the only one with the ability to see your Tile location and your device location,” the company states in its privacy policy. But the researchers found that the MAC address and unique ID that a Tile tag broadcasts is not encrypted, allowing someone in the vicinity of a tag with a Tile app on their phone or a radio frequency antenna to intercept this information as its transmitted and track the location of the tag and associated item or its owner.Other tag makers replace the MAC address with a rotating unique ID and only transmit the ID. By changing the ID periodically, someone recording broadcasts from a tag cannot easily link multiple broadcasts to the same tag to track the movement of that tag and associated item or owner.But because Tile’s system transmits both the MAC address and the unique ID, and does not encrypt this transmission, someone can intercept this information. Tile’s unique ID also rotates—it changes every 15 minutes if the tag is near the owner’s phone or once in 24 hours if not—but because the MAC address is static and does not change, it can be used to track a tag regardless of the changing ID. Even if Tile chose to not transmit the MAC address, the researchers say, the way Tile generates the changing ID is not secure and can still be used to track a tag.“An attacker only needs to record one message from the device … to fingerprint it for the rest of its lifetime,” says Kumar, who says this creates a risk of systemic surveillance for anyone whose tag is caught up in a scan.Law enforcement could potentially use this to identify anyone in an area that has a Tile tag or Tile-enabled device. And because this location information seems likely to be stored unencrypted on Tile’s server, researchers say, Tile could also track the location of tags or share this information with any third party.“These issues transform Tile’s infrastructure into a global tracking network,” the researchers claim in a paper they wrote about their findings.When an Apple, Google, or Samsung tag gets detected in a scan, the report that gets sent to the company servers containing the tag’s ID and location information is end-to-end encrypted so that no one can intercept the broadcasts as they’re transmitted, and the companies themselves cannot see the location information to track the movement of the tags. Only a tag owner can see this information because a key on their phone decrypts the location data on the company’s server that is associated with their tag ID.“They have designed their system intentionally such that they aren’t able to recover your location or the location of where your items are,” says Specter. “Because they don’t want to be in the business of knowing where all people are at all times.”Talking Anti-StalkingIn a study published last year, researchers measuring the misuse of Bluetooth location trackers—including devices from Apple, Tile, Samsung, and Chipolo—found that more than 40 percent of stalking victims had been tracked with Bluetooth tags hidden in their cars, purses, or backpacks.To address this, makers of location-tracking technology have implemented solutions to alert users when a tracking device they don’t own appears to be moving with them. But the researchers say that Tile’s implementation is flawed in ways that both undermine its effectiveness and make it susceptible to being used to track the movement of other users.Unlike other trackers—which conduct a continuous scan for trackers in a user’s vicinity that they don’t own and automatically alert the user to the presence of these trackers—Tile’s so-called Scan and Secure system has to be manually initiated by a user through the Tile app. The scan lasts only 10 minutes, and the user has to be moving around an area while the scan is in progress to detect tags that are moving with them. Users have to also remember to re-initiate scans periodically to detect any rogue devices that might be traveling with them since their last scan.Tile’s app performs six Bluetooth scans during the 10 minutes and extracts the MAC address and unique ID from each broadcast it detects. The app then checks these addresses against a database to determine if they are paired with the phone of the person doing the scan. Any address or ID that is not paired with their phone is designated “unknown.” The app produces a report of these tags for the person to view. It also sends a message to the Tile server with all the MAC addresses and unique IDs detected during the six scans, and the number of times they appeared.But the researchers found that the Scan and Secure feature is undermined by another feature Tile offers for preventing theft. The researchers say this anti-theft mode is unique to Tile, and the problems it presents for Tile users may be the reason.The aim of anti-theft is to prevent would-be thieves from running a scan using a Tile mobile application to see if there is a Tile tag paired with an item they plan to steal. But when a tag owner enables anti-theft to make their tag invisible to would-be thieves, those tags also won’t be visible to someone running a scan to determine if they are being stalked with a rogue tag. This means a stalker could hide their stalking tag by putting it in anti-theft mode. A scan will still detect the tag and send its MAC address, unique ID, and location to Tile’s servers, but the tag won’t be included in the scan results that are displayed to the user who initiated the scan, effectively making potential stalking victims blind to rogue devices that may be following them.Kumar says other makers of location trackers avoid this by not even offering anti-theft mode for their products.“They never say, ‘Here’s a tag that can prevent your devices from being stolen.’ They say it helps recover lost devices. Anti-theft is just not a feature,” she says. “That’s a compromise that these companies are willing to make in order to have stronger anti-stalking properties.”The researchers also say that the anti-theft mode isn’t foolproof because a user with a modified Tile app can easily circumvent it to collect and display all MAC addresses and unique IDs recorded during a scan, regardless of whether any of those tags are using anti-theft mode.Tile believes it solves the anti-theft abuse problem by requiring that anyone who enables anti-theft mode for their tag provide a government-issued ID and live photo of their face to Tile before anti-theft mode will be enabled. Users of this mode also have to consent to a $1 million fine if they are convicted of using Tile for stalking—though the researchers point out that it’s unclear if this is enforceable.Tile states in its terms that the identity information users provide will be shared with law enforcement if Tile believes someone has abused the feature for stalking. But the company is inconsistent about whether law enforcement needs a warrant to get this information. In a FAQ the company says it will “work with law enforcement through a properly issued court order to identify the owner of a suspicious Tile.” But in the terms for its anti-theft mode, users agree that their “personal information can and will be shared with law enforcement at our discretion, even without a subpoena” to aid investigations of suspected stalkers.Lastly, the researchers say someone can abuse the Scan and Secure feature to frame someone else for stalking by executing a replay attack to impersonate their Tile tag. Using a radio-frequency antenna to collect the unencrypted broadcasts from another user’s tag, an attacker can extract the MAC address and unique ID from these broadcasts, and transmit that in another location. If a user conducts an anti-stalking scan in that location, they would see this MAC address and unique ID in the scan, and this information and the location of where it was scanned would be sent to Tile’s server, making it appear as if that tag was near the person who did the scan. There is no way to determine, the researchers say, if a MAC address and unique ID was emitted by a legitimate Tile device or someone maliciously replaying that information.The researchers say many of the problems they found could be addressed simply by Tile encrypting the broadcasts from its tags, and they don’t understand why the company apparently hasn’t followed the example of its competitors.
Source: wired.com

Filed Under: INDUSTRY NEWS Tagged With: Source-9

Character.AI removes Disney characters after receiving cease-and-desist letter

Character.AI received a cease-and-desist letter from Disney, urging the chatbot company to remove Disney characters from among the millions of AI companions on its plaftorm, Variety reports. Character.AI allows users to generate AI chatbots that can range from real people like Elon Musk to fictional characters like Hermione Granger, plus users’ own original creations. These chatbots can be quite … [Read More...]

Home Assistant's October update brings more automation improvements, smarter dashboards, and new AI-powered tricks

Home Assistant follows a monthly release cadence, typically where the first Wednesday of every month brings a new update, and the last Wednesday of every month is the beta for that release. October's update is now here and rolling out to every user. Source: xda-developers.com … [Read More...]

I ditched all my photo editors for this lightweight editing stack, and I'm never going back

Photo editing can get messy fast, it certainly does for me. I reach for one app for cropping, another for filters, another for retouching, and before I know it, my work is scattered across my desktop. Not to mention file storage — I have image duplicates and editing iterations in almost every folder. I thought that hoarding photo editing apps would give me more and better options, but it only … [Read More...]

Whizz co-founder says Trump’s Chicago crackdown is scaring delivery workers off the streets

The footage was striking: A food delivery worker scrambles with his e-bike across a bridge in Chicago, chased by a cadre of armed, masked federal agents. “Get him!” one yells, before the worker ultimately slips away. The viral clip became a rallying point this week for critics of President Donald Trump’s deportation machine, which has spread to multiple U.S. cities and swept up citizens in the … [Read More...]

FTC sues Zillow and accuses it of buying off rival Redfin

The Federal Trade Commission (FTC) is suing home-search website Zillow, alleging that it paid rival Redfin $100 million to eliminate competition in the online listing business. The suit refers to a deal inked back in February between the two companies in which Redfin allegedly agreed to become "an exclusive syndicator of Zillow listings."The allegations suggest that Redfin began copying over … [Read More...]

Why California’s new AI safety law succeeded where SB 1047 failed

California just made history as the first state to require AI safety transparency from the biggest labs in the industry. Governor Newsom signed SB 53 into law this week, mandating that AI giants like OpenAI and Anthropic disclose, and stick to, their safety protocols. The decision is already sparking debate about whether other states will follow suit.  Adam Billen, vice president of public … [Read More...]

OpenAI’s new social app is filled with terrifying Sam Altman deepfakes

In a video on OpenAI’s new TikTok-like social media app Sora, a never-ending factory farm of pink pigs are grunting and snorting in their pens — each is equipped with a feeding trough and a smartphone screen, which plays a feed of vertical videos. A terrifyingly realistic Sam Altman stares directly at the camera, as though he’s making direct eye contact with the viewer. The AI-generated Altman … [Read More...]

I replaced Windows Search and I’ve never been happier

If you've been waiting for Microsoft to fix Windows 11's atrocious Search, I wouldn't bother. Not because the company shouldn't fix it, of course, but because they show no inclination to improve it and keep stuffing things users don't want, like targeted advertising, into the search results. The good news is that you've got plenty of options to replace Search with, depending on your needs and how … [Read More...]

Saturn’s ocean moon looks more hospitable to subsurface life than we thought

Mars isn't our only neighbor that may harbor life. The odds have risen that Saturn's moon Enceladus may, too. On Wednesday, scientists published a paper outlining the increasing complexity of molecules emitted from beneath the moon's surface. "We now have all elements required for Enceladus to harbour life," the ESA's Dr Jörn Helbert told The Guardian.Enceladus gives researchers a unique window … [Read More...]

What founders need to know before choosing their exit — straight from Roseanne Wincek, Jai Das, and Dan Springer — at TechCrunch Disrupt 2025

Exit planning is no longer optional — it’s an essential conversation on the Going Public Stage at TechCrunch Disrupt 2025, happening October 27–29 at San Francisco’s Moscone West. Whether you’re already eyeing a liquidity event or just starting to scale, this is your chance to hear what top VCs and operators are looking for and how to set up your company for long-term success. Three of the best … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • Character.AI removes Disney characters after receiving cease-and-desist letter
  • Home Assistant's October update brings more automation improvements, smarter dashboards, and new AI-powered tricks
  • I ditched all my photo editors for this lightweight editing stack, and I'm never going back
  • Whizz co-founder says Trump’s Chicago crackdown is scaring delivery workers off the streets
  • FTC sues Zillow and accuses it of buying off rival Redfin

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023