Part II · Chapter 22
The Platform and the Tunnel
The tools a person trusts for protection — a platform’s moderation, a VPN’s privacy — repeatedly fail to deliver it under real legal pressure; and the same metadata that fails to hide a stalker is exactly what convicts him.
Matthew Herrick reported his own harassment to a company more than a hundred times, and the company did nothing. It is the starkest single fact in this book’s account of platform failure.
Beginning in October 2016, Herrick’s ex-partner created impersonating profiles of him on the dating app Grindr and a smaller competitor called Scruff, describing him as interested in specific rape-fantasy scenarios and directing strange men to Herrick’s home and workplace for sex. At the peak of the campaign, as many as sixteen men a day showed up at his door; the pattern repeated more than a thousand times over five months. The ex-partner later pleaded guilty to stalking, identity theft, falsely reporting an incident, and criminal contempt, and was sentenced to prison in 2019 — the conduct described here is not an allegation but a matter of his own admission and the court’s record.1 Herrick reported the impersonation to Grindr more than a hundred times with no effective response. Scruff, the smaller of the two platforms, responded immediately — a personal email expressing concern, takedown of the fake accounts, an IP ban on the person responsible.2 The same abuse, reported to two different companies, produced two entirely different outcomes: effective intervention was operationally possible. It was not a technical impossibility Grindr couldn’t meet. It simply didn’t happen.
Herrick sued Grindr, framing the claim as a products-liability case to route around Section 230 of the Communications Decency Act, the federal statute shielding platforms from liability for content their users post. The Southern District of New York dismissed all fourteen claims; the Second Circuit affirmed the dismissal; the U.S. Supreme Court denied certiorari in October 2019. Grindr faced no legal liability whatsoever, despite more than a thousand documented incidents directing strangers to a specific person’s home over five months.3 This is the deniability this book has traced through every scale. Section 230 doesn’t merely make a platform practically difficult to hold responsible for what happens on it. It is a statutory grant of exactly that deniability, written into federal law and upheld all the way to the country’s highest court.
Two further mechanisms round out the pattern, each a distinct product-design failure rather than a repeat of Herrick’s moderation failure. WhatsApp’s public “Online” status indicator, intended as a convenience feature, was documented by the cybersecurity firm Traced in 2021 to be passively monitorable by anyone, without the monitored person’s knowledge or consent, enough to build a detailed log of when a specific person is active on their phone. Because the status is public by design, a stalker needs no special access, only the target’s phone number.4 The feature works precisely as built; the surveillance is simply a side effect nobody accounted for. Published research from the British Psychological Society finds online status indicators generally make users feel under surveillance by partners or family watching for sign-ins, producing measurable anxiety around how quickly they’re expected to respond.5 Snapchat’s Snap Map feature drew a related but distinct concern from police and child- safety advocates from its launch onward — real-time, precise location- sharing with “friends,” a category that can include near-strangers on a youth-dominated platform, capable of leading someone directly to another person’s front door. Snapchat’s own response, a feature called Ghost Mode that lets a user retain full Snap Map functionality while hiding their own location from others, reads like the vendor responses this book has noted elsewhere: an acknowledgment, embedded in the product itself, that the default visible state carried a real risk the company felt compelled to build an opt-out for.6 Between them (a moderation failure, an architectural default, and a feature that must be opted out of rather than defaulting to safety) they produce the identical result: a platform built for ordinary use becomes a surveillance or contact vector for anyone willing to misuse it, absent a deliberate choice to make safety the default.
Every mechanism examined in this book so far has involved a tool being turned against someone. What follows is more specific: a tool a person might reasonably rely on for protection, repeatedly proven, under real legal pressure, not to deliver on that promise.
Ryan Lin was charged in 2017 with an extensive cyberstalking and hacking campaign against a former roommate, her family, friends, and various institutions, using the VPN service PureVPN throughout. PureVPN’s own privacy policy stated plainly that it did not monitor user activity or keep logs of any kind. In practice, the company retained connection timestamps and originating IP addresses — not full browsing records, but enough for investigators to run a time-correlation analysis: the same VPN connection touched, within minutes of each other, Lin’s real Gmail account, a threatening secondary email, and an account he’d created on an unrelated service, tying his real identity to his anonymous activity with certainty.7 This was not an isolated failure. Six years earlier, independently, Cody Kretsinger used the proxy service HideMyAss while participating in the LulzSec hack of Sony Pictures; a single UK court order compelled the company to hand over stored IP-address logs and connection timestamps, directly identifying him and leading to his conviction. A Tor Project developer publicly called the company hypocritical for marketing privacy while retaining exactly the data that ended its user’s anonymity.8 The pattern extends well past these two cases: IPVanish, despite marketing what it called a strict zero-logs policy, provided detailed connection logs to Department of Homeland Security investigators in 2016; seven separate VPN providers, each claiming a no-logs policy, were found to have exposed 1.2 terabytes of user activity logs; and the Center for Democracy and Technology filed a formal FTC complaint against Hotspot Shield in 2017 alleging its no-logs and no-tracking claims were false.9 Across these cases, the same structural gap recurs: “no logs” reliably means no content logs, not no metadata — and connection timestamps paired with IP addresses are, on their own, sufficient to deanonymize a specific person the moment a legal process compels their disclosure. Beneath that sits a distinction the marketing elides entirely: a “no-log” policy is a promise not to keep records, not a technical inability to produce them. A provider that has merely chosen not to log can be ordered to start, or found to have logged anyway — the latter being exactly what the PureVPN and IPVanish cases above document. Only an architecture that cannot retain what it never stored, verified by outside audit rather than asserted in a policy, offers protection a court order cannot reach. Someone evading a stalker or an abusive partner who believes a no-log VPN makes them genuinely untraceable is relying on a claim that has failed, under real legal pressure, in multiple independent and fully documented cases. It is exactly the kind of assumption this book’s closing chapters insist on verifying rather than trusting, when the stakes of being wrong are someone’s physical safety.
A related but distinct mechanism shows the same disguise running in the opposite direction: not a privacy tool failing to protect, but a privacy tool built, from the outset, to surveil. Facebook acquired the Israeli mobile-analytics company Onavo in October 2013; its flagship product, Onavo Protect, was marketed to consumers as a VPN, a privacy and security tool. Installing it in fact gave Facebook visibility into every app opened on the device, how long each was used, and every website visited — data the company used to track competitive threats, monitoring usage of Snapchat, YouTube, Amazon, and Houseparty.10 In 2016, Facebook developed an internal technical method, candidly named “Project Ghostbusters,” to decrypt and intercept Snapchat’s own encrypted traffic for competitive analysis, using the Onavo pipeline as the delivery mechanism.11 The consequences that followed are unusually complete for a corporate-surveillance case: Apple forced Facebook to remove Onavo Protect from the iOS App Store in August 2018 for violating its data-collection policies; renewed reporting the following year revealed Facebook had been paying teenagers to install a rebranded version called Project Atlas through a research app distributed outside normal app-store review, and Facebook sunset Onavo entirely rather than continue defending it;12 and in July 2023, Australia’s Federal Court ordered Meta to pay twenty million Australian dollars specifically for failing to disclose how Onavo’s data collection would actually be used. That is a completed legal penalty, not a pending allegation.13 It is the identical inversion this book has already documented at the individual scale, in apps marketed as “parental monitoring” and browser extensions requesting permissions no translator actually needs. Here it was run not by an individual abuser but by one of the largest technology companies in the world, with a fully adjudicated legal outcome to show for it.
What unites both halves of this chapter is a single usable fact. The platform that refused to help Herrick still held the records of every impersonating account; the VPNs that promised to hide Lin and Kretsinger kept the connection logs that convicted them; even Onavo’s covert collection became a paper trail a court could penalize. A tool can fail every person who trusted it and still be scrupulously honest about one thing: who used it, and when. That record — not the broken promise — is the answer Part II has been building toward across every surveillance mechanism in it.
One layer sits beneath even the platform and the tunnel, and it is worth naming because it defeats the intuition this chapter has been dismantling in its most stubborn form — the belief that a secure app is enough. Interception at the cellular network itself requires no compromise of the target’s phone and no access to any account. The signaling protocols that route calls and messages between carriers — the SS7 system and its kin — carry long-documented weaknesses that allow calls, texts, and location to be pulled from the network side; and the device known as an IMSI-catcher, a false cell tower that nearby phones connect to automatically, harvests the same data out of the air, available well below the level of a state.14 The encrypted messenger protects the message’s contents; it does nothing about a network that can log who is talking to whom, and where, without ever touching the endpoint at all. The tunnel can be perfect and still open, at its far end, onto a road that was never yours.
In plain terms: the phone network itself can be listened to — without touching your phone and without breaking into any account — so even a flawless encrypted app hides what you say but not who you spoke to, when, or where. No app setting fixes this; it is a limit of the network, and the only safe assumption is that the record of who you contacted, and when, is not private.
Notes
Beginning October 2016, Matthew Herrick’s ex-partner created impersonating profiles of him on Grindr and Scruff, describing him as interested in specific rape-fantasy scenarios and directing men to his home and workplace; at the campaign’s peak, up to 16 men a day showed up at his door, recurring more than 1,000 times between October 2016 and March 2017. https://www.buzzfeednews.com/article/tylerkingkade/grindr-herrick-lawsuit-230-online-stalking · The ex-partner, Oscar Juan Carlos Gutierrez, pleaded guilty to criminal contempt in the first degree, identity theft in the second degree, falsely reporting an incident, and stalking in the third degree, and was sentenced to prison in November 2019. He is not named in the body text because the chapter’s subject is the platform’s response, not his; the plea is recorded here because a book that states a charge is not a finding owes the reader the finding when there is one. https://www.cagoldberglaw.com/matthew-herrick-v-grindr-llc/↑
Herrick reported the impersonation to Grindr over 100 times with no effective response; Scruff responded immediately with a personal email, takedown of the fake accounts, and an IP ban on the person responsible. https://www.cagoldberglaw.com/matthew-herrick-v-grindr-llc/↑
Herrick sued Grindr as a products-liability claim to route around Section 230; the Southern District of New York dismissed all 14 claims, the Second Circuit affirmed, and the US Supreme Court denied certiorari on October 7, 2019. https://news.bloomberglaw.com/tech-and-telecom-law/grindr-harassment-case-wont-get-supreme-court-review↑
Cybersecurity firm Traced documented in 2021 that WhatsApp’s public “Online” status indicator can be passively monitored by anyone, without the monitored person’s knowledge, to build a log of when they are active — covered by Forbes under the headline “WhatsApp Has A Serious Unstoppable Cyberstalking Problem.” https://traced.app/2021/04/13/whatsapp-status-loophole-is-aiding-cyberstalkers/; https://www.forbes.com/sites/gordonkelly/2021/04/17/whatsapp-users-status-tracking-stalking-monitoring-hack/↑
The British Psychological Society’s research digest documents that online status indicators generally make users feel under surveillance by partners or family members watching for sign-ins, producing measurable anxiety around response expectations. https://www.bps.org.uk/research-digest/heres-how-online-status-indicators-apps-influence-our-behaviour↑
Snapchat’s Snap Map feature drew documented concern from police and child-safety advocates over real-time precise location-sharing; Snapchat’s Ghost Mode feature lets users hide their own location while retaining full Snap Map functionality. https://blog.oup.com/2017/07/ghost-mode-snapchat-maps/↑
Ryan Lin was charged in 2017 with an extensive cyberstalking and hacking campaign using the VPN service PureVPN, whose privacy policy stated it did not monitor activity or keep logs; PureVPN in fact retained connection timestamps and IP addresses, letting investigators run a time-correlation analysis tying his real identity to his anonymous activity. https://www.helpnetsecurity.com/2017/10/09/cyberstalker-unmasked-purevpn/; https://grahamcluley.com/vpn-logs/↑
Cody Kretsinger used the proxy service HideMyAss during the LulzSec hack of Sony Pictures; a UK court order compelled the company to hand over stored IP-address logs and connection timestamps, identifying him and leading to his conviction (Kretsinger, a U.S. resident, was arrested in Arizona and transferred to Los Angeles for prosecution — there was no extradition). https://www.theregister.com/2011/09/26/hidemyass_lulzsec_controversy/↑
IPVanish provided detailed connection logs to Department of Homeland Security investigators in 2016 despite marketing a “strict zero logs policy”; seven VPN providers (UFO VPN, Fast VPN, Free VPN, Super VPN, Flash VPN, Secure VPN, Rabbit VPN) were found to have exposed 1.2TB of user activity logs despite no-logs claims; the Center for Democracy and Technology filed a formal FTC complaint against Hotspot Shield in 2017 alleging false no-logs/no-tracking claims. https://cdt.org/wp-content/uploads/2017/08/FTC-CDT-VPN-complaint-8-7-17.pdf↑
Facebook acquired Israeli mobile-analytics company Onavo in October 2013; its Onavo Protect product was marketed as a VPN/privacy tool but gave Facebook visibility into every app opened, usage duration, and websites visited, used to track competitive threats including Snapchat, YouTube, Amazon, and Houseparty usage. The Wall Street Journal reported Facebook’s use of Onavo data to monitor competitors (August 2017); further detail (the internal “Project Ghostbusters”) emerged in later antitrust court filings.↑
In 2016, Facebook developed an internal technical method called “Project Ghostbusters” to decrypt and intercept Snapchat’s encrypted traffic for competitive analytics, using the Onavo pipeline. https://www.businesstoday.in/technology/news/story/how-facebook-turned-a-vpn-into-a-surveillance-engine-to-spy-on-snapchat-youtube-and-more-487454-2025-08-01↑
Apple forced Facebook to remove Onavo Protect from the iOS App Store in August 2018 for violating data-collection policies; renewed reporting in 2019 revealed Facebook had paid teenagers to install a rebranded version, “Project Atlas,” via a research app outside normal app-store review, after which Facebook sunset Onavo entirely. https://techcrunch.com/2019/01/29/facebook-project-atlas/↑
In July 2023, Australia’s Federal Court ordered Meta to pay A$20 million for failing to disclose how Onavo’s data collection would actually be used.↑
SS7 signaling-network weaknesses were demonstrated publicly by Karsten Nohl of Security Research Labs, including the consented live interception of a US congressman’s calls for CBS 60 Minutes (“Hacking Your Phone,” April 17, 2016). IMSI-catchers (“StingRay” being the best-known trade name) are documented in US litigation over law-enforcement use and in civil-liberties tracking of the technology; commercial and hobbyist variants circulate well below the state level.↑
From The Machinery of Compliance by Willow Whitman · edition 1.0.2, · free under CC BY-NC-ND 4.0 · corrections