What this protects, and what it doesn't
Protects
- VPN: hides your browsing from the local network (public Wi-Fi, office, hotel) and from your ISP.
- VPN: hides your real IP address from the websites you visit.
- Tor: no single relay knows both who you are and which site you visit.
- Tor: reaches onion services, whose location and IP stay hidden and whose address verifies the destination.
- Both: can help get around network censorship.
Does not protect
- A VPN is not anonymity. Everything you send through it is visible to the VPN provider instead of your ISP.
- Neither hides you from a site you log in to. Accounts, cookies, tracking pixels and browser fingerprinting still identify you.
- "No logs" is a claim, not a guarantee. A provider can log, or be compelled to, under the laws where it operates.
- Tor does not protect against an observer who can watch both you and the destination (or your exit relay) and match the traffic timing.
- Tor does not encrypt the last hop: without HTTPS, the exit relay can see and change what you send.
Prerequisites
- A written threat model (see the start-here guide) naming who you are hiding from.
- A hardened browser, or willingness to use Tor Browser as shipped.
Step by step
-
Understand what a VPN changes
A VPN puts an encrypted tunnel between your device and a server run by the VPN provider. Your local network and your ISP see only that you connect to the VPN; websites see the VPN server's IP address instead of yours.
The trade: your traffic is now visible to the VPN provider, as EFF's Surveillance Self-Defense puts it. You have not removed a party who can watch you; you have swapped your ISP and the local network for the provider. That is only an improvement if you trust the provider more.
-
Know what a VPN does not do
- It is not anonymity. EFF says plainly that a VPN is not a tool for anonymity: the provider knows your real IP and what you connect to.
- It does not stop tracking. Cookies, pixels, browser fingerprinting, app analytics and GPS location still work over a VPN. If you log in, the site knows it is you.
- Logging policies are claims. A provider may keep logs unless its policy rules it out, and courts or agencies in its jurisdiction can request what it holds. An audit helps, but it is a snapshot.
- It moves risk, it does not remove it. A malicious or breached provider sees as much as your ISP did.
-
Understand how Tor works
Tor sends your traffic along a random path through volunteer-run relays, three by default. Each relay knows only the one before and the one after it, and the encryption keys are set up separately for each hop. The first relay knows your IP but not your destination; the last (exit) relay knows the destination but not who you are.
Onion services (addresses ending in
.onion) are reachable only through Tor. The service's location and IP stay hidden, the connection is end-to-end encrypted, and the address is generated automatically and verifies that you reached the right destination.The simplest correct way to use Tor for browsing is Tor Browser, downloaded from the Tor Project's own site.
-
Know Tor's limits
- The exit relay sees unencrypted traffic. Tor encrypts inside the network, not from the exit to the website. Use HTTPS-only sites (on desktop, Tor Browser has turned on HTTPS-Only Mode by default since version 11.5) or onion services.
- Timing correlation. The Tor Project says it does not protect against an observer who can see both you and the destination or your exit relay.
- It can be slower, because traffic is routed through volunteer relays around the world.
- Sites challenge it. Many people share the same exit relays, so some sites show CAPTCHAs or warnings about unusual activity.
- Your behaviour links your identity. Logging in to your usual accounts, reusing a username, or running other apps over the same circuit ties Tor activity back to you. The Tor Project warns that circuit reuse can associate anonymous and non-anonymous traffic at an exit.
-
Threat: untrusted public Wi-Fi
On café, hotel or airport Wi-Fi, the risk is the local network operator and other users on it. HTTPS already protects page contents; what leaks is which sites you visit (DNS and connection metadata).
Choose: a VPN you trust, or Tor Browser for the session, or your phone's mobile data. A VPN is usually the most convenient here, because it covers every app, not just the browser.
-
Threat: a hostile ISP or state
If your ISP sells browsing data, or the state monitors or censors the network, a VPN hides your destinations from them but puts one company in the same position, and that company may be reachable by the same state.
Choose: Tor Browser when you need no single party to see both you and your destination. If Tor itself is blocked, the Tor Project offers bridges and other anti-censorship options. At High threat level, use an amnesic system such as Tails, which routes everything through Tor and leaves no trace on the computer.
-
Threat: hiding from the website itself
If the adversary is the site (an advertiser, a forum operator, a company you are researching), your IP is only one clue. Cookies, fingerprinting and anything you log in with matter more.
Choose: Tor Browser, which is designed to make its users' browser fingerprints as similar as possible, and never log in to an account tied to your real identity in the same session. A VPN plus a hardened browser hides your IP but leaves the rest; it is enough for casual tracking, not for a determined site.
-
If you choose a VPN, judge the provider, not the advert
This guide does not rank providers. Check, from the provider's own documents: who owns it and in which country, what its privacy policy says it logs, whether an independent audit was published, how you can pay, and whether it shows you its kill-switch and DNS settings. EFF's VPN module lists the same questions. Avoid free VPNs whose business model you cannot explain.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Buying a VPN for "anonymity" and then logging in to the same accounts as always.
- Trusting a "no logs" marketing line as if it were a guarantee.
- Using Tor and then typing passwords on HTTP sites, which the exit relay can read.
- Running Tor and normal browsing side by side in a way that links the two (same accounts, same usernames).
- Installing a browser extension or a "Tor" app from an unofficial store instead of Tor Browser from torproject.org.
Going further
Read the Tor Project's support pages before relying on it for anything serious, and pair either tool with browser hardening. For the highest threat level, use Tails. If a VPN is mandated at work, remember your employer's VPN sees your traffic on that device the same way a commercial provider would.