← all articles

Tor vs a VPN: what each actually hides

Tor Browser costs nothing. Mullvad, one of the few VPNs I’d point a beginner at, charged a flat 5 euros a month when I last checked. Plenty of people treat them as two brands of the same product. They aren’t.

Both hide your IP address from the websites you visit, and that is where the overlap ends. A VPN moves your trust from your internet provider to one company. Tor spreads it across volunteer computers, so no single one of them knows both who you are and what you’re looking at. Which fits depends on who you’re hiding from, and the wrong pick can leave you feeling private while exposing exactly what you meant to protect. I work with IP addresses and network traffic for a living, here in Singapore, so I’ll be blunt about what each can and can’t do.

What it is

A VPN, short for virtual private network, builds an encrypted tunnel from your device to a server the provider runs. Your traffic leaves that server under its IP address instead of yours. You install an app from Mullvad, Proton VPN, IVPN or a similar provider, press connect, and everything your device sends goes through the tunnel.

Tor is two things sharing a name. It is a network of relays run by volunteers, and it is Tor Browser, a modified Firefox that sends its traffic across that network. The name began as “The Onion Router”. The Tor Project, a US nonprofit, maintains the software, and anyone can run a relay. Tor Metrics publishes live relay counts, and they sit in the thousands.

In one line: a VPN asks you to trust one company. Tor is designed so you never have to trust any one relay.

How it works

How a VPN works

Your VPN app opens an encrypted connection to the provider’s server, usually with WireGuard or OpenVPN. Anyone watching your side, whether that’s your ISP, the café Wi-Fi or the router at home, sees scrambled data going to one address. The server decrypts it and forwards it on, so the website sees the server’s IP, shared with many other customers.

Now the catch. The VPN server sees everything your ISP would have seen: every domain, when, and how much data. Nothing in the technology stops a provider logging it, so “no logs” is a promise. The EFF’s Surveillance Self-Defense guide to choosing a VPN makes the same point, that a VPN shifts trust from your ISP to the VPN company. In April 2023 Swedish police arrived at Mullvad’s office with a search warrant and left without customer data, and Mullvad said there was nothing stored to hand over. Good sign. Still one company’s word, and I haven’t audited anyone’s servers, and you probably haven’t either.

What the network owner learns even without a VPN is a separate question, and I covered it in your router sees every site on the network.

How Tor works

Tor Browser builds a circuit of three relays: an entry (the guard), a middle relay and an exit. It wraps each request in three layers of encryption, one per relay, and each relay can peel off only its own layer. The guard knows your IP address and the next hop, nothing more. The middle relay knows neither you nor the destination. The exit knows the destination but not who you are.

To link you to a site, someone would have to watch both ends of the circuit at once. Tor keeps your guard for a long stretch instead of picking a new one each time, because fresh entry points would give an attacker more chances to land on your path. Circuits rotate roughly every ten minutes for new connections, and different sites get different circuits. The Tor Browser manual covers the details.

The costs are real. Three hops through volunteer machines is slower than a VPN, and video calls suffer. Tor carries TCP traffic only, which rules out most torrenting and voice apps. It covers Tor Browser, not the rest of your laptop. Exit relays are on a public list, so plenty of sites throw up CAPTCHAs or block them, and an exit can read anything that isn’t HTTPS.

Your ISP still sees that you’re connecting to Tor, because relay addresses are public. Where Tor is blocked, bridges such as obfs4 and Snowflake disguise the connection. Tor Browser also makes every user’s browser look nearly identical, with a standard window size and fingerprinting defences, which is a separate protection from the routing. I go into that in how websites recognise you without cookies.

Who sees what, side by side:

  • your ISP or the Wi-Fi owner, with a VPN: a connection to one VPN server, plus timing and volume. No site names.
  • your ISP, with Tor: a connection to a Tor relay or bridge. Same timing and volume, still no site names.
  • the website, with a VPN: the VPN server’s IP, shared with other customers.
  • the website, with Tor: an exit relay’s IP. The exit list is public, so the site can tell it’s Tor.
  • whoever runs the service: a VPN company sees your real IP and every site you visit. On Tor, no single relay sees both.

Why it matters

Public Wi-Fi is the classic VPN case. Most sites use HTTPS, so the network owner can’t read your pages, but they can still see which sites you open. In a hotel or airport that’s a small leak and a VPN closes it. At home the gain is narrower: you’re choosing whether your ISP or a VPN company sees your browsing.

Your IP address is a rough location tag, usually accurate to a city, and your ISP can match it to your account if it gets a legal request. Sites and ad networks use it as one signal for linking your visits. A VPN swaps in a different IP, but one that often stays the same from visit to visit, so the linking still works. Tor changes it per circuit.

Some people can’t safely trust one company. Journalists, activists, and anyone living where VPN providers get blocked or leaned on. Tor’s design doesn’t need you to trust any single relay, and the Tor Project’s support pages explain how to connect from places that block it. Laws on VPNs and Tor differ by country and some restrict them. This is not legal advice, so check yours.

Choosing a VPN matters more than people think, because a bad one hands a single company your whole browsing history. In 2015 Hola, a free VPN, was found to be reselling its users’ bandwidth through a company called Luminati. I avoid free VPNs with no visible business model. Proton VPN’s free tier, paid for by its subscribers, is the only free one I’d bother with.

Common misconceptions

“A VPN makes me anonymous.” It hides your IP from websites and your browsing from your ISP, and that’s about it. Log into Google and Google knows who you are. Cookies and your browser fingerprint keep following you, and you probably paid the provider with a card. The antidetect browser world deals with fingerprinting more than anyone, and antidetectreview.org’s blog covers it from that side. VPN ads that say “anonymous” are overselling it.

“Tor is the dark web, so it’s for criminals.” Tor is legal to use in most countries (again, not legal advice) and most of what people do on it is ordinary browsing through exit relays. Onion services exist, and some are mainstream: the BBC and the New York Times both run onion versions of their sites so readers in censored countries can reach them.

“Tor makes me anonymous on any site.” Log into your personal Gmail or Facebook over Tor and the site knows exactly who you are. The route stays hidden, the identity doesn’t. Typing your real name into a form does the same. The Tor Project also advises against installing extra add-ons in Tor Browser, since they can make your browser more distinctive.

“Stacking Tor and a VPN is safer.” More layers means more things to get wrong, and depending on the setup it can make you easier to identify. The Tor Project’s own support pages advise most people against combining them unless they know how to configure both. Two separate tools for two separate jobs beats a clever chain.

Where to go from here

My rule of thumb: a VPN for networks you don’t trust, Tor Browser for anything you don’t want tied to your name. Neither fixes what’s below, and the blog index has more.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-24.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →