Why using a free VPN is a no good, very bad idea
Note: This article was first published on 4th September 2018.
Using a virtual private network (VPN) is usually a good idea, especially if you frequent public Wi-Fi. By encrypting your Wi-Fi connection, a VPN protects your communications from invasive eyes and plays a vital role in your overall digital defense.
But using a free VPN is a no good, very bad idea.
“A VPN has the capability to track users’ online behavior as well as their IP,” Shahnawaz Backer, Security Specialist, F5 Networks, says. “So it’s important that a user validates the credibility and privacy clauses of the free VPN services. Otherwise, they risk giving up their data to advertisers or worst, cybercriminals.”
To be clear, I’m not talking about free VPN plans offered by known names like ProtonVPN. These companies offer complimentary, but slower, free tiers next to their full-speed VPN plans. I mean free VPN services offered by obscure brands without any paid options.
A VPN connects your device to the VPN provider’s servers, using an encrypted connection. It then connects you to the internet through those servers. Anyone trying to intercept your connection can only see that you’re connecting to the VPN’s servers.
But the way a VPN works also means that whoever runs the VPN has the potential to see what you’re doing. Facebook’s free Onavo VPN app, for example, was explicit in how it harvested users’ data. Onavo’s terms of service stated that, “ … Onavo collects your mobile data traffic. This helps us improve and operate the Onavo service by analyzing your use of websites, apps and data.”
Apple reportedly asked Facebook to remove the Onavo VPN app, as it violated the App Store’s guidelines on data collection. But the app is still available on the Google Play Store for download.
“The free VPNs services are able to log and track all user activity, online habits, and IP addresses.” Backer says. “This potentially poses as a treasure trove for advertisers, cybercriminals and agencies, should the data fall into the wrong hands.”
But how do you know that legitimate VPN services aren’t spying on you too?
Short of rolling your own VPN, there’s no way to know for sure. A VPN secures you from eyes on the network but can expose you to the VPN. There’s always risk involved, but you can call it a calculated risk. An anonymous spy on the network is most likely malicious. A VPN company with paying customers is less likely to be evil.
“Like so much else in computer security, VPNs are mainly about trust,“ Nick FitzGerald, ESET Senior Research Fellow, says. “The cryptographic protocols employed in VPNs mean that, by design, only two parties can decrypt the traffic traversing the VPN — the two parties at each end of the VPN connection. Hence, if you are using a VPN for privacy and/or security reasons, you must be especially sure that you can trust the VPN service provider.”
How to shop for a VPN
So what should you do when looking for a paid VPN service?
1. Look for transparency
One way to ascertain the credibility of a VPN provider is through transparency. A leadership page with real names and faces provides more trustworthiness than an anonymous company.
2. Look for logging
3. Look for open protocols
Shop for a service that supports open source protocols like OpenVPN. Open source means that anyone can audit the code, making it less likely to compromise the protocol.
4. Look for global servers
A solid VPN will have servers around the world. This increases your odds of getting reliable and fast connections.
5. Look for the ‘14 eyes’
If you’re especially paranoid, you’ll want to avoid VPNs based in the ‘14 eyes.’ These are countries that are known to spy on citizens and can force VPNs to give up private data.
The Wirecutter has an extensive review of VPN services and links to other VPN review sites. You should know that one of these, That One Privacy Site, has a different recommendation from Wirecutter’s. Wirecutter prefers IVPN and TorGuard, while That One Privacy Site gives Mullvad its first and only ‘Choice’ badge.
After trying a few services, a colleague and I have settled on AirVPN and ExpressVPN. It’s a muddled plethora of choices, which further highlights how difficult it is to choose a VPN you can trust. As in all things, I encourage you to do your homework.
Alvin Soon / Former Deputy Editor
I like coffee and cameras, but not together.