Security researchers have uncovered a serious vulnerability in Tile's Bluetooth trackers that could enable stalkers to track victims undetected[reference:23]. The flaw centers on Tile's Anti-Theft Mode, a feature designed to make tags invisible to thieves[reference:24]. The problem is that it also makes them invisible to the very anti-stalking features meant to protect potential victims[reference:25].
How the Flaw Works
Tile trackers broadcast unencrypted data over Bluetooth, including their MAC address and a unique ID transmitted in plaintext[reference:26]. This makes it relatively simple for a tech-savvy attacker to identify and track a specific tag[reference:27].
The Anti-Theft Mode, intended to prevent thieves from detecting and removing a tracker, hides the tag from Tile's "Scan and Secure" detection feature[reference:28]. While this makes it harder for a thief to find the tracker, it also removes the safety checks that would otherwise alert a potential victim that an unwanted tracker is traveling with them[reference:29][reference:30].
When Anti-Theft Mode is enabled, Tile tags no longer show up in the Scan and Secure feature, making it easier for malicious actors to plant trackers on unsuspecting people without detection[reference:31]. The data about the trackers is sent to Tile, but not to the victim[reference:32].
The Accountability Problem
Tile has implemented an accountability mechanism to discourage abuse of the Anti-Theft Mode for stalking[reference:33]. However, researchers have identified several exploitable vulnerabilities and design flaws, disproving many of the platform's claimed security and privacy guarantees[reference:34].
The researchers note that Tile intentionally weakens its anti-stalking features to support an anti-theft use case, relying on a novel accountability mechanism to punish those abusing the system[reference:35]. This trade-off creates a gap that stalkers can exploit.
Broader Implications
The findings highlight a fundamental tension in the design of personal item tracking devices. Manufacturers are aware of the potential for abuse and have implemented anti-stalking features in response[reference:36]. These commonly include scanning for unwanted trackers following a user and alerting the user of the unwanted tracker[reference:37].
However, the Anti-Theft Mode undermines these protections. Until Tile encrypts its broadcasts and overhauls its anti-stalking features, users may be putting themselves at risk every time they clip a Tile tag to their keys or pet collar[reference:38].
The Response
The research, conducted by a group of Georgia Tech researchers, has drawn attention to the serious security and privacy implications[reference:39]. The researchers have called for Tile to encrypt its communications and adequately rotate device identifiers to prevent abuse[reference:40].
Tile has not yet publicly responded to the specific findings, but the vulnerability represents a significant challenge for the company, which is owned by Life360[reference:41]. The findings also raise broader questions about the design of location tracking devices and the trade-offs between anti-theft and anti-stalking features.