.::vpn::.

updated 2026-07 · 10 min read · index

a vpn is an encrypted pipe between your device and a company's server. your isp sees that you talk to the company. websites see the company's address instead of yours. that is the entire product. the diary from the dns guide does not get burned, it gets handed to whoever runs the pipe. trust displaced, not removed. this page is about choosing that whoever, and about cutting through the thickest marketing fog in all of privacy.

what you actually buy

useful, real, and bounded. now the other list.

what you do not buy

the protocol

wireguard recommended in the linux kernel · noise framework

the protocol worth caring about. the linux implementation is under 4,000 lines of code, against the hundreds of thousands in openvpn plus openssl or the ipsec stack, which is the difference between something one person can audit and something nobody ever fully has [1]. the handshake is built on the noise framework and the protocol has been formally verified with the tamarin prover [2]. it lives in the linux kernel since 5.6, it is fast, and it roams from wifi to mobile data without dropping the tunnel.

one honest caveat: a plain wireguard server holds each peer's public key and last seen endpoint ip in memory while the peer is configured. serious providers wipe idle peers and build mitigation around this; it is a fair question to ask any provider that does not document it. and remember what a protocol is. wireguard is the metallurgy of the pipe. it says nothing about the plumber.

"no logs" is a claim, not a feature

anyone can type the words into a privacy policy, and nearly everyone does. evidence comes in three grades, weakest first.

the same involuntary test cuts the other way. purevpn and hidemyass both advertised no logs, right up until the logs they kept put their own customers in handcuffs [5]. the words on the website were identical in every case. only the raids told the truth.

jurisdiction is not a talisman

swiss flags and offshore islands are decoration until a court order arrives. in 2021 proton, as swiss as it gets, was legally compelled to start logging the ip of one mail account, and a french climate activist was arrested off the result. no appeal was possible. under the same swiss law, their vpn arm could not have been compelled the same way, because the law happens to class email and vpn services differently [6]. read that twice: the outcome turned on a statutory category, not on anyone's principles. that is also why proton is filed on this page as a lesson and not in the shortlist below. laws change, orders arrive gagged, and the only data that survives every future legal theory is data that was never written down.

who owns your vpn

a quieter problem: consolidation. kape technologies, formerly crossrider, a company with an adware pedigree, owns expressvpn, private internet access, cyberghost and zenmate, plus a collection of vpn review sites that rank its own products at the top [7]. that is not proof any of them misbehaves today. it does mean four apparent competitors share one owner, and much of the "independent review" economy is that owner's marketing arm. the top-10 listicle that sent you shopping was probably part of the inventory.

free vpns

researchers analyzed 283 android vpn apps: 18% tunneled without encryption at all, around 38% tripped malware detection, 75% embedded third party tracking libraries, and 84% leaked ipv6 traffic outside the tunnel [8]. a vpn sees everything your isp saw. handing that position to an unpaid stranger is the whole threat, gift wrapped. the rare honest free tier exists, funded openly by a paid one, but the category defaults to hostile.

picking one

the checklist, in the order that matters: can you sign up without an email address, can you pay with cash or monero, is the infrastructure diskless, has the no-logs claim survived an involuntary test, who is the owner, does it run wireguard. lifetime deals are a red flag by themselves, subscriptions are the business model and a lifetime of costs against one payment has to be recouped somehow.

mullvad recommended sweden · wireguard · cash accepted

numbered account, no email asked. a flat monthly price for over a decade, cash in an envelope accepted, ram-only servers, and the one office raid on this page that ended with police leaving empty handed [3]. mullvad.net

ivpn recommended gibraltar · wireguard · audits published

same ethos: accounts without email, monero accepted, regular independent audits, and no review-site marketing machine pushing it at you. ivpn.net

cryptostorm niche token auth · monero · onion and i2p

no accounts at all: you buy a token, the service stores a hash of it and nothing else. diskless nodes, traffic obfuscation, zero marketing polish. built for people whose threat model includes the provider itself. cryptostorm.is

mullvad and ivpn also sit on the privacy guides shortlist, built from published criteria [9]. and the community-run directory kycnot.me, already covering the rest of the no-kyc world, grades all three of these on exactly the account and payment questions above. a good second opinion that is not owned by anyone's marketing department [10].

the dials that matter

the five minute audit

run it after every install and every big update. connect, then test for dns leaks. ask a what-is-my-ip page whether it sees the exit or your home address, in ipv4 and in ipv6. start a download, pull the cable or toggle wifi, and confirm the kill switch fails closed. reconnect and check the leaks again. five minutes, and it catches almost every way a tunnel quietly fails. what it cannot catch is the browser you carry through the tunnel, which is its own war.

the seams

vpn or tor

privacy from your isp, your network, and casual site logging: vpn, and the trade is paying one company you chose carefully. anonymity against someone who might actually come looking: tor, free, slower, and with no customer list anywhere. combining them is a real topic with real trade-offs in both directions, and the right answer depends on which adversary sits at the top of your threat model, not on a forum post. when in doubt, plain tor beats a clever stack you do not fully understand.

sources

[ home ]

.::  eof  ::.