Consumers looking for tools for strong data protection and privacy often turn to commercial VPNs, or virtual private networks. VPNs route internet traffic—including users’ browsing history and other sensitive information—through their own servers or those they contract, so the privacy and security of these services is important.
Many people turn to VPNs in large part to either avoid risks on untrusted networks or to protect themselves from advertisers and internet service providers (ISPs) that might monitor, disrupt, or even tamper with internet traffic. Unfortunately, some people might not realize that apps and websites may be identifying them even when they’re masking their IP addresses. One way to do this, known as digital fingerprinting, involves apps and websites looking at and triangulating characteristics of a computer or mobile device, such as operating systems and models, screen resolutions, and so forth, to uniquely identify individual users. It’s also not possible for consumers to know with certainty that any VPN is not sharing or even monetizing user data, failing to secure it properly, or sharing it with third parties that may, themselves, be malicious.
However, it is possible to conduct a rigorous, objective evaluation of VPNs—to test for different aspects of the service that are testable, such as security misconfigurations and leaks and whether strong controls are implemented by default, and to analyze their privacy policies. It’s also possible to look for language that might mislead users about the level of protection they can expect from a VPN, and to generally shine a light on both good and harmful practices in the industry. This is what we set out to do