HomeTechnologyWhat a VPN actually hides

Technology / The Privacy Desk

A VPN tunnel is not a cloak

A VPN is the most misunderstood product on the internet. It hides real things — and leaves other things in plain view that most people assume are covered. Here is exactly who can still see you, what happened when “no-logs” promises met courtrooms, and how the law changed underneath all of it.

Illustration of a laptop connected through a glowing tunnel, surrounded by watching eyes representing internet providers, websites, and data brokers
The tunnel hides your traffic from some observers — and hands it, in full, to another.
32%of US adults say they currently use a VPN — a frequently misunderstood privacy tool, firmly in the mainstream
+1,400%the surge in one VPN provider’s UK signups within hours of the UK’s age-verification law taking effect in July 2025
~96%flow-correlation accuracy demonstrated against Tor in published research, from about 900 packets — timing attacks that apply to VPN tunnels too
Sources EFF·DOJ & court records·USENIX Security·Citizen Lab·FTC·Supreme Court·Ofcom·Apple·Mozilla·vendor disclosures (all cited, with direct links, below)
The bottom lineVPN privacy / 2026
§1A VPN moves trust; it does not erase it. It blinds your internet provider and hands its privileged view — every destination, every timestamp, your real IP address — to the VPN company instead. Who sees what →
§2Your identity leaks above the tunnel. Cookies, browser fingerprints, and logged-in accounts identify you across sessions no matter what your IP says. Disconnecting and reconnecting changes almost nothing. The two-session problem →
§3Nobody finds your address from a VPN visit. They find it from breach dumps and people-search sites — a chain that has nothing to do with your IP, and everything to do with reused emails and phone numbers. The exposure chain →

Picture your internet traffic as postcards. Everyone who handles a postcard can read it. A VPN puts your postcards inside one envelope addressed to the VPN company, which opens it and mails the contents onward. Your mail carrier — your internet provider — now sees only that you send a lot of envelopes to one address. But the VPN company inherits the privileged position your carrier just lost: your real IP plus every destination and its timing, while HTTPS still seals the contents of properly encrypted pages. That is most of what a VPN is. The rest of this article is what that sentence does not cover.

Who sees what: the honest grid

Five observers watch your browsing. A VPN blinds exactly one and a half of them.

Your browsing, as seen by…
Without a VPNWith a VPN
Your internet providerEvery domain you visitSees only the tunnel
The VPN companySees nothingDestination metadata + timing
Websites you visitYour IP + cookiesNew IP, same cookies
Google, while logged inEverything, by accountEverything, by account
Employer (managed device)The screen itselfThe screen itself

“Sees only the tunnel” still includes that you use a VPN, which one, when, and how much data moved. One nuance the ads skip: thanks to HTTPS, even without a VPN your ISP sees which domains you visit — not the pages or searches on them.

The second row is the one the ads skip. The VPN company inherits the privileged position your provider lost: your originating IP plus destination and traffic metadata for every connection — attached, usually, to a payment method with your name on it — while HTTPS still protects the contents of properly encrypted pages. Even Mozilla, which sells a VPN, states plainly that a VPN will not stop cookies, fingerprinting, or logged-in accounts from recognizing you. And your ISP still sees the tunnel itself: a real million-user ISP identified more than 85% of OpenVPN connections in live traffic.

The industry selling the cloak
12 of 16VPNs tested by Consumer Reports misrepresented products or made overly broad protection claims
75%of leading VPNs made misleading claims, per lawmakers’ letter asking the FTC to investigate
N/Athe meaning of “military-grade encryption” — a marketing phrase, not a real standard
Myth“A VPN makes me anonymous online.”
FactA VPN changes who can see you, not whether you can be seen. Anonymity tools exist — Tor routes traffic through three parties so no single one sees both you and your destination. A VPN is one party that sees both.

The employer row deserves one plain sentence: on a company-managed laptop or phone, monitoring software sits below any VPN — it can capture the screen, the keystrokes, and the browser itself, and corporate firewalls with an installed company certificate can decrypt HTTPS outright. No consumer VPN changes that. (On an iPhone, Settings → General → VPN & Device Management shows whether such a profile is installed.)

What this means for you

A VPN is a trust decision, not an invisibility decision. You are choosing to believe a VPN company’s promises over your internet provider’s. Sometimes that is a good trade — the next sections are about checking the promises.

The two-session problem

Connect. Look at something. Disconnect. Reconnect an hour later. Can anyone tell both sessions were you? Three observers — and none of them necessarily forget you.

Observer 1 · the VPN company

Trivially, if it keeps records: both sessions authenticate with the same account, bought with the same payment details, from the same home IP.

Observer 2 · the websites

They can, without noticing your IP changed — cookies and your browser’s fingerprint survive the disconnect untouched.

Observer 3 · anyone watching both ends

Given the right vantage point, yes: published traffic-correlation research matches encrypted flows by timing and volume alone.

The uncomfortable summary: disconnecting and reconnecting resets your exit IP — and almost nothing else.

On observer one, the proof is a court record. In 2017, the FBI asked PureVPN — a “no-logs” provider — about a Massachusetts cyberstalking suspect. PureVPN’s records showed the same customer connecting from two originating IPs: his home and his workplace — and investigators described the same VPN exit IP touching his real Gmail, the burner account sending the threats, and an everyday pet-sitting account within minutes of each other. No browsing logs were needed; timestamps did it. Ryan Lin was sentenced to more than 17 years. The counter-model proves the rule: Mullvad issues random numbered accounts, takes no email, and accepts cash in envelopes precisely so it cannot link sessions to a person.

On observer three, the research is stark. DeepCorr, a deep-learning correlation attack presented at one of security’s top conferences, matched flows through an anonymity network with about 96% accuracy using roughly 900 packets — a few seconds of browsing — and that was against three-hop Tor. A one-hop VPN is the easier target. Website-fingerprinting studies hit ~98% accuracy guessing which site you visited from encrypted traffic patterns alone in lab conditions.

The 60-second failure that cost 6 years

Nickolas Sharp, a senior developer, stole gigabytes from his employer, Ubiquiti, hiding behind a Surfshark VPN. Then his home internet blipped. The VPN dropped, he had no kill switch, and one request went out bearing his real home IP — straight into the company’s AWS logs. The FBI matched the VPN subscription to his PayPal. Six years in federal prison.

The tunnel held. The human, and one dropped connection, did not.

What this means for you

Turn the kill switch on — it is the setting that failed Sharp. Assume the provider can connect everything you do under one account. And know that for a motivated, well-positioned observer, timing patterns are a signature you cannot turn off.

Cookies do not care about your IP

The tracking industry stopped caring where you connect from years ago. It recognizes the browser itself.

A cookie is a name tag your browser volunteers to every site that set one. Change your IP a hundred times; the name tag stays pinned. And even with cookies blocked, your browser’s configuration — fonts, screen size, time zone, graphics quirks — forms a fingerprint. In the EFF’s landmark study of real browsers, more than 8 in 10 carried a fingerprint unique enough to identify them with no cookies at all.

Browsers with an effectively unique fingerprint

83.6% of 470,161 browsers tested were uniquely identifiable by configuration alone (EFF, Panopticlick study). Test your own at coveryourtracks.eff.org.

Then there is the mode people trust most. Incognito windows delete local history when they close — and nothing else. Google spent four years litigating what its own servers collected from Incognito users, and settled by agreeing to delete or de-identify billions of records of private-browsing data, rewrite Incognito’s disclosures to say Google still collects data, and block third-party cookies in Incognito for five years. Class members received $0.

Incognito window + VPN = anonymous?
No. The website still sets cookies for the session, your fingerprint is unchanged, anything you log into identifies you by account, and the VPN provider sees every destination. What you have hidden is your history from your own device, and your IP from the site. That is all.
What this means for you

Privacy from websites is a browser problem, not an IP problem. Firefox isolates cookies per-site by default; Mullvad Browser (built with the Tor Project) makes your fingerprint generic; separate browser profiles keep your logged-in life away from your private one. A VPN complements these. It replaces none of them.

The iPhone section: Apple does it differently

iPhones have a private-browsing tool most owners already pay for — and a VPN quirk Apple has never fixed.

Start with the quirk, because it is the kind of thing this article exists for. In 2020, Proton disclosed that on iOS, connections opened before the VPN turns on keep running outside the tunnel — including Apple’s own services. Researcher Michael Horowitz confirmed it was still leaking in 2022; follow-up testing found Apple services bypassing VPNs into iOS 16; and as of his August 2025 update, he reports the behavior remains. Apple has called aspects of it expected behavior and offers developers a mitigation API. If your threat model is serious, the defensible summary is: an iPhone VPN app cannot promise that everything goes through the tunnel.

What you probably have

iCloud Private Relay

Two hops: Apple sees your IP but not your sites; a partner sees your sites but not your IP. Covers Safari, DNS, and insecure app traffic only. Comes with paid iCloud+.

What you might buy

A VPN app

One hop: the provider sees both your IP and every destination, for all apps — minus the iOS leak above. You are trusting one company instead of splitting the view.

Private Relay’s split design means no single company holds the complete picture — architecturally stronger for Safari browsing than a one-hop VPN, and useless for anything outside it.

Two weeks ago: Private Relay sprang three leaks

Researchers at Mysk showed that three built-in WebKit features — DNS prefetching, the passkey standard WebAuthn, and WebTransport — send traffic around Private Relay, exposing users’ real IPs (and, via prefetching, their real DNS servers). Every iPhone browser uses WebKit, so proxy-based privacy browsers leak too. Notably, Mysk says system-level VPNs are not affected, since they tunnel all device traffic — a rare point in the VPN column. Apple says a fix is coming this fall.

And the App Store itself is part of the threat model. The Tech Transparency Project found roughly 1 in 5 of the top 100 free VPN apps in the US App Store had obscured Chinese ownership — several linked to a US-sanctioned firm — while academic testing of free Android VPN apps found decades of consistent results:

Free VPN apps, tested (283 Android apps, CSIRO)
Leaked IPv6 traffic
84%
Used tracking libraries
75%
Leaked DNS lookups
66%
Contained malware flags
38%
Didn’t encrypt at all
18%

CSIRO / UNSW / Berkeley analysis of 283 Android VPN apps. A free VPN’s business model is usually you.

How bad can free get?

The free VPN that made 19 million homes a crime scene

Free apps MaskVPN and DewVPN quietly carried the 911 S5 botnet: devices at more than 19 million unique IP addresses became proxies that criminals rented to route fraud through — including some 560,000 fake unemployment claims and $5.9 billion in confirmed losses. Users installed a privacy tool; strangers borrowed their home address on the internet.

What this means for you

On an iPhone: Private Relay for everyday Safari privacy, a reputable paid VPN when you need all-app coverage — knowing the iOS leak caveat — and never a free VPN from the charts. Check VPN & Device Management for profiles you did not install.

The courtroom record: when “no logs” met subpoenas

The marketing says nobody keeps logs. The court record keeps score — and it opens with a VPN that was the spy.

The VPN that watched you back

Facebook’s Onavo Protect was a free VPN. Unsealed court documents from an ad-practices lawsuit describe “Project Ghostbusters”: at Mark Zuckerberg’s urging, the company used its VPN position to intercept and decrypt users’ Snapchat analytics traffic — later extended toward YouTube and Amazon — to spy on competitors. The privacy product was the surveillance. Separately, the FTC found antivirus maker Avast selling “re-identifiable” browsing data from its privacy tools to over 100 third parties; it paid $16.5 million.

“No-logs” claims, tested by police, courts, and leaks
YearProviderThe testHeld?
2011HideMyAssUK court order — handed logs; LulzSec hacker convicted
2016IPVanish“Zero logs” — gave Homeland Security connection records
2016/18Private Internet AccessFBI subpoenas, twice — nothing to produce, proven in court
2017PureVPN“No logs” — logs identified a cyberstalker for the FBI
2017ExpressVPNTurkey seized the server in an assassination case — empty
2020OVPNSwedish court demanded Pirate Bay logs — none existed; won
2020UFO VPN +6 brands“No-log” free apps leaked 1.2TB of logs — with passwords
2023MullvadSwedish police raid with a warrant — left with nothing
2023SuperVPNFree app exposed 360M records: emails + real IPs + locations
2026“First VPN Service”12 years of no-logs promises — police quietly captured its traffic from late 2021 until the May 2026 takedown

Every row links to a court record, government release, or first-party disclosure in the references. The 2026 row is the newest lesson: French and Dutch police infiltrated the criminal-friendly “First VPN Service” beginning in late 2021 and quietly captured its traffic until the May 2026 takedown; the US Treasury sanctioned it in July. The pattern: audits and diskless servers pass; promises fail.

Two nuances the table cannot hold. First, jurisdictions can force the issue going forward: in 2021, Proton — under a binding Swiss order — began logging one account’s IP prospectively, leading to a French activist’s arrest. A no-logs policy is not immunity from a future court order. Second, breaches happen upstream: NordVPN’s 2018 incident was one rented server compromised through the datacenter’s management interface — forward secrecy meant no past traffic could be decrypted, but it took a researcher’s tweet in 2019 to surface it.

Can governments just decrypt the tunnel? The documented answer is: they did, when the crypto was weak. Snowden-era NSA documents describe an industrial VPN-exploitation pipeline — PPTP was broken outright, and researchers later showed a single weak 1024-bit prime would let a nation-state passively decrypt about 66% of IPsec VPN servers of that era. Modern, correctly configured WireGuard and OpenVPN have no known practical break; WireGuard’s handshake carries machine-checked proofs. The experts’ refrain: the math holds — so attackers go after keys, endpoints, metadata, and humans instead.

The modern attack timeline — leaks, not decryption
Port Fail: port forwarding exposes real IPs across providersNov 2015
USENIX: ISPs can fingerprint 85%+ of OpenVPN flows in live trafficAug 2022
TunnelCrack: rogue Wi-Fi routes traffic outside every tested iOS VPNAug 2023
TunnelVision (CVE-2024-3661): rogue DHCP silently bypasses the tunnel — a flaw baked in since 2002May 2024
Port Shadow: attackers on the same VPN server can intercept peersJul 2024

The common thread: none of these break encryption. They trick your traffic into stepping outside it — usually on hostile Wi-Fi.

What this means for you

Pick providers whose no-logs claims survived contact with police — the table names four. Prefer WireGuard or modern OpenVPN. And treat coffee-shop Wi-Fi as the actual battleground: that is where TunnelVision-class attacks live, and where a VPN — ironically — earns its keep even while these bugs exist.

Can they find your address?

Not from your VPN. From your habits — that is a different story, and it runs through the dark web’s favorite spreadsheet.

First, the reassuring mechanics. An IP address geolocates to a city at best — commercial databases are right about the city only 50–75% of the time, with errors of 25–50 km — and it resolves to your internet provider’s equipment, not your door. Turning an IP into a street address requires a legal demand to the ISP. A website operator watching a VPN visit has none of that; they would need to identify the provider, compel it (often across borders), hope it kept logs, and then compel your ISP — four steps, each needing court authority.

Now the unreassuring mechanics. People do get found — through a chain that ignores the VPN entirely:

How doxxing actually works
Username, reusedEmail found in breach dataPhone & old addresses join inPeople-search sitesCurrent address

Every link is a documented dataset: 773M emails in one 2019 credential dump; a 2024 broker breach exposed roughly 272M Social Security numbers with names, phones, and address histories; people-search sites aggregate the rest legally.

The darkest irony in the research: free VPNs feed this exact machine. SuperVPN’s 2023 leak exposed 360 million records pairing email addresses with users’ real IPs and locations — the precise join a stranger needs to connect “anonymous” activity to a person. The tool bought for privacy became the breach.

The market that sold your fingerprint

Genesis Market, taken down in an international operation, sold packages harvested from 1.5 million compromised computers: 80 million logins bundled with the victims’ cookies and device fingerprints, so a buyer’s browser could impersonate yours so convincingly that websites saw a normal login from your usual device. Criminals stopped chasing your IP years ago. They wear your browser.

And your physical location has its own market: the FTC moved in 2026 to ban broker Kochava from selling phone-location data capable of tracing individuals to health clinics and homes. Your GPS betrays your address; your IP never had it.

Can you scrub yourself out? Consumer Reports tested seven paid data-removal services against the people-search sites for four months. The results argue for doing it yourself:

Share of found records actually removed
Manual opt-outs (you, free)
Paid removal services (avg.)

Consumer Reports, four-month study, 2024. Data also reappears — opt-outs are a routine, not an event. One bright spot: Californians can now file a single deletion request that reaches 600+ registered data brokers through the state’s DROP platform, which brought its first enforcement action this month.

What this means for you

Your address leaks through your email, your phone number, and forty old accounts — not your IP. Unique emails per site, a masked phone number, and an annual people-search opt-out sweep protect your address better than any VPN ever will.

The law moved: why 2025–26 changed everything

VPNs went from nerd tool to civic flashpoint in eighteen months — and lawmakers noticed.

The backdrop is American: in 2017, Congress killed FCC rules — finalized but never yet in effect — that would have required your consent before your internet provider used or sold browsing data, and barred similar rules from returning. Since then, only general consumer-protection law constrains what ISPs do with your history — the original mass-market reason to buy a VPN. What changed recently is age verification. 27 states (as of August 2026) require adult sites to verify visitors’ ages; the Supreme Court upheld Texas’s law 6–3 in June 2025; and Pornhub has blocked itself in roughly two dozen states in protest.

US states with adult-site age-verification laws

Cumulative count by year enacted laws took effect, per the Free Speech Coalition’s tracker, August 2026.

Then the UK ran the natural experiment. When the Online Safety Act’s age checks switched on July 25, 2025, VPN apps seized the UK download charts — Proton reported signups up 1,400% within hours, tracked UK VPN traffic ran roughly +1,300% to +2,000% over baseline for days, and five VPNs filled the top-10 free apps, including free ones researchers flag as dangerous. Ofcom’s position, as of mid-2026: VPN use by adults is legal and no ban is contemplated — but sites must not encourage children to circumvent checks.

And the crosshairs are real, if so far empty. Wisconsin’s age-verification bill originally required adult sites to block known VPN traffic — a US first — until backlash stripped the provision in February 2026. The UK House of Lords voted to ban VPN provision to under-18s in January 2026; the Commons rejected it in March. A federal bill that would force sites to treat VPN addresses as unverified remains stalled in committee as of publication — and Utah’s 2026 amendments point at the next frontier, judging location by physical presence rather than IP, so a VPN’s address no longer legally moves you.

How we got here
Congress kills FCC rules that would have required consent for ISP use of browsing data (S.J.Res. 34)Apr 2017
India mandates 5-year VPN customer logs; major providers pull servers out2022
FTC: major ISPs pool browsing, app, and location data into ad segmentsOct 2021
Russia bans VPN advertising outrightMar 2024
Supreme Court upholds Texas age verification, 6–3Jun 2025
UK age checks begin; VPN signups spike four figures overnightJul 2025
Wisconsin drops America’s first VPN-blocking mandate after backlashFeb 2026
FISA Section 702 lapses — but existing certifications keep collection running into 2027Jun 2026

Also in the mix: the CFPB withdrew its data-broker rule in May 2025, no comprehensive federal privacy law exists, and abroad the picture darkens — India mandates five-year VPN customer logs, Russia fines VPN ads and even searches, China licenses VPNs, Iran restricts them to state-approved services.

What this means for you

Nothing here makes a VPN illegal for you in the US or UK. What the trend means: VPNs are now load-bearing civic infrastructure, governments are studying them, and the free-app sewers fill fastest exactly when a law sends millions of new users shopping. Choose before the rush.

The actually-private checklist

In order of effort. Each step closes a hole the previous ones cannot.

Pick a court-tested VPN, and flip the kill switch onPrefer providers whose empty logs are a matter of court record — and remember the setting that cost Nickolas Sharp six years.
Split your browsing into separate browsers or profilesOne for logged-in life, one for private reading. Cookies and logins stay behind the profile wall; a hardened browser shrinks the fingerprint that remains.
Harden the private browserFirefox isolates cookies per-site by default; Mullvad Browser makes your fingerprint generic. Log out means log out.
Run a leak testCheck for DNS, IPv6, and WebRTC leaks after connecting — the classic quiet failures that undo everything.
Starve the identity graphUnique email aliases per site, a masked phone number, annual people-search opt-outs — one request via California’s DROP if you qualify. This protects your address; the VPN never did.
Need actual anonymity? That’s TorThree hops, no single party sees both ends. Slower, stricter — and a different tool for a different job.

And to be fair to the much-advertised product: a VPN can earn its subscription on an untrusted network, against ISP data collection, and wherever your IP is the thing being judged — though with HTTPS now near-universal, even public Wi-Fi is less naked than the ads suggest. It is a good tool. It was just never a cloak.

A VPN moves trust. It does not create anonymity.It blinds your ISP, deputizes a company you chose, and leaves every cookie, login, and fingerprint exactly where they were. Use it for what it does — and browsers, aliases, and opt-outs for what it does not.
Jargon decoder
KILL SWITCH
A setting that cuts all internet traffic if the VPN drops, instead of quietly exposing your real IP.
NO-LOGS
A provider’s promise not to record your activity. Worth exactly as much as its court record.
FINGERPRINT
The combination of your browser’s settings that identifies it without cookies — unique for 8 in 10 browsers.
EXIT IP
The VPN server’s address that websites see instead of yours — shared with thousands of strangers.
TRAFFIC CORRELATION
Matching encrypted flows by timing and size to link a person to a destination without decrypting anything.

How we measured this

Technical claims are cited to peer-reviewed research (USENIX Security, ACM CCS, PETS), CVE disclosures, and vendor documentation; legal cases to Department of Justice releases, court records, and first-party provider disclosures; legislation to statutes, the Supreme Court’s opinion, regulator statements, and primary trackers. Statistics that conflict across surveys (VPN adoption rates) use one labeled series. Where the research record has a gap — such as the absence of any documented end-to-end case of VPN activity being matched to identity via leaked databases — the article says so explicitly rather than dramatizing the mechanism.

This article describes documented capabilities and risks for a general audience. It is not legal advice, not an endorsement of any provider, and not a guide to evading any law. Product behaviors and laws described were verified as of August 19, 2026, and both change quickly.

Common questions

Can police track you through a VPN?
Often, yes - three documented ways. Providers that keep logs can be compelled to hand them over (PureVPN, HideMyAss, and IPVanish all did, leading to convictions). Providers that keep nothing can be ordered to start logging a specific account going forward, as happened in a 2021 Swiss case. And investigators routinely bypass the VPN entirely using cookies, payments, account details, or a momentary disconnection - which is how the Ubiquiti extortionist was caught despite his VPN working correctly.
Does a VPN hide my browsing from my internet provider?
Yes - the sites you visit are hidden inside the encrypted tunnel. Your provider still sees that you use a VPN, which provider, when, and how much data moves, and research shows ISPs can fingerprint VPN protocols in live traffic. Note the trade: the VPN company inherits the privileged network position your ISP had, attached to your account and payment details.
If I disconnect and reconnect to the same VPN, can the two sessions be linked?
Yes, by three separate observers. The VPN provider links them through your account and real IP. Websites link them through cookies and your browser fingerprint, which don't change when your IP does. And an observer watching both ends can link them by traffic timing - published research demonstrated roughly 96% correlation accuracy on encrypted flows in Tor experiments, a technique that applies to one-hop VPN tunnels as well.
Can someone find my home address from my IP or VPN?
Not directly. An IP geolocates to a city at best and resolves to your internet provider, not your door - turning it into an address requires a subpoena. The realistic route to your address is reused emails and phone numbers joined against breach data and people-search sites, which works the same whether or not you use a VPN. Protecting your address means unique emails, a masked phone number, and data-broker opt-outs.
Share LinkedIn X

Sources & references

Technical claims cite peer-reviewed papers and CVE disclosures; legal cases cite DOJ releases, court records, and first-party provider statements; legislation cites primary documents and regulator pages. Laws and product behaviors change quickly — details verified August 19, 2026.

  1. EFF Surveillance Self-Defense. What a VPN does and does not protect; the trust-shift to the provider; how Tor differs. ↗
  2. Mozilla. A VPN vendor’s own admission: VPNs do not stop cookies, fingerprinting, or logged-in account tracking. ↗
  3. DeepCorr (ACM CCS 2018). Deep-learning traffic correlation: ~96% flow-matching accuracy with ~900 packets, against Tor — a one-hop VPN is the easier case. ↗
  4. USENIX Security 2022. “OpenVPN Is Open to VPN Fingerprinting” — a real ISP identified >85% of OpenVPN flows; best-paper award. ↗
  5. Leviathan Security. TunnelVision (CVE-2024-3661): rogue DHCP routes traffic outside any routing-based VPN; Android unaffected; unfixable at the protocol level. ↗
  6. TunnelCrack (USENIX 2023). LocalNet/ServerIP attacks; every tested iOS VPN vulnerable at publication; vendor patches tracked. ↗
  7. Citizen Lab / PETS 2024. Port Shadow: attackers sharing your VPN server can intercept and de-anonymize peers. ↗
  8. Proton (2020) & Michael Horowitz (2022–25). The iOS VPN leak: pre-existing connections persist outside the tunnel; reported unfixed as of August 2025. ↗
  9. Apple. iCloud Private Relay technical overview: the two-hop design, and its Safari/DNS/insecure-HTTP scope. ↗
  10. Tech Transparency Project. Roughly 1 in 5 top free VPNs in the US App Store had hidden Chinese ownership; several tied to a sanctioned firm. ↗
  11. CSIRO / UNSW / Berkeley. Analysis of 283 Android VPN apps: 38% malware flags, 84% IPv6 leaks, 66% DNS leaks, 75% tracking libraries. ↗
  12. EFF Panopticlick. 83.6% of 470,161 tested browsers carried a unique fingerprint — no cookies required. ↗
  13. Brown v. Google settlement. Google agreed to delete or de-identify billions of Incognito-era records and rewrite its disclosures; $0 to class members. ↗
  14. DOJ. The PureVPN case: “no-logs” provider’s records linked two originating IPs to one customer; 17+ year sentence. ↗
  15. DOJ. HideMyAss logs, produced under UK court order, convicted the LulzSec Sony hacker. ↗
  16. TorrentFreak. IPVanish’s “zero logs” connection records, produced to Homeland Security in 2016, revealed via court documents. ↗
  17. Mullvad. April 2023: Swedish police arrived with a search warrant and left with nothing — no customer data existed to seize. ↗
  18. ExpressVPN. Turkey seized its server in the Karlov assassination investigation; the server held no logs. PIA (2016, 2018) and OVPN (2020) passed equivalent court tests. ↗
  19. Comparitech. UFO VPN and six sibling “no-log” free apps exposed ~1.2TB of activity logs, including plaintext passwords. ↗
  20. vpnMentor. SuperVPN’s 2023 exposure: 360 million records pairing emails with users’ real IPs and locations. ↗
  21. NordVPN. The 2018 single-server breach via a datacenter management interface; forward secrecy prevented retroactive decryption. ↗
  22. Logjam / weakdh.org (ACM CCS 2015). One weak 1024-bit prime would enable passive decryption of ~66% of IPsec VPN servers — the likely basis of Snowden-era NSA capability; PPTP was broken outright in 2012. ↗
  23. WireGuard. Machine-checked formal verification of the modern VPN handshake — the crypto that has no known practical break. ↗
  24. DOJ SDNY. The Ubiquiti case: a momentary VPN drop with no kill switch exposed Nickolas Sharp’s real IP; six-year sentence. ↗
  25. Proton. The 2021 Swiss order compelling prospective IP logging of one account — why “no logs by default” is not immunity from future orders. ↗
  26. National Public Data breach (2024). ~2.9B rows; roughly 272M SSNs with names, phones, and address histories — the dark web’s join table. ↗
  27. Consumer Reports (2024). Paid data-removal services removed 35% of found records over four months; manual opt-outs hit 70%. ↗
  28. Supreme Court. Free Speech Coalition v. Paxton (June 27, 2025, 6–3): Texas’s adult-site age-verification law upheld under intermediate scrutiny. ↗
  29. Free Speech Coalition tracker. 27 states with adult-site age-verification laws as of August 2026, with effective dates. ↗
  30. UK surge reporting. Proton signups +1,400% within hours of the Online Safety Act’s July 25, 2025 age checks; tracked UK VPN traffic up ~1,300–2,000%; Ofcom: VPN use legal, no ban contemplated. ↗
  31. EFF. Wisconsin’s first-in-nation VPN-blocking mandate, stripped from the bill in February 2026 after backlash; the UK Lords’ under-18 VPN ban was rejected by the Commons in March 2026. ↗
  32. CERT-In (India). The 2022 directive requiring 5-year VPN customer logs — major providers removed physical Indian servers rather than comply. ↗
  33. S.J.Res. 34 (2017). The repeal of FCC rules that would have required consumer consent for ISP use or sale of sensitive browsing data, and that bars substantially similar FCC rules from returning — the origin of mass-market VPN adoption. ↗
  34. FTC (2021). Staff report: major ISPs combine browsing, app, and location data into ad segments, including sensitive categories. ↗
  35. Brennan Center. FISA Section 702 lapsed in June 2026; existing FISC certifications keep collection authorized into March 2027. The CFPB withdrew its data-broker rule May 2025. ↗
  36. Security.org. Annual US consumer survey: 32% of US adults currently use a VPN (2025 series; survey methodologies vary widely). ↗
  37. MaxMind. IP geolocation accuracy: city-level correctness of 50–75% with errors of 25–50 km — an IP is not an address. ↗
  38. Unsealed court records (via TechCrunch). Facebook’s Onavo VPN and “Project Ghostbusters”: intercepting Snapchat analytics traffic at Zuckerberg’s urging — the VPN as the spy. ↗
  39. FTC. Avast sold “re-identifiable” browsing data from its privacy software to 100+ third parties; $16.5 million in redress. ↗
  40. US Treasury / Europol (2026). “First VPN Service”: 12 years of no-logs marketing while police secretly captured its traffic for 4½ years; 33 servers seized in May, sanctions in July. ↗
  41. DOJ. The 911 S5 botnet spread via free VPN apps: 19M+ device IPs rented to criminals; $5.9B in confirmed fraud. ↗
  42. DOJ. Genesis Market: 80M credentials bundled with victims’ cookies and device fingerprints from 1.5M computers — browser identity for sale. ↗
  43. Mysk (Aug 4, 2026). Three WebKit features — DNS prefetch, WebAuthn, WebTransport — leak real IPs past iCloud Private Relay; Apple fix planned for fall 2026. ↗
  44. FTC (2026). Kochava banned from selling sensitive phone-location data that could trace individuals to homes, clinics, and churches — location leaks from GPS, not IPs. ↗
  45. California Privacy Protection Agency. DROP: one deletion request reaching 600+ registered data brokers; first Delete Act enforcement announced August 11, 2026. ↗
  46. Consumer Reports. 12 of 16 tested VPNs overstated protections; lawmakers separately asked the FTC to probe misleading claims like “military-grade encryption.” ↗