惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
S
Securelist
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
IT之家
IT之家
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
云风的 BLOG
云风的 BLOG
N
News and Events Feed by Topic
AI
AI
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Schneier on Security
Schneier on Security
Attack and Defense Labs
Attack and Defense Labs
Vercel News
Vercel News
腾讯CDC
Google DeepMind News
Google DeepMind News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
M
MIT News - Artificial intelligence
WordPress大学
WordPress大学
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
N
Netflix TechBlog - Medium
量子位
S
Schneier on Security
Hacker News: Ask HN
Hacker News: Ask HN
Cyberwarzone
Cyberwarzone
S
Security Affairs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
N
News and Events Feed by Topic
T
Tenable Blog
PCI Perspectives
PCI Perspectives
MyScale Blog
MyScale Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cyber Attacks, Cyber Crime and Cyber Security
W
WeLiveSecurity
N
News | PayPal Newsroom
P
Proofpoint News Feed
O
OpenAI News
C
CERT Recently Published Vulnerability Notes
B
Blog
Cisco Talos Blog
Cisco Talos Blog
Microsoft Security Blog
Microsoft Security Blog
V
Visual Studio Blog
MongoDB | Blog
MongoDB | Blog
大猫的无限游戏
大猫的无限游戏
A
Arctic Wolf
Y
Y Combinator Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Spread Privacy
Spread Privacy

The Register - Security: Research

www.theregister.com Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine ChatGPT blindly trusts browser content, turning the page into a payload Russia-linked threat group put ChatGPT to work from lure to payload Kids can bypass some age checks with a drawn-on mustache What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia ORNL builds more sensitive GPS interference detector Researchers find sabotage malware that may predate Stuxnet Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Anthropic, Google, Microsoft paid AI bug bounties – quietly Security reserchers tricked Apple Intelligence into cursing Don't open that WhatsApp message, Microsoft warns Security boffins harvest bumper crop of API keys from web Lightning-fast exploits mean patch fast, says Cisco Talos AI agents are 'gullible' and easy to turn into your minions Smooth criminals talking their way into cloud environments, Google says Snoops plant info-stealing malware on iPhones, Google warns Cybercrime up 245% since the start of the Iran war Rogue AI agents can work together to hack systems Fake applicants are sending security-killing malware AI agent hacked McKinsey chatbot for read-write access Kaspersky: No signs Coruna iPhone exploit kit made by US Perplexity Comet browser hole was exploitable via cal invite DEF CON hackers 'fed up with government,' Jake Braun says DEF CON hackers 'fed up with government,' Jake Braun says Ransomware payments cratered in 2025 – attacks did not Ransomware payments cratered in 2025 – attacks did not Claude's collaboration tools allowed remote code execution AI takes a swing at online anonymity Fake 'interview' repos lure Next.js devs into running secret-stealing malware Threat intelligence supply chain is full of weak links AI agents abound, unbound by rules or safety disclosures RAT disguised as an RMM costs crims $300 a month Android malware taps Gemini to navigate infected devices Posting AI caricatures on social media is bad for security Payroll pirates conned the help desk, stole employee’s pay Microsoft boffins show LLM safety can be trained away For the price of Netflix, crooks can rent AI crime ops For the price of Netflix, crooks can rent AI crime ops Fast Pair, loose security: Bluetooth accessories open to silent hijack Fast Pair flaw exposes Bluetooth devices to hijacking A simple CodeBuild flaw put every AWS environment at risk A simple CodeBuild flaw put every AWS environment at risk DeadLock ransomware uses smart contracts to evade defenders Python libraries in AI/ML models can be poisoned w metadata OpenAI patches déjà vu prompt injection vuln in ChatGPT Fake Windows BSODs check in at Europe's hotels to con staff into running malware Hotel staff tricked into installing malware by bogus BSODs Your car’s web browser may be on the road to cyber ruin China's Ink Dragon hides out in European government networks Browser 'privacy' extensions have eye on your AI, log all your chats NCSC finds cyber deception tools work, if deployed right 10K Docker images spray live cloud creds across the internet 'Botnets in physical form' are top humanoid robot risk 'Botnets in physical form' are top humanoid robot risk Apache warns of 10.0-rated flaw in Tika metadata toolkit Novel clickjacking attack relies on CSS and SVG 'Exploitation is imminent' of max-severity React bug Swiss government bans SaaS and cloud for sensitive info Scattered Lapsus$ Hunters stress testing Zendesk weak spots HashJack attack shows AI browsers can be fooled with '#' New ClickFix attacks use fake Windows Updates to swipe creds Years-old bugs in open source took out major clouds at risk LLM-generated malware improving, but not operational (yet) 3.5B WhatsApp users' info scooped through enumeration flaw 3.5B WhatsApp users' info scooped through enumeration flaw 50k more ASUS routers pwned by evolving Beijing-linked op Overconfidence is the new zero-day as teams stumble through cyber simulations LLM side-channel attack could allow snoops to guess topic Landfall spyware used in 0-day attacks on Samsung phones MIT Sloan shelves paper about AI-driven ransomware Security hole slams Chromium browsers - no fix yet OpenAI Atlas Browser tripped up by malformed URLs Devs of VS Code extensions are leaking secrets en masse Chatbots that butter you up make you worse at conflict Beijing's RedNovember hacked critical US, global orgs Lazarus RAT code resurfaces in North Korean IT-worker scams Suspected Chinese spies broke into 'numerous' enterprises Deepfaked calls hit 44% of businesses in last year: Gartner Kaspersky: RevengeHotels returns with AI-coded malware Ruh-roh. DDR5 memory vulnerable to new Rowhammer attack HybridPetya ransomware dodges UEFI Secure Boot
Tile trackers leak unencrypted Bluetooth data, say boffins
Brandon Vigliarolo Brandon Vigliarolo · 2025-10-01 · via The Register - Security: Research

Research

Tile trackers are a stalker's dream, say Georgia Tech researchers

Plaintext transmissions, fixed MAC addresses, rotating 'unique' IDs, and more, make abuse easy

Tile Bluetooth trackers leak identifying data in plain text, giving stalkers an easy way to track victims despite Life360's security promises, a group of Georgia Tech researchers warns.

A trio of researchers led by assistant professor Michael Specter found [PDF] a number of flaws in Tile trackers, they say disprove many of Tile maker Life360's security and privacy guarantees. Most shocking, say the researchers, is the fact that Tile servers continually collect tag locations, MAC addresses, and unique ID codes without end-to-end encryption, while the tags themselves broadcast unencrypted Bluetooth signals that can be sniffed to track someone else's device.

What's worse, the MAC address of Tile trackers is static - and the periodically-cycled unique IDs are only semi-randomized and are reused over time. "This reuse pattern … allows an adversary to link private IDs over time and track the device," the researchers explained. 

The discovery by Specter and PhD students Akshaya Kumar and Anna Raymaker raises the specter of Bluetooth tag stalking, a known problem that has plagued companies like Life360 for years. The Tile maker was sued in 2023 by a pair of stalking victims who argued the company's partnership with Amazon, which opened Tile's tech up to the company's Sidewalk network, magnified the danger posed to stalking victims. Both Android and Apple devices have since had anti-stalking technology added to their more modern OS versions, but Tile trackers appear to still have significant problems, per the Georgia Tech team. 

Sign in to sound off

Register for The Register's Forums here.

According to their research, conducted by decompiling the Tile app on Android, studying its code and analyzing the Bluetooth and network traffic between a Tile Mate device manufactured in 2022 and a rooted Google Pixel 3XL smartphone, Tile's anti-stalking features are just as useless as relying on a tracker that constantly broadcasts a fixed MAC address in plain text over Bluetooth.

Because Tile tags are broadcasting unencrypted data, an attack could target device Bluetooth advertisements to identify specific tags and "construct detailed movement profiles of individuals without their knowledge or consent." 

One specific anti-stalking feature, Scan and Secure mode, makes Tile trackers visible to anyone who scans for them, a feature designed to detect rogue tags being used to stalk someone. But an anti-theft feature that the company advertises for putting hidden trackers on one's own devices can simply be enabled to hide the trackers from Scan and Secure. 

Tile's anti-theft feature can be subverted, however, since using anti-theft mode simply tells Tile's servers not to display results from those specific trackers, but "a user with a modified app can … [display] all privateIDs recorded" during a Scan and Secure search. Good news for a tech-savvy person worried about being stalked, but there's still a problem here, the researchers pointed out: Tile requires someone to actively scan for malicious trackers and doesn't passively keep a lookout for malicious, hidden trackers.

"All service providers except Tile have implemented anti-stalking algorithms that guarantee tag detectability at the operating system level, ensuring that these scans always run in the background and alert the user automatically," the researchers said. "Tile's reliance on manual, user-initiated scans creates dangerous detection gaps."

The researchers pointed out that this is a shortcoming of the fact that Tile is a third-party product - it doesn't have OS-level access to the devices it's installed on - just app-level access, meaning it can't perform background scans unless it were to use Google or Apple's own protocols. 

The team told us that, while it only examined the Tile Mate tracker, they have no reason to assume the rest of the company's products - or the third-party devices that implement its protocols - are any safer than the one they tested.

"It’d be surprising if [other Tile devices] worked differently," Specter told The Register in an email. "We found no evidence in the app to indicate that they were different."

Life360 … finds a way to avoid dealing with the problem

The Georgia Tech research team first reported their findings to Life360 in November of last year by reaching out to the company's CEO, Chris Hulls, and its support team because there was no official vulnerability disclosure channel available. Life360 did respond to the team, but communications apparently ceased after a time. 

"Tile acknowledged the vulnerabilities and engaged in dialogue until February 4, 2025, after which communications ceased," the research team wrote. The company was given an opportunity to reopen channels, the team said, but it doesn't appear to have ever done so. 

The researchers said they also offered to provide mitigations for the vulnerabilities they identified - like randomizing MAC addresses, end-to-end encrypting data, and finding a way to actually randomize unique device IDs - but it's not clear whether that information was shared with Life360 before communication dried up. 

According to a Life360 spokesperson, the company has made improvements since hearing from the researchers, but despite requests for specifics, it didn't provide any.

"Since receiving the submission, we have made a number of improvements," Life360 told The Register. It also disputed some of the team's claims, telling us that it does encrypt data in transit, and on its servers at rest. The company said it's also in the process of transitioning to rotating MAC addresses.

While the research team didn't answer questions about the status of its communication with Life360 or whether the company may have implemented any of its suggested changes, its findings suggest Life360's security promises may not be entirely accurate.

"We go to great lengths to ensure that your data is secure and that any information transmitted across our network is anonymous," Life360 says on its privacy policy page. "You are the only one with the ability to see your Tile location and your device location."

The Georgia Tech team's findings, if correct, suggest those assurances don't hold up in practice.

"Our work demonstrates that many of Tile's security claims were incorrect, insinuated but substantively wrong, [or] correct, but vulnerable to an active attacker," the team wrote. Without a clear response from Life360, it might be best to opt for a different brand of Bluetooth tracker if you're worried about privacy.

"In the version of the protocol we examined, Tile gets a user’s location at all times, and can share this with law enforcement or others," Specter told us. "Users that are sensitive to this kind of privacy issue should consider not using the system." ®