Part II · Chapter 21

The Body, the Car, and the Door

The cheapest consumer devices — a coin-sized tracker, a fitness band, a smart lock — turn a body, a car, and a door into instruments of surveillance; and, as a Fitbit that outlasted its owner’s killer showed, the same data can convict.

No device in this book’s account has produced a more concentrated legal and criminal record than a tracker the size of a coin, sold for about thirty dollars to help someone find a misplaced wallet.

Apple’s AirTags are the subject of an active class-action docket, Hughes v. Apple, filed in December 2022 by two women alleging Apple released the product despite internal warnings about stalking misuse and failed to build in adequate safeguards before launch; the case has grown to more than three dozen plaintiffs.1 In March 2024, a federal judge denied Apple’s motion to dismiss in part, allowing three California plaintiffs’ negligence and product-liability claims to proceed on the theory that AirTag’s safety-feature failures were directly tied to their stalking injuries; class certification was later denied because the individualized nature of each incident made a single class impractical, and more than thirty individual lawsuits are now proceeding separately against the company.2 An active docket still generating new filings years after the original complaint reflects a recurring pattern, not a single litigated incident.

The criminal record behind that docket is built from real, named cases. A man in Indiana County, Pennsylvania, was arrested in January 2025 after allegedly tracking his ex-girlfriend’s car with an AirTag; she was alerted by her own iPhone that an unknown tracker was traveling with her.3 A Pennsylvania man was charged in April 2025 with allegedly duct-taping an AirTag to a victim’s car.4 In Tulsa, Oklahoma, investigators logged a cluster of women who found AirTags planted to track them.5 And in the most severe case the courts have actually resolved, Gaylyn Morris hid an AirTag in the back seat of Andre Smith’s car in June 2022, tracked him to a bar outside Indianapolis, and ran him over twice in the parking lot; he died of traumatic asphyxia. A Marion County jury acquitted her of murder and convicted her of voluntary manslaughter, accepting that she had killed in sudden heat rather than by design, and she was sentenced to eighteen years. Smith’s mother is among those now suing Apple.6 A Vice investigation obtained police records from eight departments documenting a hundred fifty AirTag-related cases over an eight-month span, fifty of them specifically involving women who received a notification that an unknown tracker was traveling with them. Vice’s own reporting characterized this as “just the tip of the iceberg,” since departments willing to respond to a records request are not a random or complete sample of what’s actually happening.7 A related piece of reporting, “The Legal System Is Completely Unprepared for Apple AirTag Stalking,” documents that many jurisdictions’ stalking and harassment statutes were never written with covert Bluetooth trackers in mind, producing real prosecutorial gaps even where police recognize the pattern.8

The industry’s response reads as its own form of confirmation: companies do not build dedicated anti-stalking infrastructure for products that pose no real risk. Apple published a direct statement in February 2022 acknowledging the problem and describing new safeguards — unwanted- tracking alerts when an unregistered AirTag travels with a phone for an extended period, a precision-finding tool to locate the specific device, and an audible chirp on trackers separated from their owner.9 More tellingly still, Apple and Google, direct competitors, jointly published an industry-wide technical standard in 2023 called Detecting Unwanted Location Trackers, rolled out across both Android and iOS.10 Two competing platforms building a shared standard is stronger evidence that the risk is industry-wide, not an Apple-specific defect.


A fitness tracker records something no other device here captures: a person’s own body, continuously, whether or not they’re thinking about being tracked. That record has, in one concluded case, done what no smart speaker’s contested legal fight has managed — decided a murder trial outright.

Connie Dabate was killed in her family’s Connecticut home on December 23, 2015. Her husband, Richard, told police a masked intruder had broken in, killed her, and tied him to a chair; investigators found him with superficial knife wounds and zip-tied at one arm and leg. Connie’s Fitbit data told a different story: it showed her still moving inside the house at 10:05 in the morning, a full hour after the time her husband’s account placed her death. That contradiction, timestamped movement data against a suspect’s own sworn statement, became the central evidence in the case. Richard Dabate was convicted of murder, tampering with evidence, and making false statements to police in May 2022, sentenced to sixty-five years, with prosecutors arguing a motive built on a years-long affair with another woman who was pregnant at the time of the killing. Connecticut’s Supreme Court upheld the conviction on appeal despite finding some prosecutorial improprieties along the way11 — meaning this case is as fully and finally adjudicated as any this book has examined. It is this project’s clearest instance of reconstruction succeeding, in an actual courtroom, over belief.

A different mechanic shows what happens when individually anonymous data becomes dangerous only in aggregate. In early 2018, an Australian researcher noticed jogging routes glowing on the fitness app Strava’s public heatmap in the middle of the Syrian desert — precisely where American and allied military bases were located. Journalists confirmed that the aggregated, ostensibly anonymized fitness data was exposing base perimeters, supply routes, patrol paths, and the daily movement patterns of soldiers and contractors across Iraq, Afghanistan, and Syria. The U.S. Department of Defense launched a formal review, acknowledging that personal fitness-tracker data could genuinely endanger military operations, and Strava responded by restricting street-level heatmap detail to registered users only.12 No single user’s data caused this; the risk existed only once enough individually anonymized routes were stacked together — a distinction worth carrying into any ordinary use of a public fitness app by someone trying to keep an address or daily routine private from one specific person. Anonymized and private are not the same guarantee, and this is the one fully documented, government-acknowledged case of it.

A third mechanic shows the same lesson at the level of a simple default setting. In 2011, Fitbit’s manual activity log let users record any physical activity, including sexual activity, categorized by intensity from “passive, light effort” to “active and vigorous” — and new profiles defaulted to publicly searchable, discoverable through ordinary search engines. Most users never checked or changed this setting. A tech entrepreneur discovered that summer that hundreds of users’ sexual-activity logs were indexed and searchable on Google, Yahoo, and Bing. Fitbit’s response was direct: it had the indexed data delisted, changed the default for new users to private, and removed sexual activity as a trackable category.13 It is the same gap this book named in a smart television’s disclosed-but-unread privacy policy: a setting existed, was within the user’s control, and still produced a real, publicly reported privacy failure, because almost no one thought to check it.


Every device in this chapter assumes, implicitly, that the lock on the door itself is at least reliable. The last mechanic is the discovery that this assumption does not always hold — sometimes in the most literal sense.

A researcher presenting at DEF CON’s twenty-eighth conference disclosed a flaw in August smart locks: when an owner revokes a guest’s access through the app, the guest can continue locking and unlocking the door as though nothing had changed, until the owner’s own device next communicates directly with the lock. The revocation takes effect only locally, not immediately, and not remotely.14 It is the literal scenario this book’s ownership-model material has been building toward across connected cars, hubs, and cameras: a person believes, in good faith, that they have removed someone’s access after a relationship ends, and the removal silently fails at the technical level while the app’s own interface reports success. Whether this particular flaw has since been patched matters less than the class of failure it demonstrates — an interface reporting, in good faith, a revocation the hardware has not yet honored — because specific products age out of any list like this one, and the class survives every patch cycle. The durable question for a reader is not whether the August lock was fixed but whether anything now standing between them and a door has been tested for exactly this gap between what the app says and what the mechanism does. Two further vulnerabilities in the same product line compound the concern: one security researcher found the August Smart Lock Pro transmitted its WiFi credentials completely unencrypted, giving anyone within range full access to the home network, not merely the lock;15 another documented that intercepting the Bluetooth pairing handshake lets a nearby device unlock the door stealthily, entirely without the owner’s knowledge.16

A structurally distinct pattern involves not an intimate partner but a landlord. The Electronic Frontier Foundation documented in 2023 that smart locks are increasingly installed in rental units, often without a tenant’s permission, creating a standing stream of entry-log location data accessible to the landlord and sometimes to law enforcement or the lock vendor — and, critically, letting a landlord lock a tenant out instantly and without notice, a capability an ordinary deadbolt has never had.17 In New York City, tenants forced a settlement in 2019 after a landlord attempted to require smart-lock use building-wide; the settlement required the landlord to offer tenants a physical-key alternative, and the lock vendor involved subsequently changed its own privacy policy to remove references to marketing use and collection of tenants’ location data.18 A separate case in a Massachusetts housing court involved a tenant alleging a smart lock box had been installed on his unit without permission, and that a subsequent eviction attempt was retaliation for his demand that the device be disconnected.19 This is the same ownership-model problem, its asymmetry now made structural rather than merely relational: a tenant living behind someone else’s smart lock has, by design, less standing over the device securing his own front door than the person who installed it.

A final, quieter failure mode involves no misuse of legitimate access at all — only a company’s own solvency and competence, which a mechanical lock has never once depended on. In August 2017, a botched remote firmware update from the lock manufacturer LockState disabled smart-code access for an estimated five hundred customers at once, locking them out of the smart-entry function of their own doors; the failure hit Airbnb hosts particularly hard, some of whom scrambled to deliver physical keys to guests who had already checked in.20 A well-funded, high-profile smart- lock startup called Otto suspended operations in December 2017 before shipping a single unit to customers who had pre-ordered seven-hundred-dollar locks, after an acquisition meant to rescue the company collapsed on the day it was to close.21 Neither case involves a person misusing access they were never meant to have. Both demonstrate that a smart lock’s security depends on a company remaining solvent and competent indefinitely — a dependency the humblest mechanical deadbolt has never carried, and one worth weighing against whatever convenience a smart version of the same object provides.


Every mechanic in this chapter so far weaponizes a device the target owns. The last one weaponizes the system built to protect them, and needs no device in the home at all. “Swatting” is the placing of a false emergency report — a hostage, a shooting, a bomb — against a target’s address, so that a heavily armed police unit is dispatched to break down their door expecting lethal violence. On December 28, 2017, a swatter named Tyler Barriss, enlisted over a dispute about an online video game, phoned in a fake hostage situation at a Wichita address; officers arriving at the door shot and killed Andrew Finch, a twenty-eight-year-old man who had nothing to do with the dispute and no idea why armed police were outside his home. Barriss was sentenced to twenty years, the longest term yet imposed for the practice.22 The address, the telephone network, and the emergency response all functioned exactly as designed; the attack is simply aiming that infrastructure at a chosen person from a distance, the operator’s hand nowhere near the door the force comes through.

Across all of it, though, this is the layer of the book that has produced the most convictions, not the fewest. An AirTag carries a registration tying it to an Apple ID; a victim’s own phone timestamps the moment it was detected; a Fitbit outlasted the man who invented an intruder to explain his wife’s death; even Barriss, calling from another state, was traced through the network he used and sentenced to twenty years.

Notes

  1. Hughes v. Apple (filed December 2022, N.D. Cal.): two women alleged Apple released AirTags despite internal warnings about stalking misuse and failed to build in adequate safeguards before launch; the case grew to three dozen+ plaintiffs. https://www.npr.org/2022/12/07/1141176120/apple-airtag-harassment-stalker-lawsuit↑

  2. On March 15, 2024, Judge Vince Chhabria (N.D. Cal.) denied Apple’s motion to dismiss in part, allowing three California plaintiffs’ negligence and product-liability claims to proceed; class certification was later denied due to the individualized nature of each stalking incident, and 30+ individual lawsuits were proceeding separately as of 2026. https://jolt.law.harvard.edu/digest/suggested-article-title-airtag-stalking-class-action-survives-motion-to-dismiss; https://www.macrumors.com/2026/05/01/airtag-stalking-lawsuits-apple/↑

  3. A man (Indiana County, PA) was arrested January 2025 after his ex-girlfriend was alerted by her iPhone to an AirTag allegedly tracking her car; charged with felony criminal use of a communication facility, misdemeanor stalking, and harassment. https://www.cbsnews.com/pittsburgh/news/indiana-county-apple-air-tag-stalking-charges/↑

  4. A Pennsylvania man was charged April 2025 with allegedly duct-taping an AirTag to a victim’s car; charged with criminal trespassing, stalking, and harassment. https://local21news.com/news/local/man-charged-with-stalking-after-allegedly-duct-taping-apple-airtag-to-victims-car↑

  5. In Tulsa, Oklahoma, a 2023 review documented a cluster of AirTag-stalking cases in which women found trackers planted to follow them; the same reporting covered an Indianapolis murder in which Gaylyn Morris used an AirTag to track her boyfriend before killing him. https://9to5mac.com/2023/10/13/airtag-stalking-murders/↑

  6. Gaylyn Morris, 27, hid an AirTag in the back seat of the car of Andre Smith, 26, and used it to track him to Tilly’s Pub & Grill in Castleton, Indiana, on 2 June 2022; she then struck him twice with her car in the parking lot, and he died of traumatic asphyxia. Charged with murder, she was acquitted of murder and convicted of voluntary manslaughter (a Level 2 felony) by a Marion County jury on 17 August 2023, the defence having successfully argued she acted under “sudden heat” on discovering his infidelity — the distinction Indiana law draws between the two offences. She was sentenced on 21 September 2023 to eighteen years. https://lawandcrime.com/crime/airtag-murder-suspect-convicted-of-voluntary-manslaughter-in-death-of-cheating-boyfriend/ · https://www.wthr.com/article/news/crime/sentencing-hearing-gaylyn-morris-indianapolis-woman-found-guilty-manslaughter-running-over-boyfriend-car-castleton-bar/531-07ab4ab5-d8c3-45e1-9cc8-9471183e63b7 · Smith’s mother, LaPrecia Sanders, is a plaintiff in the consolidated AirTag litigation against Apple, whose complaint characterises the deaths it cites as murders; that characterisation is a pleading, not a finding, and in this instance a jury rejected it. https://9to5mac.com/2023/10/13/airtag-stalking-murders/↑

  7. A Vice investigation obtained police records from eight departments documenting 150 AirTag-related cases over an eight-month period, with 50 specifically involving women who received notifications that an unknown AirTag was traveling with them; Vice characterized this as “just the tip of the iceberg.” https://www.macworld.com/article/630375/police-report-150-airtags-cases-and-thats-just-the-tip-of-the-iceberg.html; https://www.vice.com/en/article/apple-airtags-police-reports-stalking-harassment/↑

  8. Vice, “The Legal System Is Completely Unprepared for Apple AirTag Stalking” — documents that many jurisdictions’ existing stalking/harassment statutes were not written with covert Bluetooth trackers in mind. https://www.vice.com/en/article/apple-airtag-stalking-police-family-court/↑

  9. Apple published “An update on AirTag and unwanted tracking” (February 2022), describing new safeguards: unwanted-tracking alerts, a Precision Finding tool, and an audible chirp on separated trackers. https://www.apple.com/newsroom/2022/02/an-update-on-airtag-and-unwanted-tracking/↑

  10. Apple and Google jointly published the “Detecting Unwanted Location Trackers” (DULT) industry standard in 2023, rolled out across Android and iOS. https://www.androidpolice.com/android-tracker-detected-airtag-stalking/↑

  11. State of Connecticut v. Richard Dabate: Connie Dabate was killed in the family’s Ellington, CT home on December 23, 2015; her husband Richard claimed a masked intruder was responsible, but her Fitbit data showed her still moving inside the house at 10:05 a.m., a full hour after the time his account placed her death. Richard Dabate was convicted of murder, tampering with evidence, and making false statements to police in May 2022, sentenced to 65 years; the Connecticut Supreme Court upheld the conviction on appeal despite finding some prosecutorial improprieties. State v. Dabate (Connecticut; conviction 2022, affirmed by the Connecticut Supreme Court); https://www.nbcnews.com/news/us-news/connecticut-man-sentenced-65-years-wifes-killing-fitbit-murder-case-rcna43859↑

  12. In early 2018, an Australian researcher noticed jogging routes on Strava’s public heatmap in the Syrian desert corresponding to American and allied military base locations; journalists confirmed the aggregated fitness data exposed base perimeters, supply routes, and patrol paths. The US Department of Defense launched a formal review, and Strava restricted street-level heatmap detail to registered users only. https://www.engadget.com/2018-03-13-after-exposing-secret-military-bases-strava-restricts-data-visi.html↑

  13. In 2011, Fitbit’s manual activity log let users record sexual activity by intensity level, and new profiles defaulted to publicly searchable; a tech entrepreneur (Andy Baio) discovered in July 2011 that hundreds of users’ sexual-activity logs were indexed on Google, Yahoo, and Bing. Fitbit had the data delisted, changed the default to private, and removed sexual activity as a trackable category. https://techcrunch.com/2011/07/03/sexual-activity-tracked-by-fitbit-shows-up-in-google-search-results/; https://www.forbes.com/sites/kashmirhill/2011/07/12/no-more-sex-ercise-for-fitbit-users/↑

  14. A researcher (“Jmaxxz”) presenting at DEF CON 28 disclosed that when an August smart lock owner revokes a guest’s access through the app, the guest can continue locking/unlocking the door until the owner’s own device next communicates directly with the lock — revocation takes effect only locally, not immediately or remotely. https://smartlockadvice.com/august-smart-lock-hack/↑

  15. CVE-2019-17098 (Bitdefender): the August Smart Lock Pro + Connect transmitted WiFi credentials unencrypted, giving an attacker within range full access to the home network. https://hackread.com/smart-lock-security-flaw-hackers-access-wi-fi/↑

  16. Security researchers documented that a revoked guest could retain access to August smart locks because revocation was enforced only in the cloud — an offline lock kept honoring the old credential until it next synced — and that a guest could escalate to owner-level control by manipulating the app’s API (Jmaxxz, “Backdooring the Frontdoor,” DEF CON 24, 2016; Ye et al., MIT, 2017). https://blog.quarkslab.com/examining-the-august-smart-lock.html↑

  17. Electronic Frontier Foundation, “Smart Locks Endanger Tenants’ Privacy and Should Be Regulated” (2023): smart locks are increasingly installed in rental units, often without tenant permission, creating entry-log location data accessible to landlords and sometimes law enforcement or the lock vendor, and giving landlords the ability to lock out a tenant instantly and without notice. https://www.eff.org/deeplinks/2023/04/smart-locks-endanger-tenants-privacy-and-should-be-regulated↑

  18. In New York City, tenants forced a 2019 settlement after a landlord attempted to require smart-lock use building-wide; the settlement required a physical-key alternative, and the lock vendor (Latch) subsequently changed its privacy policy to remove references to marketing use and collection of location data. https://news.ycombinator.com/item?id=18959275; https://www.bostonglobe.com/2020/02/11/business/smart-apartments-is-tenants-privacy-rent/↑

  19. A tenant (identified as Kaye) in a Lawrence, Massachusetts (Northeast Housing Court) case alleged a smart lock box was installed on his unit without permission, and that a subsequent eviction attempt was retaliation for his demand that the device be disconnected; the case was pending as reported.↑

  20. A botched remote firmware update from lock manufacturer LockState (August 2017) disabled smart-code access for an estimated 500 customers, hitting Airbnb hosts particularly hard. https://techdirt.com/articles/20170814/14322437995/smart-lock-vendor-locks-hundreds-out-their-home-with-bungled-firmware-update.shtml↑

  21. Smart-lock startup Otto suspended operations in December 2017 before shipping a single unit to customers who had pre-ordered $700 locks, after an acquisition meant to rescue the company collapsed on the day it was to close (reported by Fortune, January 2, 2018). https://fortune.com/2018/01/02/otto-smart-lock-suspension/↑

  22. The 2017 Wichita swatting: Andrew Finch was shot and killed by police at his door on December 28, 2017, after a false hostage-and-shooting report; the caller, serial swatter Tyler Barriss, pleaded guilty to dozens of federal charges and was sentenced to 20 years in 2019 — reported as the longest sentence imposed for swatting. Two others, Casey Viner and Shane Gaskill, whose gaming dispute triggered the call, were also prosecuted. U.S. Department of Justice, District of Kansas, “California Man Sentenced In Deadly Wichita Swatting Case”; NBC News; 2017 Wichita swatting.↑

From The Machinery of Compliance by Willow Whitman · edition 1.0.2, · free under CC BY-NC-ND 4.0 · corrections

The whole book

Forty-nine chapters, free in every sense

Read it in the browser, or take the EPUB or PDF and keep it. No sign-up, no tracking, nothing to pay.

Read online Download EPUB or PDF