How to Choose a VPN

What a VPN genuinely protects against, and the privacy claims worth being skeptical of.

VPN marketing is full of language like "total anonymity" and "invisible online" that overstates what the technology actually does. Here's what a VPN genuinely changes, and what it doesn't.

What a VPN actually does

A VPN encrypts your internet traffic between your device and the VPN provider's server, and routes it through that server before it reaches its destination. Two concrete, real effects: your internet service provider (and anyone else on the same local network, like public WiFi) can no longer see which specific sites and services you're connecting to, only that you're connected to a VPN. And websites you visit see the VPN server's location and IP address instead of your own, which is genuinely useful for accessing region-restricted content or adding a layer of privacy on untrusted networks like airport or coffee shop WiFi.

What it doesn't do

A VPN doesn't make you anonymous — it shifts who has to be trusted with your traffic from your internet provider to the VPN company itself, which can now see everything your ISP used to see. A VPN with a genuinely poor privacy policy, or one based in a jurisdiction with weak data protection law, can be a worse privacy tradeoff than no VPN at all, not a better one.

It also doesn't protect against malware, phishing, or a website itself tracking you through cookies, browser fingerprinting, or an account you're logged into — a VPN operates at the network level; it says nothing about what happens once you're logged into your Google or Facebook account through it, since those services can still identify you regardless of what IP address you're connecting from.

The claim worth being skeptical of: "no-logs"

Many VPN providers advertise a "no-logs" policy, meaning they claim not to record what you do while connected. This is a claim about company policy, not a technical guarantee — it's only as trustworthy as the company making it, and there's no way for an end user to independently verify it in most cases. Providers that have undergone a genuine, published third-party security audit of their no-logs claim are offering something more concrete than a policy statement alone; that's a meaningfully stronger signal than the claim by itself.

Speed is a real, unavoidable tradeoff

Routing traffic through an extra server, with encryption overhead, has a real cost in speed — how much varies by provider, server load, and distance to the server you connect to. A VPN that seems suspiciously fast with no noticeable slowdown compared to no VPN at all is worth a second look, since strong encryption and rerouting traffic isn't free from a performance standpoint.

The one thing people forget

Check whether the VPN includes a kill switch — a feature that blocks all internet traffic if the VPN connection drops unexpectedly, rather than silently falling back to your normal, unprotected connection. Without one, a dropped VPN connection can expose your real traffic and IP address without any obvious warning that protection has lapsed.