Installing a tracker on someone's device takes less than five minutes. No engineering degree or special skills required; physical access to the phone for the time it takes to make a coffee is enough. That alone should give us pause.

On GitHub there's a repository called device-activity-tracker, developed by gommzystudio. The project logs device activity, movement, apps in use, and behavioral trends. It's presented as a tool for personal or parental monitoring, open-source and with clear documentation that lets anyone with basic know-how deploy it. What's interesting here isn't the project itself—which has legitimate uses—but what it represents: total accessibility to surveillance.

For a long time, spying demanded significant resources. States had specialized units; corporations turned to intelligence firms. There was a barrier to entry that, without morally justifying the act, at least limited its scope. That barrier has dissolved gradually, almost imperceptibly.

This is not a new phenomenon. Gutenberg's printing press enabled propaganda just as much as knowledge. The internet expanded communication, but also disinformation. Every technological leap that lowers barriers lowers them across the board, for good and ill alike. Digital surveillance follows the same trajectory.

Device-activity-tracker works simply: it's installed as an app on an Android device, runs in the background, and sends reports to whoever configured it. It captures apps used, time spent, schedules, and location. It documents behavior with a precision unimaginable to a detective in the nineties. All of it free, with the repository public and detailed installation guides. Nothing stops it from being used with or without the knowledge of the person being monitored.

This is where the complexity kicks in, because there are reasonable applications for these tools. Parents monitoring risky content on their kids' devices. People auditing their own digital habits. Companies monitoring equipment with consent. The problem isn't the tool itself, but the absence of any obstacle between ethical uses and those that invade someone else's privacy.

Organizations tend to treat data security as a purely technical matter when it actually involves social design. Installing monitoring software without consent isn't an advanced hack; it's a human choice. Those choices depend on norms, culture, and consequences. Code has no built-in ethics because ethics isn't easily encoded.

This connects to broader debates about privacy and surveillance that aren't resolved by more or less technology, but by clear criteria for legitimacy. Could the norm of installing trackers without consent be universalized? No. A world of mutual spying would destroy itself.

What's both intriguing and alarming is the historical record of what happens when surveillance becomes normalized without defined limits. The Stasi in East Germany recruited one in every sixty citizens as informants. Not because of some inherent malice, but because the structure made spying easier, cheaper, and at times socially rewarded. Today, technology removes even that effort; one person can monitor dozens with open tools and an internet connection.

In closed communities like those of East Germany, mutual surveillance eroded trust, but it also generated resilience in unexpected ways: informal support networks, private codes of communication, underground solidarities. The abuse was real, but human responses adapted. That doesn't justify the abuse; it complicates it.

The same dynamic shows up in cases where users assume privacy without any real guarantee. There's an assumption that if something can't be seen, it doesn't exist. But invisibility isn't the same as freedom from scrutiny.

So what can be done? A few concrete measures make a difference.

First, informed consent should be the bare minimum. Any monitoring tool—parental, workplace, or personal—requires that the person being monitored know it exists. That's what separates oversight from intrusion. Several countries are already legislating on this, though enforcement varies widely.

Second, introducing technical friction has ethical value. When an action is too easy, it gets carried out without reflection. The creators of these tools can—and should—build in barriers: explicit confirmations from the monitored device, for instance. This doesn't block legitimate uses, but it complicates improper ones.

Third, detection tools urgently need improvement. If installing a tracker is simple, detecting one should be equally simple. Apps already exist that scan running software and flag anomalies. Adopting them as routine, the way we do antivirus software, is technically feasible and culturally within reach.

Open source and good intentions don't guarantee positive outcomes. Human systems don't work that way. Intent matters, but design matters more. The current design of digital surveillance—accessible and hidden—favors both legitimate use and abuse in equal measure. Recognizing that opens space for redesigns that prioritize fairness.

The tension between technological transparency and privacy is genuinely difficult, and anyone who claims otherwise is probably oversimplifying. What matters most is understanding this ease of access so we can make informed decisions about our devices, the access we grant, and the tools we install.

Surveillance no longer depends on oppressive states or powerful corporations. Five minutes and a GitHub repository will do. If we don't address this, someone else will decide it for us.

Stones don't lie, but historians sometimes do.


Sources:

1. gommzystudio. device-activity-tracker. GitHub. https://github.com/gommzystudio/device-activity-tracker

2. Garton Ash, Timothy. The File: A Personal History. Random House, 1997. (On the Stasi surveillance system)

3. Solove, Daniel J. Nothing to Hide: The False Tradeoff Between Privacy and Security. Yale University Press, 2011.

4. Electronic Frontier Foundation. Surveillance Self-Defense. https://ssd.eff.org

5. Zuboff, Shoshana. The Age of Surveillance Capitalism. PublicAffairs, 2019.