The reassurance is that your phone will tell you if a stranger's tracker is following you. The standard that promise rests on has a published threat model, and it is candid. Mix trackers from two manufacturers and you slip through the gaps between their brand-specific detection — rated high impact, mitigation: none available. Use a GPS tracker instead of a Bluetooth one and you are outside the system altogether, which the document notes is exactly what attackers do in rural areas where the crowd network is thin. And anyone who can pick up your phone can switch the background detection off. The alert is real. It is also the version of the problem that was easiest to solve. Every anti-stalking alert on every tracker works by asking one question: does this belong to you? If the answer is yes, nothing happens. So the protection holds against a stranger slipping a tag into your bag, and dissolves in the situation that actually kills people — the partner who set up your phone, who pays for the family plan, whose name is on the account. The tag is registered to them, or to the account you share, and by the standard's own logic that makes it legitimate. The IETF threat model writes it down plainly: the target is tracked by their own tag, without any warning. The alert was built for the pickpocket, not the person you live with.
What they claim: Google presents Find Hub as a network users join, and sells the Pixel Tag on the strength of its reach across more than a billion Android devices.
What we found: The Find Hub network is switched on automatically when a Google Account is added to an Android device — participation is the default state, not a choice the user makes. Android Authority's teardown of the Find Hub app found Google preparing to widen automatic enrolment to further triggers: enabling Location access, syncing a Fast Pair accessory, pulling recent location data from another device, or simply ceasing to use a linked device. Each would give the user 48 hours to opt out, raised from 24 hours in earlier builds. Those expanded triggers are unreleased code found in a teardown, not shipped behaviour; the Google Account default is current behaviour today.
What they claim: Google and Apple present DULT — the joint Detecting Unwanted Location Trackers standard — as the cross-platform protection that makes consumer trackers safe, with unknown-tracker alerts on both iOS and Android.
What we found: The IETF DULT threat model draft records that "Attackers may use a mix of Tags from different manufacturers (e.g., Apple AirTags, Tile, Samsung SmartTags) to exploit gaps in vendor-specific tracking protections", and that "Many detection systems are brand-dependent, making them ineffective against mixed Tag deployments" — rated high impact, with no effective mitigation available. GPS trackers fall outside the detection model entirely, and the draft notes attackers are "especially likely to use GPS trackers in rural areas and areas with low Crowdsourced Network saturation." An attacker with access to the target's phone "might intentionally disable background Unwanted Tracking detection on a Target's Device." A USENIX Security 2025 evaluation by Gerhardt et al. tested the reliability of unwanted-tracking notifications on iOS and Android and participants' ability to locate a hidden tracker, choosing AirTag precisely because it carries among the strongest protections on the market.
What they claim: Unknown-tracker alerts warn you when a tracker you do not own is travelling with you.
What we found: The IETF DULT threat model documents the "Tracking Using Target's Own Tag" case, in which "the Target is effectively tracked by their own Tag without any warning" because the protocol assumes the registered owner is legitimate. Where one person set up both phones, or the account is shared across a family plan, the tracker is owned — so no alert is ever generated. The draft records this as a gap the protocol does not close.