RE:NODE

Networking11 min read

What a VPN protects and what it does not: the threat model

An honest VPN threat model: what your ISP, the local network, websites and the VPN operator can see with and without a VPN, and the risks a VPN leaves alone.

0 readers

A VPN does one thing: it moves the point where your traffic becomes visible. Without one, your local network and your ISP see every address you connect to, every name you look up and anything not already encrypted, and every site sees your real IP address. With one, they see an encrypted connection to a single server; that server sees what they used to see, and sites see the server's address instead of yours. That is genuinely useful on untrusted networks, against an ISP that logs or sells browsing data, and on networks that block or filter services. It does not make you anonymous, does not stop tracking through accounts, cookies and browser fingerprints, does not protect against malware or phishing, and does not remove trust - it moves it to whoever runs the server.

The way to decide whether you need one is to name who you are protecting against. This post goes through each party that can see your traffic, what changes when a VPN is on, and the things people expect a VPN to do that it never has.

Who can see what#

Every connection you make passes several parties. A VPN changes what some of them see and leaves others exactly where they were.

PartyWithout a VPNWith a VPN
Local network (wifi owner, others on it)Destinations, DNS, unencrypted contentThat you connect to one server, how much and when
Your ISP or mobile carrierDestinations, DNS, unencrypted contentSame as the local network
The VPN server's operatorNothingDestinations, DNS, unencrypted content
The VPN server's hosting providerNothingTraffic volumes to and from the server
Websites and apps you useYour real IP address, plus whatever you tell themThe server's IP address, plus whatever you tell them
Your accounts (Google, Apple, social)Who you areWho you are

Read the third row twice. A VPN does not remove the party who sees your destinations; it replaces your ISP with the VPN operator. Whether that is an improvement depends entirely on whom you trust more.

What a VPN does protect#

Your traffic on networks you do not control. Hotel, cafe, airport and conference wifi, and any network where the operator or other users might watch or tamper. The VPN stops DNS hijacking, injection into unencrypted connections and observation of which services you use. VPN on public wifi goes through those risks one by one.

Your browsing history from your ISP. In many countries ISPs may retain or use connection metadata. With a VPN, the ISP sees one encrypted stream to one address.

Your home address from the sites and players you deal with. Websites, forums, game servers and peer-to-peer games see the VPN server's address. That stops someone mapping your address to your rough location or aiming a flood at your home connection. IP leaks and doxxing for server owners covers why that matters for people who run communities.

Access through networks that block things. A workplace, campus or national network that blocks particular services or VPN protocols. A VPN built to look like ordinary HTTPS, such as Xray with VLESS and Reality, is designed for exactly this - see VLESS and Reality explained. Bear in mind that VPN use is restricted or regulated in some countries, and technical ability is not legal permission. Know the law where you are.

What a VPN does not protect#

Your identity, once you sign in. Logging into an account identifies you to that service regardless of the address you arrive from. If you browse with your usual browser and accounts, the services you use know exactly who you are.

Tracking by cookies and fingerprints. Advertising and analytics follow browsers, not addresses. Cookies, local storage, and browser fingerprints - screen size, fonts, graphics card, language, time zone - survive a change of IP address completely. A VPN does nothing to them.

Your location from apps with location permission. Phones locate themselves with GPS, wifi and cell towers, not with your IP address. An app with location access knows where you are whether you use a VPN or not.

Malware and phishing. A fake login page is just as fake through a tunnel, and malicious software on your device happily uses the VPN. These need an updated system, careful habits and two-factor authentication - two-factor on your panel account explains why authenticator codes matter more than any network setting.

The security of the sites themselves. Encryption from a VPN ends at the VPN server. After that, your traffic travels to the site exactly as it would have without the VPN. HTTPS protects it end to end; a VPN does not add to that.

Your devices on the local network. Other devices on a shared network can still reach your laptop directly. Firewall and sharing settings protect against that; a VPN does not.

Leaks you have not tested for. DNS, IPv6 and WebRTC can bypass a tunnel that looks connected. VPN DNS leaks and how to test shows how to check.

Commercial VPN or your own server#

The two kinds of VPN put different parties in the "operator" row of the table above, and they differ in what the world sees.

Commercial VPN servicePrivate VPN server
Who can see your destinationsThe provider, under its own logging policyYou, as the operator; the host sees traffic volumes
Who else uses your addressThousands of other customersOnly you and whoever you give the link to
How sites treat the addressOften captchas and blocks, because of other usersTreated as one ordinary user, until you misbehave
Choice of locationsUsually manyWhere the server is
Blending into a crowdYes, that is part of the designNo; the address is yours
Detection by blocking networksWell-known address ranges are often listedA single address with its own reputation

The trade-off that surprises people: a private server gives you more control and a clean address, and less crowd to hide in. Everything that leaves your server's address is attributable to that address, which is you. If your goal is privacy from the hotel wifi and your ISP, that is a fine trade. If your goal was to disappear into a crowd, a private server is the wrong tool, and so, honestly, is a VPN. Private VPN server explained goes further into that comparison.

What survives encryption: metadata#

Encryption hides content. It does not hide the shape of traffic, and the shape says more than people expect.

Anyone on the path between you and the VPN server - the local network, your ISP - can still see when you are online, how much you send and receive, and the rhythm of it. A video call is a steady two-way stream of small packets at a regular interval. Streaming video is large bursts every few seconds. Browsing is short bursts with pauses. A large download is a solid block. None of that reveals which site or which call, but it reveals what kind of thing you are doing and when.

Researchers have gone further: with enough sample traffic, the pattern of sizes and timings when loading a specific web page can sometimes identify the page through an encrypted tunnel. This is known as website fingerprinting. It is a research technique rather than something your hotel does, but it is a fair reminder that a tunnel hides content, not behaviour.

The same applies at the other end. The VPN server sees your destinations, but so, at a coarser level, does the network the server sits on: its hosting provider sees the volume of traffic in and out, and the upstream networks see where it goes after the server. A party able to watch both your side and the server's side at once can match the timing of traffic entering and leaving. Ordinary attackers cannot do that; it is worth knowing it exists, because it is why no single-hop VPN claims to defeat a well-resourced observer.

The operator's position, including when it is you#

Whoever runs the VPN server is in the position your ISP used to occupy. On a commercial service, that means its staff, its logging configuration and whatever legal requests reach it. On your own server, it means you - and the server's address is yours, so complaints about traffic from that address, such as abuse reports or copyright notices, reach you rather than a provider with thousands of customers.

That has two practical consequences. First, what you share matters: giving the link to friends means their traffic leaves from your address too, and is yours to answer for. Second, the server's own security matters: it holds your key, and anyone who controls it sees what you would have hidden from your ISP. Keep the account that controls it protected with two-factor authentication, and treat the connection link like a password.

Things a VPN is often sold as and is not#

  • "Military-grade encryption." Modern VPNs use the same encryption as every HTTPS website - AES-GCM or ChaCha20-Poly1305. It is excellent, and it is not special.
  • "Protection from hackers." From people on your local network, partly. From attacks on your accounts, your device or the sites you use, no.
  • "Faster internet." A VPN adds a hop and some overhead. It can occasionally route around a bad ISP path; usually it is slightly slower. Why is my VPN slow has the details.
  • "Blocks ads and trackers." Some VPN apps bundle DNS-based blocking. That is a separate feature, not something the tunnel does.
  • "No logs, so you are untraceable." A logging policy is a promise about one party's records. It says nothing about your accounts, cookies, the sites' own logs or your device.

Building your own threat model#

Answer three questions and the right setup usually falls out.

  1. Who am I protecting against? The person on the next table in a cafe; my ISP; a network that blocks services; the websites I visit; a specific person who knows me. A VPN helps with the first four in different ways, and with the last one barely at all.
  2. What would they learn or do? Read my traffic, list the sites I visit, block a service, learn my home address, link my activity to my identity. Each maps to a row in the tables above.
  3. What else would I need? Usually: HTTPS everywhere (already the norm), two-factor on important accounts, a separate browser profile for anything you want kept apart from your main identity, updated software, and a firewall on laptops. A VPN is one layer alongside these, not a replacement for them.

A worked example. You travel monthly, work on hotel wifi, and sometimes stay in a country whose networks filter some services. Your threats: the hotel network, and a filtering national network. A VPN that disguises itself as HTTPS, always on with a kill switch on your phone - VPN kill switch and always-on shows how - covers both, subject to local law. It does nothing about your accounts knowing who you are, which is fine, because they were never the threat.

What RE:NODE's VPN line is#

The private VPN servers on RE:NODE are the right-hand column of the comparison above. Each is a server of your own running Xray with VLESS and Reality, so the connection looks like ordinary HTTPS to a well-known site and keeps working on networks that block VPN protocols. You get your own address and key, nobody else is on the server, and there is no traffic cap. Windows connects with the Renode VPN app and the link the server prints; phones and Macs use any VLESS client such as v2rayNG, Hiddify, Streisand or Shadowrocket. The server is in one location, Germany. It is a tool for privacy from the networks you pass through and for access through networks that block things; it is not an anonymity service, and nothing in this post should be read as saying otherwise.

FAQ#

Can my ISP see what I do with a VPN on?

It sees that you are connected to one server, how much data moves and when. It cannot see which sites you visit or what you send, provided the VPN is not leaking DNS or IPv6. With a disguised protocol it may not even be obvious that the connection is a VPN.

Does a VPN make me anonymous online?

No. It changes the address sites see and hides your traffic from the local network and ISP. Your accounts, cookies, browser fingerprint and behaviour still identify you, and the VPN operator can see your destinations.

Is a VPN worth it if most sites already use HTTPS?

HTTPS protects what you send; it does not hide which sites you visit, and it does nothing against networks that block services. If you use untrusted networks, want your browsing history away from your ISP, or face filtering, a VPN still adds something real. On a trusted home network with no filtering, it adds much less.

Can the VPN provider see my passwords?

Not for HTTPS sites, which is nearly all of them - the content is encrypted end to end between you and the site. The provider can see which sites you connect to and anything sent without encryption. On your own server, that provider is you.

In most countries, yes. Some restrict VPNs, require approved providers, or penalise their use, and some services forbid them in their terms. Check the law where you live and where you travel before relying on one.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000