Should You Use a VPN? - Consumer Reports (2024)

For years, many security experts advised people to use virtual private networks, or VPNs, to help make their internet browsing more secure.

In particular, VPNs were supposed to help people avoid getting hacked while they were using the free WiFi at an airport or library, because these services route browser traffic through an encrypted tunnel. VPNs could also keep your internet service provider from knowing what sites you visited because the traffic coming to and from your computer all travels through the VPN’s servers, or servers VPNs pay to use. That can sound good to anyone who doesn’t trust their ISP.

All that’s still valid, at least to some extent. But as a tech journalist who’s been looking into VPNs since 2016, I’ve seen advice from security experts change over time. VPNs can be useful, but they’re not necessary for every person or every situation, especially now that so much web traffic is encrypted using HTTPS, the secure protocol whose initials you see at the start of most web addresses.

Many experts are much less concerned about people being hacked at a local cafe than they are about ad tracking, which uses tools that a VPN can’t defend against, such as digital fingerprinting. For the average person accessing the web from their home WiFi, there’s little reason to use a VPN service. CR’s in-depth evaluations identified leading VPNs that we’d feel comfortable using ourselves or suggesting to friends and family. But the testing also showed that some VPNs can actually make things worse for your data privacy and security. (Complete details of the testing, which was conducted on laptops running Windows 10, are on CR’s Digital Lab site.)

More on Digital Security

Mullvad, IVPN, and Mozilla VPN Top Consumer Reports’ VPN Testing

VPN Testing Reveals Poor Privacy and Security Practices, Hyperbolic Claims

How to Use 'Have I Been Pwned' to See If Your Data Was Compromised

CR Security Planner

Whether or not you decide to use a VPN, security experts say, there are other, more critical actions you should take first to be safer online. “VPNs are so pervasive because it’s possible to sell them,” says Dan Guido, CEO of the cybersecurity firm Trail of Bits. “There are so many good security techniques, tools, resources, guidance that just aren’t packaged in a format to be sold.”

Important safety steps, most of which are free, include using a password manager, setting up multifactor authentication, enabling HTTPS-only mode on your web browser, and blocking ads or trackers with a tool like Privacy Badger or uBlock Origin. You should also encrypt your laptop and keep your software up to date. (For a customized plan to improve your digital security, check out the CR Security Planner.)

Why You May Not Want a VPN

Years ago, large parts of the web were unencrypted. Since well-configured VPNs encrypt all the traffic leaving your computer, they were an important layer of protection for many people. But there have been massive improvements in the security of operating systems and browsers since then. These days, you might be able to spend hours online—banking, emailing friends, posting on social networks, shopping, and watching videos—without landing on an unencrypted website.

Google now downranks sites that don’t use HTTPS, and browsers will alert you when you try to visit a site without HTTPS connections. Let’s Encrypt, a nonprofit organization that provides encryption certificates to websites free of charge, says that it is currently providing certificates for 276 million websites.

Some people may want to use a VPN to try to hide their identity or location from websites they connect to. That’s because the technology will mask your IP address, but that isn’t as effective a step as it might seem. Although company websites do use IP addresses as an identifier, there are many other tools they use that a VPN will not protect you from.

Your location can be determined from your GPS, and gleaned from the name of the WiFi network you connect to. And you can be tracked through web cookies, tracking pixels, and digital fingerprinting, in which apps and websites triangulate characteristics of a computer or phone, such as operating systems and model names, and screen resolutions, to uniquely identify individual users.

“There’s a ton of metadata, there’s a ton of time correlation, and those are not just hypothetical issues,” says security researcher Kenneth White. “There’s a multi-multi-billion dollar identity monetization industry right now. There’s entire lines of business and startups and there’s a whole ecosystem and world around it.”

Because a properly configured VPN routes traffic through an encrypted tunnel, your network history (all of your data, such as messaging and app use) is hidden from your internet service provider, and any third parties they might share that data with. Without a VPN, your ISP can see what sites you visit, how long you’re on them, and information about your devices. Many ISPs share far more data than their customers expect, including their browsing history and location data, a recent FTC report revealed.

While using a VPN means all that information is hidden from your ISP, the VPN provider can see it all instead. And it’s extremely hard to judge how well any of the hundreds of VPNs on the market take care of your data, because unscrupulous VPNs historically have left it unsecured and shared or sold the information they collected about the sites users visited and apps and services they used to marketers.

“I understand if users worry about ISPs tracking and selling their data. But on the other hand, transferring that data and trust onto a random, unverified commercial VPN provider, might be even worse,” said Reethika Ramesh, PhD candidate at the University of Michigan and lead researcher at VPNalyzer, an interdisciplinary research project headed by professor Roya Ensafi that aims to analyze the VPN ecosystem.

In Consumer Reports’ testing of VPNs running on Windows 10, Mullvad, IVPN, and Mozilla VPN stood out for their strong privacy and security protections. They all have consumer-friendly privacy policies, and marketing copy accurately represents their product and its underlying technology. In addition, their client-side code—the software that runs on your computer—is open-source, so it can be inspected by outside researchers like those at Consumer Reports. And these VPN providers subject themselves to independent third-party security audits and publish the results. (You can read our full testing report here.)

Should You Use a VPN? - Consumer Reports (1)

Illustration: Miguel Porlan Illustration: Miguel Porlan

When a VPN Can Help

For some people in some circ*mstances, VPN services can be a useful part of a plan to improve your online security and privacy.

As described above, VPNs can mask your IP address. Although there are many other ways to track you across the web, an IP address is an easy tool for doing that. Masking it can provide a bit of distance if you’re connecting to a site you don’t trust—especially when you combine a VPN with additional privacy methods.

Hiding your IP address can offer protection against being easily identified by small sites where administrators look at the logs. And because some sites do use IP addresses for ad retargeting, a VPN is one of several tools that can prevent those annoying ads from following you across the web.

In addition, you might want privacy from the owner of the local coffee shop, or the administrators at your college or a community center. Whoever runs the WiFi network you’re using can learn what websites you’re communicating with. “If you have a personal relationship where you know the name of the person operating your network, you might consider using a VPN, because that level of connection also allows the person to make a connection to you,” Guido says. “They might know your name. They might want to know what you’re doing.”

Even though most websites are encrypted, “not every single thing is encrypted,” says Matthew Green, associate professor at the Johns Hopkins Information Security Institute. “You go to websites that are not encrypted and stuff oozes out from around the side and a VPN wraps all that up so that for that coffeehouse kind of situation, you’re getting protection,” he says. “For most of the reputable services, I don’t think it can hurt and it might help.”

Tips for Using a VPN to Stay Safe

VPNs can add a layer of security and privacy to your web browsing, but it’s a relatively thin layer considering how good the tech industry has become at tracking people.

The most important thing to do about this is to use the safety steps I listed above, such as a password manager, multifactor authentication, and tracking blockers, and to follow standard safety advice to avoid online dangers that have nothing to do with your ISP or IP address. “VPNs do not protect against most known online risks, such as phishing, tracking, malware, and ransomware,” says Roya Ensafi, assistant professor at the University of Michigan’s computer science & engineering department and principal investigator of VPNalyzer.

White is quick to point out that there’s ultimately no guarantee that a VPN provider is on the level, even when testing like Consumer Reports’ comes back with good results. “The best we can do is to get an assessment for symptoms and hints of trustworthiness when we evaluate a VPN,” he says.

That said, choosing a VPN that seems solid is much safer than one without those signals of trustworthiness. Not doing so could put you at risk. If you use a VPN with a default configuration that’s insecure, it could allow for lateral movement, where an attacker can move through your home network and access all of your devices.

“Any other user on the VPN node you connect to is effectively now sitting on your internal network—be that at home or in the office,“ White says. “In attempting to be more secure, subscribers are instead literally silently opening their network up to potentially hostile or criminal threat actors.”

You may also want to create separate browser profiles to use—one for when you’re logged into your VPN and one for when you’re disconnected. If you are logged into a Google account while your VPN is connected, for example, it’ll be associated with your IP address and that account.

Also, check the VPN settings to ensure that the strongest protections are turned on. An important one to look for is a kill switch. With a kill switch enabled, the VPN will disconnect your internet connection if it temporarily loses contact with the VPN’s servers. (If your VPN connection falters and there’s no kill switch, your traffic and location will no longer be protected, but you may not realize it.)

Finally, if you are an activist, a journalist with sources to protect, or are at heightened risk because of who you are or what you do, a VPN might be part of the solution. However, it’s important to reach out to organizations such as Access Now that can provide customized recommendations for your specific situation, which will likely include additional measures beyond just using a VPN—and in some cases, may not involve a VPN at all.

Should You Use a VPN? - Consumer Reports (2)

Yael Grauer

I am an investigative tech reporter covering digital privacy and security. I'm the lead content creator of CR Security Planner, a free, easy-to-use guide to staying safer online. Prior to Consumer Reports, I covered surveillance, online privacy and security, data brokers, dark patterns, clandestine trackers, security vulnerabilities, VPNs, hacking, and digital freedom for Wired, Vice, The Intercept, Slate, Ars Technica, OneZero, Wirecutter, Business Insider, Popular Science, and other publications. Follow me on Twitter (@yaelwrites)

Should You Use a VPN? - Consumer Reports (2024)

FAQs

Is there a downside to using a VPN? ›

While VPNs have a lot of perks, there are potential downsides, too. A VPN can reduce internet speed and increase latency, which slows down online activities. Using a VPN can get your accounts blocked by social media sites for suspicious activity.

What is the best VPN service for Consumer Reports? ›

Mullvad, IVPN, and Mozilla VPN topped Consumer Reports' VPN testing. Among other characteristics, they are transparent about their privacy and security practices; offer fast, reliable connections; and are easy to use across devices.

Should the average person use a VPN? ›

Always keeping a VPN on is necessary to ensure that your device and personal information is protected. For instance, with a VPN (Virtual Private Network) always on, can protect you from cyberthreats on public Wi-Fi.

Do you actually need a VPN? ›

Is a VPN worth it? Nowadays, everyone needs a VPN. It's the best way to protect yourself online. While most people aren't suffering in oppressive regimes that heavily censor the internet and restrict what you can see and do online, that doesn't mean they don't need a VPN.

Do you think the legitimate uses of a VPN outweigh the negatives? ›

Do the benefits of a VPN outweigh the disadvantages? Using a VPN is the best online privacy and security solution available today. It's easy to use, affordable, and secure. The only downsides are a slight drop in connection speed and the bad reputation that VPNs get from sketchy free service providers.

Why not use NordVPN? ›

Torrenting: Although NordVPN allows torrenting on its servers, not all servers work with torrent clients. Finding a server for torrenting requires trial-and-error. Device limit: You can't connect all your devices to NordVPN all at once like you can with options like Surfshark and Private Internet Access.

What is better than using a VPN? ›

One of the best alternatives to a VPN is a proxy server. A proxy server acts as a gateway that sits between a user's device and the internet. The user can activate the server in their web browser and proceed to reroute their traffic through it. This helps to hide their IP address from any web servers that they visit.

Which VPN is most trusted? ›

What is the best VPN in 2024?
  • ExpressVPN holds CNET Editors' Choice Award for best overall VPN. ...
  • Surfshark is a great choice for folks seeking good features on a budget. ...
  • NordVPN is an excellent feature-packed VPN.
5 days ago

What is the safest VPN location? ›

5Which countries are best for VPN server locations? Switzerland, Iceland, Estonia, Canada, Singapore, Spain, the UK, Panama, Romania, and Germany are considered the best countries for VPN server locations due to strong privacy laws, advanced internet infrastructure, and minimal content restrictions.

Do you need a VPN on home Wi-Fi? ›

Do you need a VPN? Probably not. When you established your home Wi-Fi network, it is likely that you protected your network with a password. Because of that, you may not need the added security of a VPN to shield your online activity.

Does VPN work on home Wi-Fi? ›

You can use a VPN for home network security by configuring one on your router. Once you've set up a router VPN, every single device connected to your router will have its traffic sent through the encrypted tunnel. Your PC, your laptop, your home entertainment system, and even your smart IoT toaster.

When should a VPN not be used? ›

While people sometimes use VPNs to bypass geo restrictions or for malicious deeds, some websites block access if a user's VPN is on. In such cases, disabling a VPN might be necessary. Avoiding software conflicts. Some applications or services, such as online games or streaming services, may clash with a VPN.

Should I leave my VPN on all the time on my phone? ›

Yes, you should always keep your VPN on whenever you're online. It keeps your sensitive information away from prying eyes and ensures a private, secure connection to the internet. On top of that, setting up and using a VPN is super simple, making it easy for you to protect yourself online.

When should you not use VPN? ›

Why shouldn't I use a VPN?
  1. A VPN might reduce your connection speed even if your internet service provider isn't throttling your speed;
  2. Using a VPN on mobile will increase your mobile data usage;
  3. Some apps may require your IP to come from your country of residence. This is particularly common with banking apps.

Is VPN safe or risky? ›

A VPN connection is made through highly secure protocols at a level of encryption that has never been cracked. This, coupled with the anonymity of IP masking and location spoofing, renders your online presence nearly untraceable. If you or your organization handle sensitive information, then a VPN is a must.

What are the pros and cons of VPN? ›

A VPN is an effective tool to enhance online security and privacy, access geo-restricted content, and protect against cyber attacks. The use of a VPN can result in slower internet speeds, compatibility issues with certain devices, and premium services coming at an additional cost.

Top Articles
Latest Posts
Article information

Author: Gregorio Kreiger

Last Updated:

Views: 5737

Rating: 4.7 / 5 (77 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Gregorio Kreiger

Birthday: 1994-12-18

Address: 89212 Tracey Ramp, Sunside, MT 08453-0951

Phone: +9014805370218

Job: Customer Designer

Hobby: Mountain biking, Orienteering, Hiking, Sewing, Backpacking, Mushroom hunting, Backpacking

Introduction: My name is Gregorio Kreiger, I am a tender, brainy, enthusiastic, combative, agreeable, gentle, gentle person who loves writing and wants to share my knowledge and understanding with you.