← all articles

What a VPN actually does, and the claims that cost you money

vpn privacy consumer-security subscriptions

Disclosure first, because it should change how you read the rest. I sell mobile proxy infrastructure for a living. Physical SIM cards in modems, rented to businesses that need traffic leaving from a specific carrier. That is an adjacent business to the one I am about to be rude about.

I say it up front because almost everything published on this subject was written by a company selling a subscription or an affiliate earning a cut of one.

This is not an argument against using a VPN. I run tunnels for particular jobs and they do them well. The argument is against paying for one because of things it was never doing.

The whole mechanism, in one sentence

A VPN changes where your traffic enters the public internet.

That is it. Instead of appearing to come from your flat, your connection appears to come from a machine in Frankfurt or Tokyo, and on the way there the contents are wrapped so your local network cannot read them.

Two useful consequences follow. The site sees a different address, and your network sees encrypted traffic to one destination instead of a list of everywhere you went.

Every claim you have read is either a restatement of those two things or it is wrong.

It cannot make you anonymous, and you undo it in four seconds

The tunnel has no opinion about who you are. It moves packets.

The moment you log into an account you have introduced yourself by name and the exit address stops mattering there. People do this constantly. They connect, open their email in the same browser, then wonder why the results still feel personalised.

Your device fingerprint arrives regardless. Installed fonts, screen dimensions, the exact way your graphics hardware renders a test image. That combination recognises you across sessions from a cold start, and half the reason my customers pay for a real carrier line is that the address is one signal out of dozens.

So the accurate description is narrow. It hides your location from the site and your contents from your network, and leaves you recognisably yourself to anything that could already recognise you.

The coffee shop argument expired quietly

This one was true once. True for long enough that an industry got built on it, and then the ground moved.

The attack everybody describes needs your traffic readable in transit, which was a real problem when much of the web ran unencrypted. Today the overwhelming majority of sites are encrypted by default and your browser complains loudly when one is not. The person two tables away cannot read your banking session with or without a tunnel.

What is still visible is which sites you connect to, and a tunnel does hide that. Whether that is worth a monthly fee depends on how much you mind a cafe router knowing you visited a particular domain. It is sold as protection from theft and it is closer to a curtain.

The trust does not disappear, it changes address

Before, your telco could see the sites you visit. After, your telco is mostly blind and the VPN operator sees everything instead.

So the question is whether that operator has earned more trust than a licensed telco that is regulated, auditable, and has a local address you could visit. In a country with functioning privacy law that is a hard argument to win.

“No logs” is the standard claim and it is a claim. My bias showing, from the operator side: every piece of network software I run logs by default. Connection tables, session records, bandwidth counters, error output with addresses in it. Not logging is a configuration you apply and keep applying through every upgrade and every emergency fix at 3am. I know how easy it is to leave one on by accident, and that nobody outside would find out.

Published independent audits are worth something. They are also a snapshot of one configuration on one date, and the ones I have read were narrower than the marketing quoting them.

What tells you more is dull. Who owns the company and who owns the owner, where the entity is incorporated, and whether they have ever been compelled to produce records.

Free ones are the worst version of this trade, and I will say plainly that a free VPN is worse than none. I know what carrying traffic costs because I pay it monthly: about ten dollars for a SIM on a Singapore carrier, plus roughly a dollar fifty of modem depreciation. That is the floor for one line, and consumer video costs vastly more. No invoice means the money arrives some other way, which historically has meant selling the traffic data or injecting ads.

The price on the page is not the price

Here is where the money actually leaks, and the pattern is deliberate.

That headline figure of a couple of dollars a month is nearly always a two or three year plan billed as one payment up front. Pay month to month and the real rate is commonly five or six times higher. The advertised number is true only if you commit years to a service you have used for zero days.

Then the renewal lands well above the introductory rate, on a subscription you stopped thinking about eighteen months ago. A large up front commitment, a low anchor, a quiet renewal. That is the business.

If you decide you need one, pay monthly for the first month and use it properly. Check whether it drags your connection somewhere irritating, whether your work applications still function, whether anything you use blocks it outright. Plenty of banks and streaming services do.

Commit after it has earned it. No prepay discount is worth three years of something untested.

Two settings decide whether any of it works

Before your device reaches a site it turns the name into an address, and that lookup goes to a resolver. If it escapes outside the tunnel, whoever runs your network still gets a tidy list of every site you asked for. Your contents are protected and the index of your browsing is not.

Good clients route lookups through the tunnel. Some do not, and when it goes wrong it is silent. Same story when the tunnel drops: without a kill switch that cuts traffic the instant the connection fails, your device reverts to the ordinary network and carries on.

I found lookups leaking on my own laptop months after setting it up, and only because I was debugging something unrelated.

Run the leak test pages, then confirm the kill switch is genuinely enabled rather than just present in the settings. The tools I use for that are here. An operator with perfect policies cannot help you if your machine walks around them.

Speed, measured on your own line instead of theirs

Your traffic is taking a detour, so you are adding distance, and distance costs milliseconds.

An exit in your own city is usually a small difference. One on another continent, which is what you pick to appear somewhere specific, shows up in anything interactive: Singapore to London and back is around 160 to 200 milliseconds.

Test it yourself with the tunnel off, then on, then on with a distant exit. The numbers on the marketing page were measured under conditions you will never reproduce.

The two things it was never going to fix

Advertising follows you through cookies, browser storage, fingerprinting, and above all the accounts you stay logged into. None of that cares which address the request came from. Browse through a tunnel for an hour and the ads are the same, with the targeting moved to a city you are not in.

Phishing is the other one. Some providers bundle a blocklist and market it as protection. It stops some known bad domains, and does nothing about a convincing message that gets you to type your password into a page that looks correct. There is no network signature for a person being persuaded, and that is the threat that empties accounts.

When I would pay for one

Hiding your browsing from the network operator you are sitting on. An employer, a hotel, or a country where your provider must log and hand over records. That is a real threat model and precisely what the tool solves.

Making traffic appear to originate elsewhere, for reaching a service from abroad or checking how a page renders to visitors in another country, which is a consumer grade version of what I sell.

Adding a layer on a network you have concrete reason to distrust. Not the cafe, which is mostly fine now.

Reducing what your internet provider can compile and sell about you, which in some countries is a live concern with real money behind it.

If one of those describes you, pay for it, monthly first. If none do, you are buying a feeling.

The list that is cheaper and does more

Spend the money, and more importantly the attention, on a password manager, because credential reuse is what actually drains bank accounts. Then a second factor on anything holding money or identity, from an app or a hardware key instead of text messages. Then third party cookies off and a content blocker running. Then keep every device updated, which costs nothing and prevents more harm than the rest combined.

That list is cheaper than one annual subscription and it addresses what happens to people in practice: an account takeover through a reused password, or a convincing message at the end of a long day. Neither involves anyone reading your traffic.

Since I opened with my interest, here is the consistent version. The infrastructure I sell exists for automation and for businesses that need traffic from a particular network. It is not a privacy product for ordinary browsing, I would not sell it to you as one, and for someone who wants to be harder to track, the boring list above beats anything I could invoice you for.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →