A technical investigation into Facebook's acquisition of Onavo, a VPN app, reveals that the company used the app to intercept encrypted traffic from users' devices, potentially breaching the Wiretap Act. The app, Onavo Protect, had over 10 million Android installations and contained code to prompt users to install a Facebook-issued certificate authority certificate, allowing Facebook to decrypt TLS traffic. This technique, known as 'ssl bump', was used to gain competitive insights into other companies, including Snapchat, YouTube, and Amazon. The investigation is based on court documents and reverse engineering of archived Onavo Protect app packages for Android.