Part I · Chapter 6

The Omniscient Pocket

The phone in a target’s pocket erases the perpetrator’s oldest limit — proximity — handing him something close to omniscience with no wound to show for it, and making every other tactic in this book more precise.

For most of history, monopolizing a person’s reality required physical proximity. A perpetrator had to be present, or have an agent present, to know where someone went, who they spoke to, what they said. That requirement has quietly disappeared. A phone in a pocket now makes all of it knowable in real time, from anywhere — and the target frequently has no way of knowing the knowing is happening at all.

The infrastructure for this is neither exotic nor hard to obtain. Commercial spyware, sold openly under names like mSpy and FlexiSPY and marketed as “parental monitoring” or “employee monitoring” software, can be installed on a phone to give a remote party access to messages, calls, location, contacts, and browsing history.1 SIM cards can be cloned to intercept communications outright. A phone can be rooted or jailbroken to grant administrative access to everything the operating system controls. Cloud accounts, if their credentials are known or guessed, expose whatever photos, messages, and contacts sync to them, often without the account holder ever seeing a login notification. Shared home networks can be monitored directly. Smart-home devices — always-listening speakers, networked cameras, internet-connected locks — extend the same access into physical space. And even without any of it, metadata alone — who called whom, when, for how long, from where — reveals an enormous amount without anyone needing to hear a single word that was said.

None of this is standalone coercion. It is infrastructure — the layer that makes every other mechanism more effective by removing the perpetrator’s need to guess.

Where an abuser once had to infer what a partner might be thinking or doing, digital surveillance supplies the answer directly: every message sent and received, every call placed, every website visited, every photograph taken, every location at every hour, every companion at each of them. The perpetrator’s model of the target’s life becomes, or feels, complete and continuous — close enough to omniscience that the practical difference stops mattering. Any deviation from the official story becomes instantly catchable: I was at work meets no, you were at your sister’s at three; I saw your location, and there is no arguing with a location log.

Isolation, once dependent on physically preventing contact, becomes instead a matter of monitoring and punishing it. A text to a friend, a call to a family member, an email to a support line — all visible to the perpetrator in real time. Reaching out no longer requires merely finding an opportunity; it requires accepting the risk that the attempt itself will be discovered and answered with retaliation. This is a more totalizing form of control than simple prevention: it doesn’t need to stop every attempt at contact, only to make every attempt feel dangerous enough that most never happen.

Surveillance also arms gaslighting with something it never had before: proof. You said you were at work, but you were at Starbucks — you’re lying. You texted your mother that you’re unhappy — that’s betrayal. I can see what you’ve been searching; is that really what you’re interested in? A victim who cannot trust her own memory against digital evidence of her own movements finds the old defense — I know what actually happened — much harder to sustain: the perpetrator, for once, actually has the receipts.

Threats acquire the same new precision. I saw you texting Mark. Don’t talk to him again. I know you looked at apartments. I have access to your cloud; I can see everything you write. A threat backed by specific surveillance data is far more credible than a vague one: the victim knows the perpetrator actually knows, which forecloses the usual hope that this particular thing went unnoticed.

And escape itself becomes close to impossible to attempt covertly. Job applications, housing searches, calls to a domestic-violence hotline, consultations with an attorney — all of it potentially visible before the victim gets far enough to act. Surveillance watching for an exit doesn’t need to catch the exit in progress; it only needs to see the search history that precedes it.


The scale of this in intimate-partner contexts is not speculative. A survey of US domestic-violence shelters found seventy-one percent of abusers had monitored survivors’ computer activity, and fifty-four percent had tracked their phones with stalkerware.2 A separate study in the Journal of Family Violence, January 2020, found sixty to sixty-three percent of survivors in domestic-violence programs reported some form of technology-based abuse.3 Researchers at Cornell have separately documented that stalkerware applications are simple to install, difficult to detect, and marketed through a diffuse, largely unregulated web of blogs, videos, and online advertisements — putting the barrier to acquiring this capability, for practical purposes, close to nonexistent.4

At organizational scale, closed groups extract the same visibility by requiring members to surrender phone passwords, installing monitoring software on shared devices, and in some documented cases enlisting members to watch each other — turning the community itself into a distributed surveillance network with no single point of installation to detect. Institutions with legitimate authority over devices — hospitals, schools, prisons, employers — layer their own monitoring on top: institutional email and messaging, network traffic on institutional WiFi, location tracked through badge readers and key cards, biometric identification through fingerprints or facial recognition.

At the largest scale, states run the same architecture with resources no individual or organization can match. The Snowden disclosures of 2013 documented bulk collection of communications data by the NSA and Britain’s GCHQ — calls, texts, emails, and searches copied and stored at a scale that made individual targeting almost beside the point. The collection came first; any targeting could be applied to it retroactively.5 The Five Eyes intelligence alliance, spanning the United States, the United Kingdom, Canada, Australia, and New Zealand, shares this data across borders.6 Israeli-developed Pegasus spyware, sold to governments under the banner of national security and documented in use since 2016, grants remote access to a target’s calls, location, photos, and microphone, and has been documented against journalists, human-rights activists, and political dissidents worldwide.7 China’s social credit system extends the same logic into an explicit reward-and-punishment architecture, monitoring citizens’ online behavior, financial transactions, and physical movements and tying results to social and economic consequences — though the popular image of a single unified national “score” ranking every citizen is misleading. What actually exists is a fragmented patchwork of municipal pilots, court blacklists, and corporate schemes of uneven reach, not one centralized algorithm rating everyone; the direction of travel is real, but the totalizing version is, so far, more feared than built.8


What makes digital surveillance categorically different from the physical surveillance of an earlier era is its invisibility. A person being followed can, with effort, notice the follower. A person whose phone has been quietly compromised typically cannot. Modern surveillance tools are built to leave the victim no reliable signal that anything is happening: monitoring runs continuously, awake or asleep; it requires no physical presence at all; well-designed spyware evades detection entirely, hiding from app lists, battery statistics, and data-usage logs; and it frequently leaves no forensic trace unless the perpetrator is careless or the device is examined by an actual expert.

This invisibility produces its own distinct form of harm, independent of whether monitoring is actually occurring at a given moment. A victim who suspects surveillance cannot reliably distinguish three very different possibilities: that she is being actively monitored, that the perpetrator simply guessed right this once, or that a coincidence has been misread as evidence. The uncertainty itself becomes coercive. Believing surveillance is likely, she begins behaving as though it is certain, curtailing her actions even in the many moments when no one is watching at all.

Even when spyware is discovered, deniability tends to survive. I installed it to keep you safe, not to control you. You must have put it there yourself. Anyone could have installed that. It’s just a parental app. Each denial reframes an intrusive act as protective, accidental, or someone else’s doing — and because the technical sophistication of the tool is real (modern spyware genuinely does survive phone resets, operate below the level normal troubleshooting would find, and mimic legitimate app behavior to avoid suspicion), the victim frequently cannot produce, on her own, the technical proof that would settle the question.

Proving surveillance after the fact is genuinely difficult. It typically requires a forensics expert, physical access to the device, and a device that hasn’t already been reset or updated in a way that erases the relevant traces — conditions a careful perpetrator can defeat simply by acting first. Some evidence does persist under the right conditions: installation logs that forensic examination can recover even after an app has been deleted, unusual patterns in network traffic, unauthorized-access logs on cloud accounts, purchase records for trackers or monitoring hardware, and messages in which a perpetrator lets slip knowledge he shouldn’t have had. Other categories — real-time location tracking through certain services, message interception via SIM cloning, telecom-level call interception of the kind the NSA and GCHQ conduct — leave few or no traces a victim, rather than a state investigator with subpoena power, could ever recover on her own.


Mass state surveillance produces a form of coercion that requires no individual targeting to take effect. The mere possibility of being monitored changes behavior on its own — a documented chilling effect in which people self-censor simply because surveillance might be occurring, whether or not it actually is. States that collect everyone’s data can apply selective enforcement to a chosen few — a dissident, a journalist, a member of a minority group — years after the fact, using data gathered long before anyone knew it would matter, turning “we didn’t do anything wrong at the time” into no defense at all against a retroactive prosecution built from an archive nobody knew was being kept.

This intersects directly with two other mechanisms already described. A state that possesses a target’s entire communications history can use that archive to construct exactly the narrative reversal an earlier chapter documented — presenting a target’s own words, stripped of context, as proof of instability or extremism — and can pair it with the psychiatric relabeling a later chapter describes in detail. The target’s claim of being surveilled becomes, in the state’s own telling, further evidence of paranoia: a closed loop in which the very existence of the surveillance archive discredits anyone who correctly suspects it exists.

Victims who discover surveillance frequently do not report it, for reasons that compound rather than cancel out: fear that a perpetrator who has already demonstrated this level of access will retaliate; shame at having been watched and violated in ways that feel deeply personal; a learned distrust of one’s own judgment after enough gaslighting that even the discovery of real spyware triggers a reflexive would he really do that, or am I imagining it; and practical barriers — forensic examination costs money, requires physical access to a device, and takes time a victim in crisis frequently doesn’t have.

Establishing state-level surveillance against a specific individual in real time, while it is happening, is close to impossible by design: the same invisibility that makes the mechanism effective also makes it resistant to contemporaneous proof. What works instead is the forensic bridge. Establish the mechanism historically first — Zersetzung’s methods, COINTELPRO’s documented programs, the NSA’s own disclosed practices, Pegasus’s leaked target list. Once a mechanism is documented as a real, repeated pattern of state behavior, an individual’s contemporary claim of something structurally similar stops sounding like paranoia and starts sounding like a plausible instance of a known phenomenon. Nothing about the surveillance itself changes between the two readings. What changes is that she can finally point past her own word — to Zersetzung’s files, to a leaked target list — and let the documented record stand where her testimony alone could not.

Notes

  1. Commercial spyware products mSpy and FlexiSPY, marketed as “parental” or “employee” monitoring software, providing remote access to messages, calls, location, contacts, and browsing history. The stalkerware products mSpy and FlexiSPY are documented in Christopher Parsons et al., The Predator in Your Pocket: A Multidisciplinary Assessment of the Stalkerware Application Industry (The Citizen Lab, University of Toronto, 2019).↑

  2. The figures that 71% of domestic abusers monitored survivors’ computer activity and 54% tracked their phones with stalkerware come from Kaspersky, “The State of Stalkerware in 2019” (Securelist), which attributes them to an NPR survey of 72 US domestic-violence shelters. https://securelist.com/the-state-of-stalkerware-in-2019/93634/ For victim-service-agency data specifically, NNEDV’s Safety Net survey reports that 72% of programs said a survivor’s location was being tracked: https://nnedv.org/latest_update/technology-abuse-experiences-of-survivors-and-victim-service-agencies/↑

  3. Jill Theresa Messing, Meredith Bagwell-Gray, Megan Lindsay Brown, Andrea Kappas, and Alesha Durfee, “Intersections of Stalking and Technology-Based Abuse: Emerging Definitions, Conceptualization, and Measurement,” Journal of Family Violence 35, no. 7 (2020): 693–704: across the quantitative samples, 60–63% of survivors receiving services from domestic-violence programs reported experiencing technology-based abuse by an intimate partner.↑

  4. Rahul Chatterjee et al., “The Spyware Used in Intimate Partner Violence,” 2018 IEEE Symposium on Security and Privacy (Cornell Tech / Clinic to End Tech Abuse) — stalkerware applications are simple to install, difficult to detect (antivirus tools “universally fail” to flag them), and marketed through a diffuse, largely unregulated web of blogs, videos, and online advertisements. https://nixdell.com/papers/spyware.pdf; summary at https://news.cornell.edu/stories/2018/07/apps-make-it-easy-domestic-abusers-spy↑

  5. Snowden disclosures, 2013: bulk collection of communications data by the NSA and GCHQ. Disclosed by Edward Snowden in June 2013 via The Guardian and The Washington Post; see Glenn Greenwald, No Place to Hide: Edward Snowden, the NSA, and the U.S. Surveillance State (Metropolitan Books, 2014).↑

  6. Five Eyes intelligence alliance (United States, United Kingdom, Canada, Australia, New Zealand) sharing surveillance data. The UKUSA Agreement underpinning the “Five Eyes” alliance (United States, United Kingdom, Canada, Australia, New Zealand), declassified and released by the NSA and GCHQ in 2010.↑

  7. Pegasus spyware (NSO Group, Israel), sold to governments and documented in use since 2016, when UAE human-rights activist Ahmed Mansoor was targeted (Bill Marczak and John Scott-Railton, “The Million Dollar Dissident: NSO Group’s iPhone Zero-Days Used Against a UAE Human Rights Defender,” The Citizen Lab, August 2016); subsequently documented in use against journalists, human-rights activists, and political dissidents worldwide by The Citizen Lab and Amnesty International’s Security Lab. Examined in full in Chapter 16.↑

  8. China’s Social Credit System, monitoring citizens’ online behavior, financial transactions, and physical movements via camera networks, linked to social and economic consequences. See the People’s Republic of China State Council’s 2014 “Planning Outline for the Construction of a Social Credit System” (the founding policy document).↑

From The Machinery of Compliance by Willow Whitman · edition 1.0.2, · free under CC BY-NC-ND 4.0 · corrections

The whole book

Forty-nine chapters, free in every sense

Read it in the browser, or take the EPUB or PDF and keep it. No sign-up, no tracking, nothing to pay.

Read online Download EPUB or PDF