If you think a VPN is protecting your identity then this IT manager has something shocking to share

IT manager Michael Dear explains why virtual private networks aren’t at all private when it comes to protecting your identity or online behaviour

I would like to start this column with two statements.

The first is, I donโ€™t care. When it comes to peopleโ€™s proclivities, that is. Do whatever you want so long as it isnโ€™t illegal or hurting someone. Believe me, Iโ€™ve been doing this job long enough that I have almost certainly seen it before.

Instead, I’d rather you were honest. I firmly believe in the idea of IT/user confidentially as I want to help and definitely donโ€™t want to judge. Your mileage may vary with who you are getting help from, but my rates are reasonable.

Second, if it isnโ€™t your computer then donโ€™t trust it. By definition, your work computer or mobile are not yours; theyโ€™re owned and managed by your employer, so donโ€™t play or do anything on them that isn’t required by work. I donโ€™t trust my work devices and I manage them! Let me put it another way: if youโ€™re not happy to have your computer screen projected into a public place with your face and details attached so that everyone passing can see it, then donโ€™t do it on a work device.

So with that out of the way, letโ€™s talk about VPNs. In the UK, a piece of legislation has come into effect that means websites with โ€œadultโ€ content must confirm UK-based visitors are over 18 before granting access. There are many ways this can be done, such as handing over credit card details and uploading a copy of government-issued ID, but people are rightly wary of doing this. Thatโ€™s why people have started to ask about VPNs, especially when services that require personal data checking canโ€™t hold on to the records they’re meant to keep secure.ย 

There has been a noticeable increase in the adverts for VPNs, so what are they, how do they work and are there any downsides?

What are VPNs?

In general I like VPNs. I use them regularly. But, and itโ€™s a big but here, I also understand what they do and donโ€™t do.

Most people think that using a VPN means you are untraceable, a ghost-like actor on the internet, and that just isnโ€™t true. Letโ€™s say youโ€™re trying to get around a simple geo block, be that outside of the UK and wanting to access BBC iPlayer or in the UK wanting to access US Netflix. Youโ€™re using the VPN to appear to be in a different location. I suspect some people imagine the VPN as a pipe that transports over the internet and comes out somewhere else. I know thatโ€™s how I explain it when doing staff training, but itโ€™s a lie. A useful lie, but a lie nonetheless.

Letโ€™s go back to our example above where youโ€™re using a VPN to access a TV site in another country. The trouble is that the โ€œinternetโ€ is not a single thing but a mixture of services and protocols that have built up over time. Programs take care of this complexity for you, hiding the hundreds of three- and four-letter acronyms that are in use.

You use two different protocols to access a website. One is DNS, which (for instance) translates the name bbc.co.uk into an address 123.132.12.2. Once you have the address, your browser uses that to connect to the server that hosts the website and uses HTTP to download the webpage. Iโ€™m deliberately trying to keep this high level; just remember DNS does addressing and HTTP does websites.

The DNS question

Your DNS server address is typically given to you by your ISP, and in the UK your ISP must hold a record of IP-plus-query for a length of time for the authorities. They can then request this data, so all the sites you visit are logged to the router in the house. You donโ€™t have to use your ISPโ€™s DNS and you can change it, but for most people the default is to use the ISPโ€™s choice.

Letโ€™s assume that you are only sending website traffic over a VPN. When you start your VPN, this will use DNS to look up the name-to-address of the VPN server; your ISP now has a record that youโ€™re using a VPN, but because you havenโ€™t changed your DNS settings you will continue to use the ISP DNS server. That means the ISP continues to get a record of what you are looking up, but now so does the VPN provider through the connection to the web servers. You have in effect doubled the amount of logging of what you are doing.

You can get around this by using something called DNS over HTTP. Most browsers have this option under privacy and security settings. DNS over HTTP submits the browserโ€™s DNS requests over an encrypted connection, and that would go over the VPN which is where the logging would say the request came from.

However that doesnโ€™t stop you being tracked or located, because as soon as you sign into Microsoft/Google/A.N.Other site, they capture your information. They donโ€™t care that you suddenly moved IP address via your VPN: the second you loaded your browser they knew who you are and carried on tracking you. 

How to avoid being tracked

So there are ways to use VPNs but they donโ€™t stop tracking. If you want to do that, remember that the worst tracking stems from ad firms who appear in the โ€œallow cookiesโ€ boxes on websites: if you want privacy this is the place to start every time. The reason itโ€™s annoying is because itโ€™s so powerful. Using a VPN to move geographically does work in part, but it doesnโ€™t stop you being tracked and logged. Most likely, youโ€™re increasing the footprints that you leave by doing this. 

What do I suggest?

  1. Remember on the internet everything is tracked and remembered there is no โ€˜ghost modeโ€™. You have to hide in plain sight. To try and be a ghost is very difficult; one wrong move and youโ€™re found, as many cyber criminals have found to their cost.
  2. Consider switching from your ISPโ€™s default DNS settings. Go into your router and change its DNS entry to one of these: 1.1.1.1 (Cloudflare), 8.8.8.8 (Google) or 9.9.9.9 (IBM). These are massive and you can hide in the dross. If you want to experiment further, look at services like NextDNS or OpenDNS and use these for your DNS search as they allow you do all sorts of funky stuff that can be useful.
  3. Enable DNS over HTTP in your browser, and then do the above in your browser โ€“ and that means every browser you use.
  4. Donโ€™t use a free VPN. Remember, youโ€™re letting a VPN provider track you, just as you do your ISP, so you need trust in your choice. Proton has the best reputation among the free provides, but I donโ€™t use them and never have. Remember, if itโ€™s free then you need to ask how do they run the service and pay for the bandwidth it needs? The most likely answer is by monitoring you and selling that information on.

I could go on but this article is already way too long. So I will simply finish by saying be careful out there: someone is watching.

michael dear
Michael Dear

Michael has worked for more than 20 years running IT departments, mainly for small to medium insurance firms. His primary interest is focused on security and compliance.