Skip to content

freeswan.ca is independent. Some links earn us a commission; your price stays the same. How we review

freeswan.ca

What is a VPN? What it hides, what it does not, and how it works

A VPN (virtual private network) puts an encrypted tunnel between your device and a VPN server. It hides your traffic from the local network and your internet provider, but the VPN company itself can see what passes through its servers.

Updated

Bundle of blue network cables plugged in together

A VPN in one paragraph

A VPN, or virtual private network, is software (or a setting built into your phone, computer or router) that creates an encrypted connection between your device and a server run by someone else. Everything your device sends goes through that connection first and leaves the server toward the website or app you are using. The Canadian Centre for Cyber Security describes it this way in its guidance on VPNs:

"A VPN tunnel encrypts the data being transmitted between 2 parties over an untrusted network, such as the Internet."

The idea started in companies. A worker at home or in a hotel would connect to the office network as if they were sitting at their desk. Consumer VPN services use the same technology for a different job: they protect your connection on networks you do not control and route your traffic through the provider's servers.

What a VPN tunnel is

Data travels across the internet in small packets. Each packet carries a header with the sender's and recipient's addresses, plus the content. When a VPN is on, your device wraps each packet inside a new, encrypted packet addressed to the VPN server. Anyone between you and that server sees encrypted data going to one address. The server unwraps the packet and forwards the original request to its real destination. Replies come back the same way in reverse.

That wrapping is what people mean by a tunnel. The Cyber Centre explains that in IPsec tunnel mode "the entire original IP packet is encapsulated within a new IP packet". Other VPN protocols, such as WireGuard and OpenVPN, do the same job with different designs. Our page on VPN protocols compared goes through them one by one.

The Cyber Centre lists four kinds of VPN. Three serve organizations: linking two office networks, giving a remote worker access to the company network, and linking one machine to one resource. The fourth is the one most Canadians mean when they say "a VPN". The guidance calls it "third-party privacy" and says it is used to secure a connection from a public access point, such as an airport or hotel Wi-Fi hotspot, to a third-party VPN provider, which then makes your traffic "appear to originate from the third party's network".

What a VPN hides, and from whom

A VPN moves trust from one party to another. It helps to look at each party separately.

From the local network (café, hotel, airport)

This is where a VPN helps most. On shared Wi-Fi, other people on the same network and whoever runs it can try to watch or alter traffic. The Privacy Commissioner of Canada's office (OPC) published a blog post in 2017, now archived, that gives a concrete example: with a VPN, "a café owner could not determine what site you were browsing for or modify the contents of that webpage". Our public Wi-Fi safety guide has a checklist for cafés, airports, hotels and libraries.

From your internet provider

Your internet provider (Rogers, Bell, Telus or any other) carries all your traffic. With a VPN on, the provider sees an encrypted connection to the VPN server, how much data passes and when. It no longer sees which sites you visit or what you send to them.

From the websites you visit

Websites see the VPN server's IP address instead of yours, so they cannot read your home connection's address or the rough location that comes with it. That is about all a VPN changes for them. If you sign in, the site knows who you are. The OPC post warns that browser fingerprinting and cookies "mean that advertisers could continue to track you despite your use of a VPN".

From the VPN provider itself

Here the protection stops. The provider runs the server where your traffic leaves the tunnel, so it can see what your internet provider used to see: which sites you contact, when, and from which account. The OPC post puts it plainly. Sending your data through a VPN can give a malicious provider a "privileged position to monitor, log, or tamper with any or all communications that are sent through the VPN."

The same post notes that many providers say they keep no logs, while a careful reading of their terms "sometimes reveal that they retain significant volumes of identifying information". The Cyber Centre's Wi-Fi guidance adds that public VPN services are often run from servers in countries without strict privacy and data protection laws, and that providers may not vet staff who can see both unencrypted data and customer payment details. Choosing a VPN is choosing whom to trust. Read the privacy policy, look for an independent audit the provider has published, and check where the company is based.

What a VPN does not do

  • It does not make you anonymous. The OPC post calls VPNs "a poor way of guaranteeing online anonymity", compared with systems designed for it, such as Tor.
  • It does not stop malware or phishing. The Cyber Centre writes that "a VPN does not provide security against users clicking on a malicious link or downloading malicious content."
  • It does not make illegal activity legal. Our page Is a VPN legal in Canada? covers what official Canadian sources say.
  • It does not encrypt the part of the trip between the VPN server and the website. HTTPS does that, so the padlock in your browser still matters.

What a kill switch is

A VPN connection can drop for many reasons: weak Wi-Fi, a phone switching from Wi-Fi to cellular data, or a server restart. When that happens, your device may go back to sending traffic over the normal connection, without the tunnel, and you may not notice.

A kill switch is an app setting that blocks all internet traffic while the VPN is disconnected. Traffic resumes only when the tunnel is back up. Some apps apply it to the whole device; others let you list the apps that should be cut off. If you use a VPN on public Wi-Fi, turn the kill switch on. It is the setting that makes sure the protection you paid for is still there when the connection hiccups.

What is VPN split tunnelling?

Split tunnelling (often written "split tunneling") lets you choose which traffic goes through the VPN and which goes out over your normal connection. The Cyber Centre defines it as a setting that lets you "divide your network traffic and route certain data through an encrypted VPN tunnel and other data through an open network".

Typical uses:

  • A printer or TV on your home network that stops responding when the VPN is on.
  • A banking or work app that refuses connections from VPN servers.
  • A large download you do not need to protect, so you keep the VPN's speed for something else.

The trade-off is real. Anything outside the tunnel is exposed in the same way it would be without a VPN. The Cyber Centre's advice to organizations is blunt: split tunnelling "can negate the security of the VPN", and it recommends "forced tunnelling", where all data goes through the VPN, as the safer method. For a home user, a sensible rule is to leave split tunnelling off on public Wi-Fi and use it at home only for the specific app that needs it.

Some apps offer the reverse: everything goes outside the VPN except the apps you choose. Read the setting carefully, because the two modes are easy to mix up.

What is a VPN used for?

The OPC post lists the common reasons: reaching work files while travelling or working from home, distrust of an insecure wireless network. In practice, for Canadians:

  • Public Wi-Fi. Get Cyber Safe, the Government of Canada's awareness campaign, says that if you often use public Wi-Fi, "using a virtual private network (VPN) can be a safer solution."
  • Travel. Travel.gc.ca advises travellers to "use a VPN if available and legal at your destination", for example for hotel Wi-Fi or for reaching your Canadian bank. See our guide on using a VPN while travelling.
  • Work. Employers use VPNs so staff can reach internal systems safely from home or the road.
  • Privacy from your internet provider. Some people prefer that their provider not see which sites they visit, and accept that the VPN provider sees them instead.
  • Networks that block services. School, workplace or hotel networks sometimes block apps that are otherwise lawful to use. Respect the network's rules where they apply to you.

What is a VPN router?

A VPN router runs the VPN connection itself, so every device in your home goes through the tunnel without installing an app on each one. This covers smart TVs, game consoles and other devices that cannot run VPN apps. The costs are setup time and less flexibility: switching servers or turning the VPN off for one device is harder than on a phone. Our page on VPN routers explains the options and what to check before buying one.

What is a VPN concentrator?

A VPN concentrator is a piece of network equipment, or software on a server, that an organization uses to accept many VPN connections at once. It authenticates each remote user or branch office, manages their encrypted tunnels and passes their traffic into the company network. You would not buy one for home use. If your employer's IT team talks about one, they mean the device at the office end of your work VPN.

Do you need one?

If you often use Wi-Fi in cafés, airports, hotels or libraries, travel with a laptop, or prefer that your internet provider not see the sites you visit, a VPN is a reasonable tool. Pick a provider you have reasons to trust, turn on the kill switch, and remember what it leaves exposed. At home on your own secured network, with HTTPS sites and updated devices, the benefit is smaller.

See our comparison of the best VPNs for Canada

Common questions

Does a VPN make me anonymous?

No. A 2017 post on the Privacy Commissioner of Canada's blog calls VPNs a poor way of guaranteeing anonymity, because the provider can see your traffic and advertisers can still track you with cookies and browser fingerprinting.

Does a VPN protect me from viruses or phishing?

No. The Canadian Centre for Cyber Security states that a VPN does not protect against clicking a malicious link or downloading malicious content. You still need updates, care with links and, where useful, security software.

Should I leave split tunnelling on or off?

Off gives the most protection, because every app goes through the tunnel. The Cyber Centre advises organizations to avoid split tunnelling as much as possible. Turn it on only for a specific app that will not work through the VPN, and accept that this app's traffic is not protected.

Is a VPN the same as the VPN my employer gives me?

The technology is similar, but the purpose differs. A work VPN connects you to your employer's private network. A consumer VPN sends your traffic to a provider's server and then out to the open internet.

Sources