Saturday, 15 November 2025
29.6 C
Singapore
24.4 C
Thailand
23.8 C
Indonesia
28.4 C
Philippines

Tile trackers face criticism over lack of encryption and stalking risks

Researchers warn that Tile trackers lack encryption, raising concerns about stalking risks despite the company's claims of safety improvements.

Security researchers have uncovered a major vulnerability in Tile’s tracking devices that could allow stalkers to monitor victims without their knowledge. According to a detailed report by Wired, Tile’s anti-theft mode, which is designed to make trackers “invisible” on the company’s network, also bypasses safeguards meant to prevent unwanted tracking.

Researchers found that data sent from the devices, including unique IDs and MAC addresses, is transmitted without encryption. This means that bad actors could potentially intercept the signals with Bluetooth devices or antennas and track someone’s movements over time.

Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation (EFF), has long raised concerns about the risks associated with Bluetooth-enabled trackers. “Tile has, historically, been a bad actor in this space in the sense that they have known about all of these problems with their design choices,” Galperin said.

Tile responded by saying it had made “improvements” since the issues were reported, but the company did not provide details or confirm whether encryption had been introduced.

How trackers work and why Tile is different

Tracking tags such as those from Tile, Apple, Samsung, and Google work by sending signals to nearby smartphones. These phones then relay information, such as location, MAC addresses, and unique IDs, to the company’s database, making it easier to locate lost items, including keys, wallets, or purses.

Apple’s AirTags and Samsung’s SmartTags have built-in security measures that frequently change unique IDs and MAC addresses to make it harder for outsiders to follow a tag. Google’s Find My Device network powers similar protections for third-party brands, including Chipolo, Pebblebee, and Motorola.

However, researchers Akshaya Kumar, Anna Raymaker, and Michael Specter of the Georgia Institute of Technology discovered that Tile only rotates the unique ID but not the MAC address. This enables the linking of a tag’s MAC address to a specific device indefinitely. “An attacker only needs to record one message from the device … to fingerprint it for the rest of its lifetime,” Kumar told Wired.

Galperin noted that the EFF has been advocating for industry-wide standards to mitigate such risks, collaborating with Google and Apple on a framework called Detecting Unwanted Location Trackers. “One of them is frequently rotating your goddamn MAC address and sending information encrypted, instead of in the clear,” she said.

Anti-theft mode under scrutiny

Tile’s “Scan and Secure” tool, designed to alert users if an unknown Tile is nearby, is also easily circumvented by the anti-theft feature. When activated, this mode hides the tracker from the Tile network, making it impossible for potential victims to detect.

Tile requires users to provide a photo ID and accept a $1 million fine if convicted of misuse before enabling the feature. Yet experts argue this safeguard is ineffective, as stalkers are unlikely to be caught if the technology itself prevents detection. “The stalker has to be caught, and they [Tile] have just provided the technology to make sure that wouldn’t happen,” Galperin said.

Responding to Wired, Kristi Collura, a spokesperson for Tile’s parent company Life360, said the firm has taken steps to improve safety. “Using a Tile to track someone’s location without their knowledge is never okay and is against our terms of service,” she said.

Life360 stated that it collaborates with the HackerOne programme to address security issues, works with law enforcement in rare cases of misuse, and focuses on enhancing the security of its broader platform.

Hot this week

Adyen launches new payment terminals for retail and F&B sectors

Adyen launches the S1E4 Pro and S1F4 Pro terminals, enhancing in-person payment solutions for retail and F&B businesses.

OpenAI introduces GPT-5.1 with improved conversation and customisation

OpenAI launches GPT-5.1 with improved tone, clearer reasoning and new controls that make ChatGPT more conversational and customisable.

GFTN Capital and SBI Holdings launch US$200 million global innovation fund

GFTN Capital and SBI Holdings have launched a US$200 million fund to accelerate global FinTech innovation and responsible growth.

Businesses report rising revenue loss from inefficient tech as AI adoption grows

New research shows two in five global businesses face revenue loss due to tech inefficiencies, with many turning to AI to improve productivity.

Singapore FinTech Festival 2025 marks 10 years with focus on the next decade of finance

Singapore FinTech Festival 2025 celebrates its 10th year, spotlighting AI, tokenisation, and quantum technologies shaping global finance.

vivo X300 Pro review: A flagship built for serious photography

A detailed look at the vivo X300 Pro’s camera system, design, battery life and everyday performance in real-world use.

Businesses report rising revenue loss from inefficient tech as AI adoption grows

New research shows two in five global businesses face revenue loss due to tech inefficiencies, with many turning to AI to improve productivity.

Meta announces Southeast Asia’s most impactful Reels campaigns and creators

Meta highlights brands and creators shaping Southeast Asia’s short-form video landscape at the 2025 Reels Impact Awards.

Toyota Gazoo Racing Asia brings 2025 Esports GT Championship Finals to Thailand

Toyota Gazoo Racing Asia brings the 2025 Esports GT Championship Finals to Thailand, featuring top sim drivers and an expanded racing programme.

Related Articles

Popular Categories