Tech Behind ThingsHow the ordinary machinery actually works

Networks

How a VPN actually moves your traffic, and what it moves it away from

A tunnel changes who can see your traffic and where it appears to come from. Those are the only two things it changes.

From above of optical switch equipment with many similar connectors with rubber cables and metal parts
Photograph by Brett Sayles via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

This works through virtual private networks in the order the parts actually depend on each other.

The short version

  • A VPN encrypts traffic to a server and forwards it from there.
  • Your provider sees a connection to that server and nothing more.
  • Trust moves to the VPN operator rather than disappearing.

The mechanism is a tunnel

Your device establishes an encrypted connection to a server and wraps every outbound packet inside it. The server unwraps them and forwards them to their destinations using its own address, then reverses the process for replies.

To the destination, the traffic originates at the server; to your network provider, all traffic is a single encrypted stream to one address. That is the whole mechanism, and every claimed benefit and limitation follows from it.

What your provider can still see

The fact that you are connected to a VPN, when, for how long, and how much data flowed. Traffic volume and timing patterns can be revealing on their own, and this has been demonstrated in research repeatedly.

Anything not routed through the tunnel, including some system traffic and traffic during connection drops, remains visible. A kill switch exists specifically to block traffic when the tunnel fails, and it is off by default in several clients.

What the destination sees

A server address in whatever country you chose, which is the basis of geographic unblocking and of the countermeasures against it. Everything else about you that does not depend on the network path: cookies, logins, browser fingerprint and any identifier you supply.

At the protocol level, signing into an account through a VPN links that account to the session regardless of the address. This is why a VPN is close to useless against tracking that is based on identity rather than address.

Protocols differ in real ways

Older protocols carry more overhead per packet and use older cryptography; newer ones are leaner, faster to reconnect and easier to audit. Reconnection speed matters most on mobile, where the underlying network changes constantly. Some protocols are easier for networks to detect and block, which is why providers offer obfuscation modes.

The choice affects battery life on phones noticeably, because encryption and tunnelling cost processor time continuously.

The performance cost is structural

Every packet takes a longer path, through the server, which adds latency proportional to the detour. Encryption adds a small processing cost and encapsulation adds bytes to every packet, reducing effective throughput slightly. A server close to you and close to your destinations minimises the penalty; a server on another continent does not.

In the datasheet, occasionally a VPN is faster because it routes around a congested peering point, which is a happy accident rather than a feature.

Implementations differ, and vendors are not obliged to document the differences.

Choosing on evidence rather than advertising

The operator can see everything your provider could, so the meaningful questions are jurisdiction, logging policy and whether either has been independently audited. Court records and audits are evidence; marketing claims about no logs are not. Free services must be funded somehow, and several have been found selling traffic data or injecting content.

At the protocol level, for untrusted public Wi-Fi the case remains reasonable, though nearly all web traffic is already encrypted, which removed the original argument.

The takeaway

It relocates your traffic and your trust. Decide whether the new custodian is better than the old one.

Once you know what it is trading away, the design stops looking arbitrary.

Questions readers ask

Do I need a VPN on public Wi-Fi?

Much less than you used to. Almost all web traffic is encrypted in transit already. A VPN still hides which sites you visit from the network operator.

Can a VPN stop advertisers tracking me?

Only the portion based on your address. Cookies, logins and browser fingerprinting are untouched, and those are now the dominant methods.

Networksvpntunnelsencryptionrouting
Grigor Petrov
Hardware writer, Tech Behind Things

Grigor writes about silicon, thermals and the physical limits designers keep bumping into.

Also by Grigor Petrov