- start encrypting all the data they collect (with real encryption, not base64 encoding)
- saving up the data for hours or days at time and sending it in bursts (so there is no immediate connection to a remote server)
- sending the data to plausible U.S.-registered domains (rather than to Singapore and Russia)
- monitoring at the kernel or firmware level so that it doesn't matter what browser or apps you use
- turning off data collection when it suspects a security researcher (due to signs of debuggers, development tools, network monitoring, usual network settings like to proxies or DNS, etc)
We won't be able to prove anything. So disheartening.