# gommzystudio/device-activity-tracker

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak sensitive device-activity patterns. (WhatsApp / Signal)

Repository: https://github.com/gommzystudio/device-activity-tracker
Canonical: https://ross.abutalabs.com/products/device-activity-tracker
Language: TypeScript
License: NOASSERTION
License Family: other
Topics: phone-number, signal, tracking, whatsapp, poc, baileys, exploit, messenger, nodejs, react, typescript, vulnerability, privacy
Last push: 2025-12-31T12:04:59+00:00

## Health v2 (maintenance only)
Score: 43/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 60, release rhythm 35, longevity 19
- inputs: {"age_days": 269, "days_push": 245, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5098, forks 697 (observed 2026-08-28T04:09:09.696441+00:00)

## What it is
A proof-of-concept application that tracks device activity of phone numbers on WhatsApp and Signal by measuring round-trip times of silent delivery receipts. It demonstrates a privacy vulnerability from academic research, exposing whether a device is active, in standby, or offline, and ships with a React web UI, Node.js backend, and CLI.

## Use cases
- track whether a phone number's device is active or in standby
- demonstrate WhatsApp delivery receipt privacy vulnerability
- reproduce the Careless Whisper research paper findings
- measure RTT of message delivery receipts on Signal and WhatsApp
- study device activity patterns via mobile data vs WiFi timing
- security research on mobile messenger surveillance

## When to choose
- you are a security researcher or educator demonstrating messenger privacy flaws
- you want to reproduce the Careless Whisper paper's RTT-based tracking technique
- you need a working PoC with web UI and CLI for WhatsApp/Signal receipt timing

## When to avoid
- you need a production monitoring or analytics tool
- you intend to surveil people without consent - this is unethical and likely illegal
- you need a hardened, licensed, supported product (license is non-standard and it is a PoC)

## Facets
- artifact type: application
- maturity: active
- function: security, privacy, monitoring, http-client, cli, developer-tools
- domain: security, privacy, messaging-platforms, developer-tools
- platform: cli, cross-platform
- tags: whatsapp, signal, rtt-analysis, delivery-receipts, surveillance-research, proof-of-concept, baileys, vulnerability-research, react-frontend, nodejs, web-server, docker

## Member repositories
- gommzystudio/device-activity-tracker (main) score 43

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:09.696441+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:02:13.686295+00:00, confidence not recorded.
  - readme: https://github.com/gommzystudio/device-activity-tracker (fetched 2026-08-28T04:09:09.696441+00:00, sha d3ff5083bf7e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
