Last time I wrote about the fingerprint your device gives away even when you hide behind a VPN. It prompted a lot of questions, mainly whether a VPN is still worth having at all. It is, very much so. You just need to know exactly what it does and what it does not do, and above all which one to choose and how to set it up so that it works the way you think it does.
What a VPN actually does
Think of a VPN as a car with blacked-out windows and different number plates that takes you to your destination by another route. The website you are heading for sees only the new plates, not your real ones. Your connection is encrypted and sent through the VPN server, and only from there does it continue on its way. Your internet provider therefore cannot see what you are looking at, only that you are going through a VPN. And the destination site sees neither your real IP address nor the approximate location I described in the previous article; it sees the address of the VPN server.
What it does not mean is that a VPN makes you invisible. It is a different set of number plates, not a different person. Your device fingerprint, which I described last time (canvas, graphics card, audio chip, screen resolution), stays exactly the same wherever you connect from. Cookies and signed-in accounts do not disappear either. If you are signed in to your email, the website still knows who you are; it simply thinks you are sitting somewhere else. A VPN deals with one specific thing: who can see your connection and where you appear to be coming from. It does not change who you are.
Not every VPN is the same: what to ask
Almost every VPN provider claims to store nothing. That is marketing until someone checks it independently, and more than once the promise and the reality have turned out to be two different things. PureVPN is a textbook case. For years the company advertised that it kept “no logs” of user activity, yet in 2017 it handed the FBI connection times, data usage and IP addresses that helped identify a specific individual. Those operational records had existed all along; the advertising simply never mentioned them. I take a simple lesson from this, and I pass it on to you: a claim of “we store nothing” is worth something only once someone independent has verified it, and only if it matches what is technically possible in the first place.
There is also a case that ended in exactly the opposite way, and I like it all the more for that. In April 2023 police arrived at the office of the provider Mullvad in Gothenburg, Sweden, with a search warrant, intending to seize computers containing customer data. They left empty-handed: Mullvad simply had no such data, because it does not store it in the first place. That is the whole point. Data that is never created cannot be handed over, whoever asks for it. That is why I advise choosing a provider that has its data minimisation independently audited and is based somewhere that lets you sleep soundly, not one that merely makes promises.
When you are choosing, ask four questions. First, is the “no-logs” policy verified by an independent audit, not just written into the terms of use? Second, does the VPN have a kill switch, a safeguard that blocks all traffic the moment the VPN connection drops, so that no one sees you unprotected at that instant? Third, does it protect against leaks through WebRTC, the technology for video calls in the browser that can reveal your real address even when you are using a VPN? I mentioned it last time. And fourth, where is the company based and which laws apply to it? A registered office in a country with strong privacy protection is a plus, but with a good provider, what has been verified by audit matters more than the address on the business card. Personally, I recommend Proton VPN or Mullvad; both have independent audits and a kill switch. With Mullvad the kill switch is always on and cannot be turned off. With Proton VPN, turn it on in the settings after installation.
Mistakes that make a VPN pointless
The most common problem is not a bad VPN but a badly configured one. Four things come up again and again. The first is a DNS leak: the VPN encrypts your traffic, but the lookups for the sites you actually want to open can travel outside the tunnel, straight to your internet provider’s server. The result is odd: the content of the pages is hidden, yet the sites you requested remain visible. The second is a WebRTC leak, which I mentioned above. If the VPN does not cover all of your device’s traffic, typically when it is only a browser extension or when traffic is split, your real address can leak through WebRTC outside the tunnel.
The third is split tunnelling, where you deliberately or accidentally let some of your apps run outside the VPN. It is useful for, say, a printer on your home network, but if your browser ends up there by mistake, the VPN is no longer protecting what matters most. The fourth is a forgotten kill switch. Without it, the moment the VPN drops out for a second, your device quietly switches to an ordinary, unprotected connection, and you may never know.
Here is how to check it yourself in five minutes. First, with the VPN off, find out your real IP address: simply type “what is my IP” into your browser. Then turn the VPN on and run the same search again; the address must change. Next, use specialist sites such as browserleaks.com or ipleak.net, both free and with no registration, and check the DNS and WebRTC sections in particular; your real address must not appear there. Finally, test the kill switch deliberately: turn the VPN on, then force-quit its app, or turn Wi-Fi off and on again. If the kill switch works, your internet connection should cut out completely for a moment rather than quietly carrying on without protection.
When a VPN will not help you
A VPN is the car with blacked-out windows from the start of this article. It stops anyone seeing inside while you are on the move, but it does not stop them recognising your walk once you step out. That is exactly the device fingerprint from the previous article; a VPN does nothing about it, because it works on an entirely different level. Nor does a VPN protect you against phishing, meaning fraudulent emails and websites that trick you into entering your password yourself, or against malicious software already on your device. And if you are signed in to a site, a VPN does nothing to hide your identity from that site. You know who you are and so does the site; only everyone else around you does not.
When you travel, things change
For clients who travel frequently, I have one more note. In some countries, using an unapproved VPN is a legally sensitive matter. In China, for example, it is restricted under local law, and with a company device the risk is well worth weighing up in advance, not once you are already there. The solution is usually simple: a corporate VPN for work access and a personal VPN for privacy are two different things, and it is wise not to mix them, especially on a business trip. By far the most common situation I see with clients, though, is hotel or airport Wi-Fi. There a VPN should be a matter of course, not because of the law but because on a poorly secured public network someone may try to eavesdrop or set up a fake network. HTTPS usually protects the content these days, but the services you are communicating with are still visible. Switch the VPN on before you sign in to anything.
What to do today
Choose an audited VPN; Proton VPN or Mullvad are a good place to start. Turn on the kill switch (with Mullvad it runs automatically; with Proton VPN you will find it in the settings) and use a test to confirm that your real address is not leaking anywhere. Check for leaks at browserleaks.com or ipleak.net. The test confirms only your current set-up, so repeat it after app updates or a change of device. And treat a VPN as one layer of protection among several, not a cure-all that solves everything at once. That, after all, applies to security in general, digital and real-world alike.
“The best VPN is the one you stop thinking about. It works quietly in the background, just like good protection.”— Robert Václavík




