Comments

Hacker News

"But, but, the Tile TOS says they'll fine a stalker a million dollars!"

Life360 is such a skeevy bullshit company.

by kotaKat

This explains why I'm seeing commercials for Life360 now for the first time ever: They've developed a new revenue stream by selling everybody's location to advertisers.

Now deleted from my family's phones.

by dreamcompiler

Does anyone know whether https://mygrid.app/ is trustworthy? Development had been glacial, but looking at their website it seems they finally support degoogled android which is a huge step forwards.

by kefabean

I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?

by alt227

It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model.

> Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag

Though it makes me wonder... What's the private key? If the public key is attached to the tag, how is the device getting it? I'm guessing it gets shared during pairing.

by ollien

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • "But, but, the Tile TOS says they'll fine a stalker a million dollars!"

    Life360 is such a skeevy bullshit company.

  • This explains why I'm seeing commercials for Life360 now for the first time ever: They've developed a new revenue stream by selling everybody's location to advertisers.

    Now deleted from my family's phones.

  • Does anyone know whether https://mygrid.app/ is trustworthy? Development had been glacial, but looking at their website it seems they finally support degoogled android which is a huge step forwards.
  • I dont get why this is really an issue when there are devices on Temu you can easily buy that are actually designed for stalking. Why would anybody with a genuine nefarious purpose spend their time hacking a tile when they can just buy a generic Chinese gps transponder?
  • It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model.

    > Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag

    Though it makes me wonder... What's the private key? If the public key is attached to the tag, how is the device getting it? I'm guessing it gets shared during pairing.

  • Last author on the paper here (https://arxiv.org/pdf/2510.00350). Happy to answer any questions!