Move Fast, Break Privacy
The most dangerous technology often has the calmest button label.
In 2018, Facebook showed people a small button called “Protect.”
That is the part that makes the story worth studying.
Not because one app collected data. Many apps collect data.
The lesson is sharper than that:
The button said protection.
The business use was surveillance.
The product was Onavo Protect, a free VPN owned by Facebook. A VPN sounds like a privacy tool. It sounds like something you use when you do not want websites, networks, or apps watching you too closely.
But in Facebook’s hands, the VPN also became a market-intelligence machine.
It helped Facebook see what people were doing outside Facebook.
Which apps were growing. Which features were working. Which competitors were becoming threats. Which user habits were shifting before the public market could see them.
That is why this story matters now.
We are entering another cycle where calm product labels hide deeper power.
AI assistant. Personalized feed. Smart search. Secure browser. Private cloud. Productivity agent.
The words sound helpful.
The question is what the system learns while helping.
The Wrong Mental Model
Most users judge software by the surface.
Does it look clean? Is it free? Does it solve an immediate problem? Does the label sound safe?
That is normal. Nobody has time to audit every app.
But serious builders need a better mental model.
A product is not just its interface.
A product is:
the promise on the screen
the data it collects
the path that data takes
the business model behind it
the incentives of the company
the power it gives one side over another
Onavo is a clean case study because the surface and the system pointed in opposite directions.
Surface:
Protect your privacy.
System:
Route traffic in a way that creates visibility into user behavior and competitor usage.
That gap is where trust dies.
Why Facebook Wanted This
Facebook’s problem in the early 2010s was not that it lacked users.
It was enormous.
It had crossed a billion users. It bought Instagram. It was trying to understand mobile before mobile swallowed the internet.
The hard part was visibility.
On desktop, cookies helped companies understand behavior across websites. On phones, people moved into apps. App behavior was harder to see from the outside.
If you are Facebook and young users are moving to WhatsApp, Snapchat, and whatever comes next, you want early warning.
Downloads are not enough.
You want usage. Frequency. Retention. Feature adoption. Message volume. Growth curves.
That is the kind of intelligence that can shape billion-dollar decisions.
The fern video points to WhatsApp as one example. Onavo data reportedly showed how deeply WhatsApp had penetrated certain markets. Facebook later paid $19 billion for WhatsApp.
It also points to Snapchat.
When Snapchat would not sell, Facebook copied. Stories moved from Snapchat into Instagram. The public saw a product feature. The deeper story was market intelligence plus distribution.
This is the first practical lesson:
Distribution plus data beats taste alone.
If a company can see what users are doing before everyone else can, it can move before everyone else moves.
Project Ghostbusters
The darker part of the story is not only that Facebook wanted competitive intelligence.
It is how far the company was willing to go when encryption made that intelligence harder to collect.
The Verge reported in 2024 that unsealed court documents described a Facebook program called “Project Ghostbusters.” The goal was to understand encrypted Snapchat traffic using Onavo-related technology.
The technical details matter less than the builder lesson:
When a company is built around behavioral data, encryption is not just a privacy feature.
It is a business obstacle.
That changes how we should read product strategy.
A normal user sees encryption and thinks:
My data is safer.
A surveillance-based business sees encryption and may think:
Our visibility is decreasing.
Those are different incentives.
And incentives usually win.
Project Atlas
Then came Facebook Research, also known as Project Atlas.
TechCrunch reported in 2019 that Facebook paid users, including teens, to install a research VPN. Participants could receive up to $20 a month.
The issue was not only payment.
The issue was the power imbalance.
Users were told they were joining a research program. But the app could give Facebook deep access to phone activity, including data from people who had never consented because they were communicating with the participant.
That is a pattern technical people need to remember:
Consent is not always as clean as a checkbox.
If one person installs a tool that captures messages, locations, browsing behavior, app usage, and network traffic, other people may get pulled into the data stream too.
Privacy is social.
Your settings can affect my data. My tools can expose your behavior. One person’s convenience can become another person’s surveillance.
The Fine Was Not the Lesson
In 2023, Australia’s Federal Court ordered Facebook Israel and Onavo Inc to pay AUD 20 million total after action by the ACCC. The court found conduct liable to mislead consumers about data use.
That sounds large.
For a normal person, it is huge.
For Meta, it is a rounding error.
That does not mean legal consequences are useless. It means fines alone are a weak teacher for companies with massive cash flow.
The stronger teacher is architecture.
What data can the system collect? Who can access it? What can the company infer? Can users understand the trade? Can users realistically opt out? Can regulators inspect the system before harm scales?
Those questions matter more than the privacy slogan.
The AI Version Of This Problem
This is why I think the Onavo story is still useful in 2026.
We are now handing new kinds of personal data to AI tools.
Not just clicks.
Questions. Drafts. Work documents. Searches. Voice. Photos. Private notes. Calendar context. Code. Customer data. Internal company thinking.
The product label might be “assistant.”
But the deeper question is:
What does the assistant learn while assisting?
If an AI tool sits between you and your work, it can become more than a tool.
It can become a telemetry layer.
It can learn your workflows. Your weak spots. Your company knowledge. Your habits. Your buying signals. Your technical stack. Your customers.
That does not mean every AI product is bad.
It means technical literacy now includes data-flow literacy.
If you are learning cloud, AI, Linux, networking, security, or automation, this is not a side topic.
This is the topic.
Infrastructure is power because infrastructure sees things.
A Simple Privacy Checklist
Before trusting a tool, ask:
What problem does it claim to solve?
What data does it need to solve that problem?
What extra data does it collect?
Where does the data go?
Who owns the company?
What does the company gain from the data?
Can I use the product without giving it everything?
Can I delete the data?
Can I verify the answer, or do I only trust the label?
The point is not paranoia.
The point is adult technical judgment.
Good engineers do not only ask whether something works.
They ask what it costs.
Not only in money.
In control. In visibility. In dependency. In future leverage.
The Takeaway
The most dangerous product is not always the one that looks dangerous.
Sometimes it is the one with the calm label.
Protect. Secure. Personalized. Smart. Free. Helpful.
Onavo is a reminder that the label is not the system.
The interface is not the incentive.
The promise is not the data path.
If you want to become a serious technical person, learn to read below the button.
Because the next version of “Protect” may not be a VPN.
It may be an AI assistant.


