Skip to main content
Back to blog

VPN vs Tor: Moving Your Trust or Splitting It Three Ways

Privacy

VPN vs Tor: Moving Your Trust or Splitting It Three Ways article illustration

Ask which is more private, a VPN or Tor, and the answer tends to arrive shaped like a league table, with one of them a grade above the other. It is the wrong shape. The two were built on opposite assumptions about who you are hiding from, and once you name that party the choice mostly makes itself.

The definitions are not describing the same product

Start with what a VPN is supposed to be according to the people who standardised the vocabulary, rather than the people selling it.

RFC 4949, the IETF’s Internet Security Glossary, published in 2007, defines a virtual private network as a restricted-use logical network constructed from the resources of a relatively public physical one, often by using encryption and often by tunnelling links of the virtual network across the real network. The worked example it offers is a corporation whose offices each sit behind a firewall, where “the corporation could create a VPN by using encrypted tunnels to connect from firewall to firewall across the Internet”. Keeping the network in between from reading your traffic is the whole of it. Anonymity from the far end does not appear anywhere in the entry.

Tor was designed around the thing the glossary leaves out. The Tor Project’s own account of what the network provides puts the mechanism plainly. It “routes your connection through more than one Tor relay so no single relay can learn what you’re up to”, and the reason that helps is stated just as directly: “Because these relays are run by different individuals or organizations, distributing trust provides more security than the old one hop proxy approach.”

Read those two descriptions next to each other and the gap is not one of degree. One is a private link across a public network. The other is an arrangement for making sure nobody in the chain holds the whole story.

A VPN moves your trust. Tor divides it.

With a VPN, one company takes the seat your internet provider was sitting in. They carry everything that leaves your device, they know the real address it came from, and they know every destination you asked for. That is the same pair of facts your provider had. You have not removed that capability, you have handed it to somebody else, and the question that follows is whether the new holder is better placed than the old one.

Often they are. Swapping a café network, a hotel or a landlord’s shared line for a company that has published a policy and can be held to it is a real improvement. Sometimes they are not, and working out which you have is harder than reading a marketing page, which is the subject of what a no-logs policy actually means.

With Tor, no single participant is given both halves. Your traffic passes through a chain of relays, a guard, a middle and an exit. The guard knows your real address and not your destination. The exit knows the destination and not you. The middle knows neither. Nobody in that chain has to be trustworthy on their own, because the design assumes some of them will not be, and Tor Browser explained walks through what each relay sees, along with why Tor covers only what goes through that browser while a VPN covers the device.

That is the distinction underneath everything else. A VPN concentrates the knowledge in one place you have chosen. Tor scatters it so that no one place holds enough to matter.

The question that decides it is whether anyone can see both ends

Here is where the marketing on both sides goes quiet, and where Tor’s own documentation is unusually blunt.

The original Tor design paper, published by Roger Dingledine, Nick Mathewson and Paul Syverson at USENIX Security in 2004, opens its threat model by conceding the strongest attacker straight away. “A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary.” It records the consequence among its explicit non-goals too: “Tor does not claim to completely solve end-to-end timing or intersection attacks.”

The Tor Project still says the same thing today, in its support article on the attacks that remain: “It is possible for an observer who can view both you and either the destination website or your Tor exit node to correlate timings of your traffic as it enters the Tor network and also as it exits. Tor does not defend against such a threat model.”

So the adversary Tor is built for is one who sees a part of the network rather than all of it. The adversary a VPN is built for is narrower still: the single network you happen to be sitting on. Against somebody positioned at both ends of your connection, neither tool is doing the job you would want it to, and for a VPN that is not even a limitation so much as a description, since the operator is by construction a single party holding both halves.

Neither of them hides the fact that you are using it

This one catches people out because it sounds like a failure and is a stated design decision.

The Tor design paper lists it among the non-goals in as many words: “Not steganographic: Tor does not try to conceal who is connected to the network.” Exit addresses are openly published, and the captchas and locked accounts that follow from that are set out in what Tor hides and what it does not.

A VPN is in the same position for a different reason. Your provider still carries every packet, each one still needs an outer address, and the traffic going to that address has a recognisable shape. Can your ISP tell you are using a VPN sets out what each protocol gives away and how much the observation is worth to them.

If being seen to use the tool is itself the risk you are managing, that is a separate problem with separate answers, and choosing between these two does not solve it.

Why running both is not the safe default

The obvious move, when two tools each cover a gap in the other, is to stack them. The Tor Project’s own position on that is cautious: “Generally speaking, we don’t recommend using a VPN with Tor unless you’re an advanced user who knows how to configure both in a way that doesn’t compromise your privacy.”

That caution sits well with how Tor’s protection works, even though the advice itself gives no reason. Anonymity there comes from resembling everyone else using it, which is why the same project tells you not to install extensions or resize the window. A setup almost nobody else runs cuts against that, and a second moving part is a second thing that can fail quietly while the interface still looks correct.

A related hazard applies whether or not a VPN is involved. Because Tor reuses circuits across connections, traffic you have signed into can be associated with traffic you have not, which is why the Tor Project tells you to “be careful about what applications you run concurrently over Tor”. Being yourself in one tab does not stay in that tab.

Working out which one you need

Name the party you are hiding from first, then pick. Doing it the other way round is how people end up protected from somebody who was never watching.

If it is the network you are sitting on, a VPN is proportionate and Tor is more than the situation asks for. Public WiFi, a shared office line, a landlord’s router: in each of those an untrusted network in the middle is the entire problem, which is the problem the glossary definition addresses. Confirm the tunnel is carrying your traffic before you rely on it, because one that is not protects nobody. Compare what your connection reports before and after connecting with the VPN check.

If it is the site at the far end, or anyone who could compel a single company, a VPN cannot help in the way you need, because it is still one company holding both facts. Dividing trust between parties who do not know each other is the thing a single provider cannot offer, whatever it charges. The nearest thing to an exception is a provider’s own two-server mode, and whether a second hop divides anything turns on who owns the second one.

If it is somebody who can watch both ends, neither tool claims to save you, and the honest response is to change what you are doing rather than which tunnel you do it through.

One check applies either way. Both leave a visible mark on the address you present, so look at how that address reads before you depend on it. How your connection looks to fraud detection reports whether an address is flagged as a VPN, a proxy, a datacentre range or a Tor exit, which is a fair preview of why a bank or a streaming service might treat you differently once you connect.

So the comparison is worth making once, and then setting down. A VPN buys you a single point of trust you chose rather than inherited. Tor buys you a design in which no single point holds enough to matter. Those answer different questions, and the useful work is working out which question you were asking.