Skip to content

Apps  ·  Analysis

What a VPN Does, and How to Evaluate One

A VPN moves the point at which your traffic enters the internet. That solves some problems and none of the ones most advertising implies.

VPN marketing is extensive, well funded and frequently misleading. The technology is genuinely useful for a specific set of purposes, and understanding what it does makes the evaluation straightforward.

What it actually does

A VPN creates an encrypted tunnel from your device to a server. Your traffic emerges from that server instead of from your own connection.

The consequences:

Your internet provider sees an encrypted connection to the VPN and not the sites you visit.

Sites see the VPN server's address rather than yours.

Traffic on a local network — a café, a hotel — is encrypted between you and the VPN.

Your traffic is visible to the VPN provider at the point where it leaves their server.

That last point is the one the advertising avoids. You have moved trust, not eliminated it. Your provider could see your traffic; now the VPN operator can.

What it does not do

It does not make you anonymous. You remain signed in to accounts, your browser is fingerprintable, and cookies persist. A VPN changes your apparent location, not your identity.

It does not stop tracking. Advertising networks identify you by account and browser characteristics, not primarily by address.

It does not protect against malware or phishing. Some providers bundle blocklists, which is a separate feature.

It does not secure a site that lacks encryption in a meaningful way. Almost everything uses HTTPS now, so the "protect yourself on public Wi-Fi" argument is much weaker than it was a decade ago. It has not disappeared — DNS queries and traffic metadata still leak — but it is not the emergency the advertising suggests.

It does not make illegal activity legal or untraceable.

When a VPN is genuinely the right tool

Accessing a work network remotely. This is what the technology was built for.

On a network you do not trust, where the operator can see and modify unencrypted traffic.

Where your internet provider records and sells browsing data, which varies by country and provider.

Under network censorship, where a VPN is a circumvention tool. Note that this carries legal risk in some jurisdictions, and that heavily censored networks actively block VPNs.

Testing how a site behaves from another country, which is a routine professional need.

Avoiding provider-level throttling of particular services, where that occurs.

Evaluating a provider

Jurisdiction, and what data retention obligations apply there.

The logging policy, read closely. "No logs" is a marketing phrase. Read what is actually retained: connection timestamps, bandwidth, source addresses. Some retention is operationally necessary; the question is what and for how long.

Independent audit. Has the no-logging claim been examined by a third party, when, and what was the scope? An audit of the apps is not an audit of the logging practice.

Ownership. Several VPN brands share a parent company. Some are owned by advertising or analytics businesses, which is worth knowing.

What has happened when they were compelled to produce data. Court records are the most reliable evidence of what a provider actually holds.

Open-source clients and support for a modern, well-reviewed protocol.

A kill switch that blocks traffic if the tunnel drops, and DNS leak protection. Test both rather than trusting the checkbox.

Payment and account requirements. A provider requiring extensive personal information contradicts a privacy claim.

Free VPNs

The operating cost is real, so free services monetise another way: advertising, data collection and sale, or selling your connection's bandwidth to others.

Several free VPN applications have been found logging extensively, injecting advertising, or routing other people's traffic through users' connections.

The legitimate free options are the limited free tiers of paid providers, and self-hosting your own on a server you control — which gives you a fixed address and no third party, but no anonymity, since it is obviously yours.

Alternatives worth considering

Encrypted DNS, which stops your provider seeing domain lookups and needs no VPN.

Tor, for genuine anonymity, with the performance cost that implies. Different tool, different purpose.

A self-hosted tunnel to your own server, for accessing your own network.

Browser privacy settings and tracker blocking, which address tracking far more directly than a VPN does.

A short summary

For remote work access, untrusted networks, censorship circumvention and location testing, a VPN is the right tool and worth paying for.

For anonymity, tracking prevention or general security, it is the wrong tool, and the marketing that suggests otherwise is the main reason people buy one that does not do what they wanted.

Mistakes people make

Believing it provides anonymity. You remain signed in to accounts and your browser is fingerprintable. A VPN changes your apparent location, not your identity.

Using a free VPN. The operating cost is real, so it is paid for with advertising, data sale, or by routing other people's traffic through your connection.

Taking "no logs" at face value. Read what is actually retained, and whether an independent audit examined the logging practice rather than only the apps.

Assuming public Wi-Fi is the emergency it once was. Almost everything uses HTTPS now. The argument is weaker than the advertising suggests.

Not testing the kill switch and DNS leak protection. Both are checkboxes until you verify them.

Ignoring ownership. Several VPN brands share a parent, and some parents are advertising businesses.

The short answer

Right tool for remote work access, untrusted networks, censorship circumvention and location testing. Wrong tool for anonymity, tracking prevention or general security — for those, encrypted DNS, tracker blocking and, where it genuinely matters, Tor.