USENIX Security2026Top-tier venue
Security and Privacy Analysis of Tile's Location Tracking Protocol
Akshaya Kumar, Anna Raymaker, Michael A. Specter
Abstract
We conduct the first comprehensive security analysis of Tile, the second most popular crowd-sourced location-tracking service behind Apple's AirTags. We identify several exploitable vulnerabilities and design flaws, disproving many of the platform's claimed security and privacy guarantees: Tile's servers can persistently learn the location of all users and tags, unprivileged adversaries can track users through Bluetooth advertisements emitted by Tile's devices, and Tile's anti-theft mode is easily subverted.
Despite its wide deployment-millions of users, devices, and purpose-built hardware tags-Tile provides no formal description of its protocol or threat model. Worse, Tile intentionally weakens its antistalking features to support an antitheft use-case and relies on a novel "accountability" mechanism to punish those abusing the system to stalk victims.
We examine Tile's accountability mechanism, a unique feature of independent interest; no other provider attempts to guarantee accountability. While an ideal accountability mechanism may disincentivize abuse in crowd-sourced location tracking protocols, we show that Tile's implementation is subvertible and introduces new exploitable vulnerabilities. We conclude with a discussion on the need for new, formal definitions of accountability in this setting.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0b09bf6b-7ba5-46d6-848e-9732bab40ae6Builds on4
- Security and Privacy Analysis of Samsung's Crowd-Sourced Bluetooth Location Tracking SystemTingfeng Yu, James Henderson, Alwen Tiu, Thomas HainesUSENIX Security 2024 · 20 citations
- Abuse-Resistant Location Tracking: Balancing Privacy and Safety in the Offline Finding EcosystemHarry Eldridge, Gabrielle Beck, Matthew Green, Nadia Heninger et al.USENIX Security 2024 · 11 citations
- A Thorough Security Analysis of BLE Proximity Tracking ProtocolsXiaofeng Liu, Chaoshun Zuo, Qinsheng Hou, Pengcheng Ren et al.USENIX Security 2025
- Extended Diffie-Hellman Encryption for Secure and Efficient Real-Time Beacon NotificationsLiron David, Omer Berkman, Avinatan Hassidim, David Lazarov et al.S&P 2025
Related papers
- AirTag-Facilitated Stalking Protection: Evaluating Unwanted Tracking Notifications and Tracker Locating FeaturesDañiel Gerhardt, Matthias Fassl, Carolyn Guthoff, Adrian Dabrowski et al.USENIX Security 2025
- Tracking You from a Thousand Miles Away! Turning a Bluetooth Device into an Apple AirTag Without Root PrivilegesJunming Chen, Xiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2025
- Snatcher: Apple Find My Network Exposes Your Lost Devices To StrangersZhenyu Ren, Yanbo Zhang, Boya Liu, Mo LiCCS 2026
- PrivacyShield: Relaying BLE Beacons to Counter Unsolicited TrackingFlorian Hofhammer, Daniele Antonioli, Mathias PayerUSENIX Security 2026
- WILD Attack: Stealthy Undermining of Wi-Fi-Based Geolocation Through Remote Crowdsourced Data InjectionChangjia Zhu, Xiao Han, Parush Gera, Zhuo Lu et al.USENIX Security 2026
