# Surveillance ## Notebook evidence [[Scanned_20260730-1806#Page 14 — `Scanned_20260730-1806.pdf`, PDF page 14|PDF page 14]] contains the single word “Surveillance” as a divider before the device-attestation and Android package-inspection sequence. ## Interpretive role The heading records the researcher's question and concern. The following pages investigate hidden software layers, package privileges, trackers, manifests, carrier components, and provenance. ## Evidentiary boundary The heading does not establish that the device was compromised or that any named application conducted surveillance. The archive should require capability, permission, runtime use, network behavior, signer, installer, and known-good comparison before making such a claim. ## Relationships [[Mobile Application Forensics]] · [[System Privilege]] · [[Package Provenance]]. ## Scanned_20260730-1946 overlay — XZ/Tukaani PDF page 7 circles [[XZ Utils|XZ]] inside a transitive package dependency graph; PDF page 20 returns to the exact upstream URL and names the [[Tukaani Project]]. **Owner-supplied retrospective clarification:** Bryant McGill states that, at the time of writing, he believed XZ/Tukaani's position in the dependency architecture was intentional and part of a larger surveillance architecture. He says this suspicion preceded public disclosure of [[CVE-2024-3094]]. The 2024 incident established intentional malicious subversion of XZ's upstream/release chain, but it does not prove that the earlier suspected surveillance architecture involved the same actors, versions, mechanism, or purpose. This record distinguishes early suspicion from later technical attribution.