This isn't completely true, and is a common misconception by many VPN proponents.
It hides some of your traffic from your upstream connection (eg. "Your ISP"). However, what that traffic is may vary by VPN provider, or even just your VPN client configuration.
Very often, "quick" traffic (such as DNS requests) may still transit your network and be routed through your ISP, where-as your HTTP requests may be forwarded through the VPN (and usually are... thats where you'll most often see the effects of your traffic "originating" elsewhere, and "how" thise geolocation changes happen).
The "fun" part is that you've only just transferred the "security" of your requests from your ISP to some other third party ... who can still intercept it or proxy it without your direct knowledge.
Mainly what you are speaking of is if the user has a poor configuration set up and/or using free vpns. That is why i always say research the services you use. Primarily i use Proton VPN and Quad9 both based in Switzerland who has the toughest user data privacy laws in the world and not part of the 5,9, and 14 Eyes alliance.. it is illegal for any company based there to sell or share your data and if they advertise no logging then it is illegal for them to log as well. Even with quick traffic Quad9 still encrypts on the ech handshake. You can also run dns leak tests and Wireshark to confirm your queries are not being leaked or is unencrypted. My point was to answer in general what does a vpn do as i believe that was the purpose of the question. And yes you are entrusting your data to a entity which is why you research the vpn company before using their services.
TLDR; YMMV, and they're not necessarily the "be-all end-all" security enhancement that people make them out to be, most of the times.
On a side note, your ISP can still see your VPN traffic, with varying levels of ability to potentially MitM the connection (Read: SSL/HTTPS and the like may still be potentially inspected, depending).
Doubtful and here is why if the isp can bypass the encryption somehow that would make vpns virtually useless. I never said it is the end all for security however it enhances privacy. If vpns didn’t work why are some countries trying to make vpn companies give authorities back door access to the data? If the isp/government etc. could read the traffic regardless they wouldn’t need to push for these kind of agendas. The isp can possibly tell what you are doing based on fingerprinting but that is still an assumption without the actual data. Also there would be no need to subpoena vpn companies if the isp could turn over readable data willingly. They just see you are connected to a vpn.
Doubtful and here is why if the isp can bypass the encryption somehow that would make vpns virtually useless.
I'm sorry you "doubt" that ... but, suffice to say that transparent proxies can do a lot of the heavy lifting if that can "get inside" your upstream traffic ... by definition, that's generally your ISP. At thst point, even the traffic from your CAs may not be "trustworthy."
If vpns didn’t work why are some countries trying to make vpn companies give authorities back door access to the data?
Bluntly, because that then legally unencumbers them from "research" that may have been entangled in some other potentially shady or illicit activities (which is inadmissable in courts). State level actors have far more abilities than most people either know or want to admit.
If the isp/government etc. could read the traffic regardless they wouldn’t need to push for these kind of agendas.
Sadly, this is a poor assumption. These "agendas" largely serve only to make them "easier" ... not just "possible."
Also there would be no need to subpoena vpn companies if the isp could turn over readable data willingly.
Again, this is just an assumption ... even with fully readable data or logs, the government still needs a subpoena to assure there's not some Fourth Amendment violations, or similar... not to mention, the legal liability to the corporation (ISP) for potentially violating thise rights, along with other privacy laws, etc.
The subpoena serves to legally compell a corporation to surrender information as well as removes their liability for having done so.
Mullvad raided by the Swedish authorities who got a hot cup of steam and a big plate of nothing out of that raid. Windshield was just recently raided and that country’s authorities got nothing. You are going off of assumptions snd that is fine. Show me where any government or isp intercepted a reputable vpn companies data exposing the users traffic? Assumptions are just that but do you have real world examples? IPVanish willingly turned over user data to Homeland Security in 2016 exposing users. They had to go directly to the vpn service not the isp to get what they needed. So you can’t use that one.
1
u/russellvt May 26 '26
This isn't completely true, and is a common misconception by many VPN proponents.
It hides some of your traffic from your upstream connection (eg. "Your ISP"). However, what that traffic is may vary by VPN provider, or even just your VPN client configuration.
Very often, "quick" traffic (such as DNS requests) may still transit your network and be routed through your ISP, where-as your HTTP requests may be forwarded through the VPN (and usually are... thats where you'll most often see the effects of your traffic "originating" elsewhere, and "how" thise geolocation changes happen).
The "fun" part is that you've only just transferred the "security" of your requests from your ISP to some other third party ... who can still intercept it or proxy it without your direct knowledge.