Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Password Managers Share a Hidden Weakness

      March 1, 2026

      Say Goodbye to the Undersea Cable That Made the Global Internet Possible

      March 1, 2026

      Cybersecurity & Resilience Bill Raises Compliance Stakes For Providers

      February 28, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        Say Goodbye to the Undersea Cable That Made the Global Internet Possible

        March 1, 2026

        Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

        February 28, 2026

        Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

        February 27, 2026

        Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

        February 27, 2026

        OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

        February 27, 2026
      • AI

        AI Password Generation Poses Major Security Risk, Experts Warn

        February 28, 2026

        Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

        February 28, 2026

        AI Productivity Gains Concentrated Among High-Skilled Workers, Study Finds

        February 28, 2026

        X to Let Users Mark Posts ‘Made With AI’ as Platform Eyes Voluntary Disclosure Feature

        February 27, 2026

        Uber Rolls Out “Uber Autonomous Solutions” To Support Third-Party Robotaxi Partners

        February 27, 2026
      • Security

        Password Managers Share a Hidden Weakness

        March 1, 2026

        AI Password Generation Poses Major Security Risk, Experts Warn

        February 28, 2026

        Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

        February 28, 2026

        Starkiller Phishing Kit Exposes Dangerous New Wave of Proxy-Based Credential Theft

        February 28, 2026

        Single Compromised Account Exposes 1.2 Million French Banking Records

        February 28, 2026
      • Health

        Social Media Addiction Trial Draws Grieving Parents Seeking Accountability From Tech Platforms

        February 19, 2026

        Portugal’s Parliament OKs Law to Restrict Children’s Social Media Access With Parental Consent

        February 18, 2026

        Parents Paint 108 Names, Demand Snapchat Reform After Deadly Fentanyl Claims

        February 18, 2026

        UK Kids Turning to AI Chatbots and Acting on Advice at Alarming Rates

        February 16, 2026

        Landmark California Trial Sees YouTube Defend Itself, Rejects ‘Social Media’ and Addiction Claims

        February 16, 2026
      • Science

        Microsoft Claims 100 Percent Renewable Energy Match Across Global Electricity Use

        February 28, 2026

        Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

        February 27, 2026

        Large Hadron Collider Enters Third Shutdown For Major Upgrade

        February 26, 2026

        Google Phases Out Android’s Built-In Weather App, Replacing It With Search-Based Forecasts

        February 25, 2026

        Microsoft’s Breakthrough Suggests Data Could Be Preserved for 10,000 Years on Glass

        February 24, 2026
      • Tech

        Sam Altman Says ‘AI Washing’ Is Being Used to Mask Corporate Layoffs

        February 28, 2026

        Zuckerberg Testifies In Landmark Trial Over Alleged Teen Social Media Harms

        February 23, 2026

        Gay Tech Networks Under Spotlight In Silicon Valley Culture Debate

        February 23, 2026

        Google Co-Founder’s Epstein Contacts Reignite Scrutiny of Elite Tech Circles

        February 7, 2026

        Bill Gates Denies “Absolutely Absurd” Claims in Newly Released Epstein Files

        February 6, 2026
      TallwireTallwire
      Home»Tech»New Research Reveals Tile Trackers’ Encryption Flaws Could Facilitate Stalking
      Tech

      New Research Reveals Tile Trackers’ Encryption Flaws Could Facilitate Stalking

      Updated:December 25, 20254 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      New Research Reveals Tile Trackers’ Encryption Flaws Could Facilitate Stalking
      New Research Reveals Tile Trackers’ Encryption Flaws Could Facilitate Stalking
      Share
      Facebook Twitter LinkedIn Pinterest Email

      A newly published study warns that popular Bluetooth trackers made by Tile may be vulnerable to misuse because they broadcast identifying data—like MAC addresses and unique IDs—in unencrypted form, allowing nearby devices or antennas to intercept them and track movements over time. Unlike competitors such as Apple and Samsung that rotate IDs and encrypt signals, Tile’s design reportedly leaves static identifiers exposed, enabling “fingerprinting” of a tracker. The team of researchers at Georgia Tech also found that Tile’s so-called anti-theft or anti-stalking protections can be disabled or bypassed—one mode makes the tracker invisible even to users scanning for unwanted tags. Worse, the system may be exploited to frame innocent users via “replay attacks” that mimic someone else’s tag in a different location. Tile’s parent company, Life360, claimed to have made “improvements” since being alerted, but has not detailed whether or how the core vulnerabilities are fixed.

      Sources: Wired, The Verge

      Key Takeaways

      – Because Tile tags broadcast both a stable MAC address and an evolving identifier without encryption, attackers can link those signals over time and track a device persistently.

      – Tile’s “anti-theft mode” may actually hinder detection of malicious tags by disabling Scan & Secure, and the system is vulnerable to replay attacks that could falsely implicate innocent owners.

      – Even though Tile claims to have made improvements after being notified, the company has not clearly confirmed whether the structural security issues have been addressed.

      In-Depth

      Bluetooth trackers like Tile are meant to help you keep tabs on everyday items—keys, wallets, luggage—by piggybacking on a network of nearby phones that relay signal data back to a central server. In theory, this kind of “crowdsourced” Bluetooth location network is quite clever and useful. But the recent findings from Georgia Tech show that Tile’s particular implementation has alarming privacy gaps that could turn your own tracker into a tracking tool against you.

      The core issue lies in what the tag broadcasts and how. Tile tags emit two identifiers over Bluetooth: a unique ID that is supposed to rotate periodically, and a device’s MAC address—which does not rotate and stays constant. Neither of those are encrypted in transit. That means anyone with even modest technical tools—a Bluetooth‐capable device or a simple radio receiver—could pick up those broadcasts and tie them to a specific tracker. Because the MAC address never changes, an attacker only needs to capture one broadcast to consistently identify the same tag later, regardless of how often the rotating ID changes. Over time, that yields a way to map out where the tracker—and potentially its owner—goes.

      Worse still, once that data is picked up by other devices (phones participating in the Tile network, for example), it’s transmitted to Tile’s servers supposedly in the “clear”—that is, not encrypted en route. The researchers suggest that means Tile itself could, in principle, track its users’ devices—despite the company’s claims to the contrary.

      The team also drilled into Tile’s anti-stalking protections. Tile offers a “Scan & Secure” feature that’s meant to let users scan for unwanted tags traveling with them; if it spots a tracker, it should warn you. But the catch is that one of Tile’s modes—Anti-Theft Mode—makes tags invisible to that scan. In effect, an attacker could enable Anti-Theft mode on a malicious tag to avoid detection. As one researcher put it, “the stalker has to be caught—and [Tile] have just provided the technology to make sure that wouldn’t happen.”

      An even more chilling possibility: replay attacks. Because Tile lacks cryptographic safeguards to distinguish original vs. replayed signals, a malicious actor could record a person’s tile broadcasts and then replay them near a different person, making it appear as though the first person’s tag is present. That could lead to wrongful accusations of stalking or harassment, and there’s no reliable way in the system currently to tell the difference between a genuine broadcast and a replayed one.

      Tile’s parent, Life360, says it has made “a number of improvements” since researchers disclosed the flaws last November—but so far, the company hasn’t clarified whether it has eliminated the root vulnerabilities. That ambiguity is disquieting given the severity of the risks: exposure of movement patterns, potential framing of innocent users, and the possibility of internal access by the platform owner.

      For users of Tile—and of Bluetooth trackers in general—this serves as a reminder that design trade-offs in IoT devices carry real risks. Signal encryption, frequent identifier rotation, anomaly detection, and anti-replay safeguards are not optional extras in privacy-sensitive contexts—they’re essential. Until Tile can credibly demonstrate structural fixes, anyone using its tags must weigh whether the utility of tracking beloved items outweighs the latent threat of being tracked themselves.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleNew Law Lets Content Creators Keep Up to $25,000 in Tips Tax-Free—With Caveats
      Next Article New ‘Stealerium’ Malware Turns Sextortion Fully Automated with Webcam Spying

      Related Posts

      Say Goodbye to the Undersea Cable That Made the Global Internet Possible

      March 1, 2026

      Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

      February 28, 2026

      Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

      February 27, 2026

      Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

      February 27, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      Say Goodbye to the Undersea Cable That Made the Global Internet Possible

      March 1, 2026

      Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

      February 28, 2026

      Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

      February 27, 2026

      Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

      February 27, 2026
      Popular Topics
      Taiwan Tech Tesla Cybertruck Quantum computing SpaceX Sundar Pichai Robotics Ransomware Samsung spotlight trending UAE Tech Series A Tim Cook Tesla picks Qualcomm Startup Series B Satya Nadella Sam Altman
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.