GadgetBond

  • Latest
  • How-to
  • Tech
    • AI
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Add GadgetBond as a preferred source to see more of our stories on Google.
Font ResizerAa
GadgetBondGadgetBond
  • Latest
  • Tech
  • AI
  • Deals
  • How-to
  • Apps
  • Mobile
  • Gaming
  • Streaming
  • Transportation
Search
  • Latest
  • Deals
  • How-to
  • Tech
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • AI
    • Anthropic
    • ChatGPT
    • ChatGPT Atlas
    • Gemini AI (formerly Bard)
    • Google DeepMind
    • Grok AI
    • Meta AI
    • Microsoft Copilot
    • OpenAI
    • Perplexity
    • xAI
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Follow US
SecurityTech

Tile trackers lack encryption leaving users at risk of stalking

Georgia Tech researchers reveal that Tile tags can be fingerprinted via static MAC addresses, putting owners’ privacy at serious risk.

By
Shubham Sawarkar
Shubham Sawarkar's avatar
ByShubham Sawarkar
Editor-in-Chief
I’m a tech enthusiast who loves exploring gadgets, trends, and innovations. With certifications in CISCO Routing & Switching and Windows Server Administration, I bring a sharp...
Follow:
- Editor-in-Chief
Sep 30, 2025, 5:48 AM EDT
Share
We may get a commission from retail offers. Learn more
Life360 Tile Mate Bluetooth tracker.
Image: Life360
SHARE

If you carry a Tile on your keys or slip a sticker into a backpack, you’re trusting a tiny radio with a surprisingly big job: quietly whispering your location to nearby phones so you can find the thing you lost. But a new round of security research suggests those whispers aren’t as private or as anonymous as most people assume — and in the wrong hands, they could be used to follow someone, not just find a lost wallet.

How these trackers are supposed to work — and where things go wrong

Bluetooth item trackers like Tile, Apple’s AirTag, and Samsung’s SmartTag solve the same problem: small, cheap radios don’t have long-range internet connections, so they rely on a crowd-sourced network of phones. A tag broadcasts an identifier; a nearby phone hears it and anonymously tells the company’s servers, “I heard this tag at this place and time,” which then lets the owner see the tag’s last-known location.

To stop abuse, vendors have layered in protections: rotate identifiers and MAC addresses so a tracker can’t be passively fingerprinted forever; encrypt or otherwise hide identifying details so random listeners can’t reconstruct location histories; and build detection tools so someone can scan for unknown trackers nearby. But according to Georgia Tech researchers, Tile’s implementation doesn’t do all that — and that gap is the weak link.

The technical hole

Researchers who reverse-engineered the Tile software say Tile rotates the tag’s public ID but does not rotate the device’s Bluetooth MAC address, and the tags broadcast certain information unencrypted. That means an attacker who records a single broadcast from a Tile can match the MAC address to that tag going forward and follow it — either by placing cheap Bluetooth sniffers or even by using another phone or an antenna to listen for that unchanging MAC. In short, one captured message is often enough to “fingerprint” a tracker for its lifetime.

That’s not academic hair-splitting. Changing the MAC address regularly is a straightforward mitigation many companies use specifically to prevent this kind of passive tracking; leaving it static makes the tag — and thus the person carrying whatever it’s attached to — much easier to stalk.

Anti-theft mode that helps thieves (and stalkers)

Tile also offers an “anti-theft” mode that hides a tag from Tile network scans so thieves can’t quickly check whether an item is protected. Sounds sensible — except that this exact feature can be abused by people trying to avoid being found by the very scan tools meant to detect unwanted trackers. In anti-theft mode, a tag won’t show up in a Scan and Secure search even while it continues to broadcast the same unencrypted identifiers that let passive listeners track it. In practical terms, a malicious tracker can be made invisible to the person being stalked while still leaking identifying info to someone who’s listening.

Tile does gate anti-theft mode behind identity checks (photo ID, selfie) and even a fine policy — but critics point out that those procedural steps only matter if the stalker is ever caught. As EFF’s Eva Galperin told reporters, concerns about these design choices are longstanding; she and others argue that technical protections (rotate the MAC, encrypt broadcasts) are the real fix, because policies and punishments don’t stop an attacker from slipping a tracker into a bag today.

Tile’s response — “we made improvements”

Tile’s parent company, Life360, told reporters it’s “made a number of improvements” since the researchers flagged the issue and stressed that using a Tile to track someone without consent violates its terms of service. The company also pointed to its HackerOne program as a place for researchers to responsibly disclose issues. But the public statements so far are light on technical detail — researchers and privacy advocates say they want clearer, verifiable fixes (for example: confirmation that MAC randomization and broadcast encryption were implemented and independently tested).

Why this matters beyond Tile

This isn’t only a Tile problem — it’s a reminder that convenience often outpaces security in consumer devices. The Electronic Frontier Foundation helped push Apple and Google to adopt a shared Detecting Unwanted Location Trackers standard to make it easier for phones to find unknown tags, and the EFF continues to advocate for best practices like MAC rotation and encrypted payloads. Those standards reduce the attack surface for stalkers and help users detect when a device that shouldn’t be near them is, in fact, following them. But companies still need to build those protections into product firmware and servers — and to be transparent when they do.

What researchers recommend — and what you can do today

Researchers and advocates have fairly simple technical asks: rotate MAC addresses frequently, encrypt identifying data sent over the air, and design anti-theft or privacy features so they can’t be trivially abused to hide malicious tracking.

For people who own trackers right now:

  • Turn on the phone-based “scan for nearby unknown trackers” features on your device — both Android and iOS have tools (though coverage and ease of use vary).
  • Check your items periodically; if something unfamiliar is found near you, follow vendor guidance to report it to law enforcement.
  • Consider whether you really need a persistent tracker on items you carry all the time (purse, keys). If someone wanted to follow you, those are the very things they’d put a tag into.
  • Keep device firmware and apps updated — if Tile (or others) push real fixes, updates are how you get them.

None of these are perfect; the core fixes require changes to how trackers are built. But being aware and using the tools you do have reduces short-term risk.

The bigger picture: product design, regulation, and trust

The Tile episode is illustrative of a pattern we see across many connected devices: privacy and safety are often afterthoughts. Users buy convenience and assume reasonable protections are in place; sometimes they are, sometimes they aren’t — and sometimes a feature meant to help (anti-theft) becomes a vector for abuse.

That gap is why advocacy groups, academics, and — increasingly — regulators are pushing for baseline security and privacy requirements for physical trackers and other IoT gadgets. The work between Apple and Google on tracker detection is a step in the right direction, but standards without audited implementation are still only half a solution.

Final word

A little tracking tag stuck to a wallet is an easy thing to underestimate. It’s small, inexpensive, and seems harmless. But as this research makes clear, design choices at the chip-and-protocol level can have outsized effects on real-world safety. If you own a Tile or any similar device, treat it like any other piece of tech that handles sensitive location data: check your settings, keep software current, and push companies for transparency about the concrete steps they’ve taken to stop unwanted tracking. Until manufacturers bake in hard protections — rotating MACs, encrypting broadcasts, and making detection reliable — those tiny radios will remain, in some circumstances, useful tools for people who mean to do harm.


Discover more from GadgetBond

Subscribe to get the latest posts sent to your email.

Topic:Tile
Most Popular

Xbox Game Pass explained: plans, perks, and play

What is cloud gaming?

The real purpose of Microsoft PC Manager

Universal is re-releasing The Fast and the Furious for its 25th anniversary

Apple removes many menu icons in macOS 27

Apple’s subscription overhaul brings bundles, group plans, and retention

Xbox Game Pass Ultimate: pricing, perks, and how it all fits together

Xbox Game Pass Essential: who it’s for, what it includes, what it skips

The next Xbox could arrive with a new business model

The new Beats headphones, Antonee Robinson just teased on his way to the World Cup

Also Read
Promotional image for the Swipewipe photo cleaner app showing three versions of the same portrait photo arranged on a soft beige background. The center image is highlighted with a green checkmark to indicate a photo being kept, while the smaller images on either side feature trash can icons, representing photos selected for deletion. The visual illustrates Swipewipe’s swipe-based photo organization and cleanup process for managing duplicate or unwanted images.

Swipewipe makes clearing your camera roll feel oddly easy

The Apple Music logo in white text against a vibrant red background. The text has a slight distortion or wave effect, giving it a dynamic, musical appearance. The Apple logo precedes the word "Music" and both share the same rippling, audiographic style treatment.

Apple Music iOS 27 update: AutoMix, artist pages, and Siri AI

Promotional artwork for PC Game Pass featuring a collage of game characters and worlds. The image includes a red-eyed fantasy character, a tactical soldier, an adventurer wearing a fedora, and a mythological bearded figure with glowing eyes. The Xbox logo and "PC Game Pass" branding appear across the center, highlighting a diverse library of action, adventure, strategy, and role-playing games available through the subscription service.

PC Game Pass in 2026: library, limits, and the new price cut

Promotional Xbox gaming image with the slogan “Play the Way You Want” displayed in large green text at the center. Surrounding the message are multiple gaming devices, including an Xbox console and controller, a gaming handheld, a laptop, a smartphone, and a TV, all showing Xbox games and the Xbox app interface. The artwork highlights Xbox Cloud Gaming and Game Pass, emphasizing the ability to play across console, PC, handheld, mobile, and streaming devices from a single gaming ecosystem.

Xbox Game Pass Premium: the middle tier that might be just right

Promotional image of the PlayStation Portal handheld gaming device featuring the PlayStation Plus cloud streaming interface on its display. The screen shows the PlayStation Plus logo surrounded by a glowing purple ring, while the device's white DualSense-style controller grips frame the display on both sides. Set against a dark background with PlayStation-inspired colors, the image highlights cloud gaming and remote play capabilities available through PlayStation Plus.

New to PlayStation Plus? Here’s how the service really works

Promotional image for Amazon Luna cloud gaming featuring the Luna logo on a purple gradient background. Multiple devices, including a smart TV, desktop monitor, laptop, tablet, and smartphone, display the same racing game scene with Sonic the Hedgehog and other characters. An Amazon Luna wireless controller is positioned in front of the screens, illustrating seamless game streaming across different devices through Amazon’s cloud gaming platform.

How Amazon Luna works and who it is for

Promotional image for NVIDIA GeForce NOW cloud gaming showcasing games streamed across multiple devices. Large displays feature Pragmata and Counter-Strike 2, while laptops, a handheld gaming device, smartphone, VR headset, racing wheel, and flight simulator controls are arranged on illuminated black platforms. The dark futuristic background with NVIDIA-green wave patterns emphasizes GeForce NOW’s ability to play high-end PC games across screens and gaming hardware through cloud streaming.

What GeForce Now gets right about cloud gaming

Promotional artwork for Xbox Cloud Gaming featuring Forza Horizon 5. A red Mercedes-AMG hypercar races along a dusty coastal road in a tropical landscape, while off-road vehicles jump over rocky terrain in the background. In the foreground, the game is shown running across multiple devices, including a TV, monitor, smartphone, tablet, handheld gaming device, VR headset, and Xbox Series X console with controllers, highlighting the ability to stream and play Forza Horizon 5 across the Xbox Cloud Gaming ecosystem.

What is Xbox Cloud Gaming and how does it work?

Company Info
  • Homepage
  • Support my work
  • Latest stories
  • Company updates
  • GDB Recommends
  • Daily newsletters
  • About us
  • Contact us
  • Write for us
  • Editorial guidelines
Legal
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • DMCA
  • Disclaimer
  • Accessibility Policy
  • Security Policy
  • Do Not Sell or Share My Personal Information
Socials
Follow US

Disclosure: We love the products we feature and hope you’ll love them too. If you purchase through a link on our site, we may receive compensation at no additional cost to you. Read our ethics statement. Please note that pricing and availability are subject to change.

Copyright © 2026 GadgetBond. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | Do Not Sell/Share My Personal Information.