Tor vs VPN: Which One You Really Need?
Tor and VPN no dey solve the same problem. See who fit see your IP and destination at every hop, plus why VPS rented in your name no be anonymity.
Tor vs VPN: which one you really need
Tor and VPN both dey send your traffic through machines wey no be your own, but dem dey answer different questions. VPN (virtual private network) dey move the trust from your internet provider go one company. That company go see your real address and every destination wey you visit. Tor dey spread that trust across three relays wey different people run. So, no single relay go know both who you be and where you dey go. Choose based on the party wey you dey hide from.
If na the network wey you dey use, VPN na the correct tool. If na the website itself, or anybody wey fit force one company to provide its records, Tor na the correct tool. The rest of this guide explain the details behind those two sentences.
Follow one request through both designs
Make we follow one normal request: your browser open https://news.example.com. TLS (transport layer security) protect the page content for both designs, so nobody wey dey for middle fit read the article. The important part na the metadata: who learn your IP address, who learn the destination, and who fit join both facts together. Privacy tool na machine wey dey separate those two facts. VPN move both facts go another holder. Tor split dem.
Wetin each side fit see when you use VPN
Your client go encrypt every packet and send am go one endpoint. From that endpoint onward, na ordinary traffic again.
- Your ISP (internet service provider) go see encrypted packets between your line and one VPN server address. E go see volume and timing. E no go see the destination hostname, as long as DNS (domain name system) queries sef dey pass through the tunnel.
- The VPN operator go see your real IP address for one side and every destination address for the other side, together with times and sizes. Both halves of the pair go land for the same machine.
- The destination go see the VPN exit address, plus every identifying detail wey your browser send.
So, VPN no create anonymity. E move the observer from your ISP go your VPN provider. This na real benefit when na the local network be the problem, or when your ISP dey filter or resell wetin e see. But e no give any benefit against the site wey you dey visit, because your traffic still dey arrive as one stream from one company wey know exactly who you be and keep your payment record.
The "no logs" claim na the whole product, and na the one part wey you no fit check from your side. You fit verify say the tunnel dey up. You fit verify say DNS no dey leak. But you no fit verify wetin the operator dey write to disk. Na this trade you accept: one company, wey you choose, dey hold the complete picture.
Check the leak wey fit quietly cancel the tunnel:
resolvectl status
curl -s https://ifconfig.me; echoThe address wey ifconfig.me print suppose be the VPN exit. The DNS servers listed for the link wey dey carry your default route suppose be the tunnel's resolver. If dem still list your local router for 192.168.1.1, your name lookups dey leave through the local link as cleartext, because the route go that router dey on-link and e more specific than the tunnel's default route. Your traffic private, but your list of sites no be private. DNS queries wey dey escape from WireGuard tunnel explain the fix step by step.
Wetin each party fit see when you use Tor
Tor dey build circuit of three relays wey e choose from signed list, the consensus, wey small set of directory authorities publish. Your client dey wrap the data inside layers, one layer for each relay. Each relay dey remove one layer, learn only the next hop, then pass the rest go front. Na these layers make nobody for the path hold both facts.
- Your ISP dey see encrypted traffic go one guard relay. Relay addresses dey public, so your ISP fit know say you dey use Tor. E no fit know wetin you reach.
- The guard relay dey see your real IP address. E no fit see the destination, because the part of the message wey name the site still dey encrypted for the relays after am.
- The middle relay dey see guard for one side and exit for the other. E no see you or the destination. E dey there so the guard and exit no go talk directly.
- The exit relay dey see the destination and the traffic as e dey leave the network. E dey see the middle relay address, no be your own. With HTTPS, e learn the hostname and connection metadata, but no be the page.
- The destination dey see the exit relay address, wey dey public exit lists, plus anything wey your browser hand over.
To link you with the site, person need the guard and exit at the same time. Na the whole design be this for one sentence. Na why your client dey keep the same guard for months instead of picking fresh one every time e start: if e dey rotate the entry constantly, hostile relay go get repeated chances to become your guard.
Circuits no dey permanent. New connections dey move go fresh circuit roughly every ten minutes, while stream wey don already open dey remain for the circuit wey e start with. Long download and tab wey you open fifteen minutes later normally dey leave from different exits.
How the three hops dey build without any relay learning about the others
The client no dey hand the relay list give the guard. E first negotiate keys with the guard, then send request through the guard to ask am extend the circuit go the middle relay. After that, e send another request through that hop to extend go the exit. Each relay dey hear only about the neighbour wey e must talk to next, and each hop get im own key wey the other hops no ever see. Na why the middle relay no fit learn the exit role by inspection, and why relay wey dey log everything e handle still dey log only one fragment.
Install am and prove the path:
sudo apt update && sudo apt install -y tor
systemctl status tor@default
journalctl -u tor@default -n 20
curl --socks5-hostname 127.0.0.1:9050 https://check.torproject.org/api/ipThe log suppose reach Bootstrapped 100% (done): Done. The curl suppose print {"IsTor":true,"IP":"..."} with address wey you no recognise, and na your current exit be that. If IsTor na false, the request never pass through the proxy. Ubuntu packaged Tor fit dey behind the current release; Tor Project dey publish im own apt repository if you need follow upstream.
One trap dey inside that command. --socks5 dey make curl resolve the hostname by itself, then send the resulting address through the proxy, so your normal resolver go learn every name wey you visit. --socks5-hostname dey send the name go Tor and allow the exit resolve am. Same tunnel, but the leak completely different. Tor Browser and torsocks dey handle this correctly. Tools wey you configure by hand often no dey.
Tor dey carry TCP streams only. E no fit carry UDP, so ping 1.1.1.1 never dey pass through am, and VPN protocol wey dey use UDP no fit run inside am. Any program wey ignore im proxy setting simply dey use your normal route with your normal address, and nothing go warn you. Na why system-wide Tor dey done with transparent proxy for separate box instead of environment variable.
Wetin the trust really dey go
VPN dey put plenty trust for one place. One company hold your identity, your billing record, and your complete traffic pattern. Your protection depend on its promise say e no go keep the logs. As long as that promise hold, the design clean, fast, and easy to understand. If the promise fail through subpoena, breach, or lie, everything fail at once for all your traffic.
Tor dey spread trust. Three parties wey mostly no know each other hold one fragment each. One fragment by itself no get much value. The design no require everybody to be honest. But enough of dem must dey independent. You pay for this with slower speed, TCP only, and a network where some relays surely dey run by people wey wan monitor you. Tor answer to hostile relay be say one relay no ever enough.
When VPN be the correct tool
- You no trust the local network: hotel, airport, conference hall, or landlord router. The operator go see encrypted tunnel and nothing more.
- You wan reach your own machines, or connect from a fixed address wey you control.
- You need speed and UDP: video calls, games, large transfers, and backups.
- You wan stable address wey websites no go challenge. Tor exits dey blocked or dem dey trigger CAPTCHA for plenty parts of the web.
This list na the reason to run your own VPN for a VPS instead of buying subscription, and a WireGuard server wey you set up yourself gives you a tunnel whose logging policy dey inside config file wey you own. If you want the same tunnel with device-to-device key management on top, the difference between plain WireGuard and Tailscale na the comparison wey you need read. Once you dey on a tailnet, reaching your own services and publishing one of dem to the open internet na separate decisions, and serve keeps service private to the tailnet while funnel exposes am. Each one of dem dey very good for the work wey this list describe. None of dem fit do the work for the next one.
Tor na the right tool when
- Your adversary include the destination site, or anybody wey fit demand records from one company.
- You dey read or publish something wey fit harm you if dem trace am back to your line.
- You want an onion service: traffic wey never comot from the network, no exit relay involved, and a server wey address remain hidden.
- You fit manage slow pages, CAPTCHAs and the occasional
403 Forbidden.
If the server side of that third point interest you, how to run a v3 onion service on a VPS show how person fit reach a site with no exit relay for the path, and which normal leaks still fit connect the machine to its public address.
Use Tor Browser, no be your everyday browser wey you point to port 9050. The browser na half of the protection, and the section after the next one explain why.
Why VPS wey you rent worse pass commercial VPN for anonymity
Na this point people dey often mix up. VPS wey you rent na lease wey your name dey on top. Signup email, card, invoices, and support tickets all dey inside one company database beside that IP address. Nobody need break anything before dem connect the address to you. Dem don already write am down, keep am for normal accounting reasons, and anybody wey fit ask provider question with legal backing fit access am.
The second problem na the crowd. Commercial VPN exit address dey shared by plenty customers at the same time, so that address alone no point to one person. Your VPS address na only your own. Every request wey comot from there na you, today and next month. The address no dey rotate, so destination fit build profile about you across months without any cookies.
None of this mean say self-hosted VPN bad. E good well-well to encrypt your traffic for network wey you no control, and to reach your own services from anywhere. E simply no be anonymity tool, and na the mistake be to use am like one. If you want plain explanation of wetin your provider fit and no fit see for the machine itself, read how safe VPS hosting really be.
Wetin neither Tor nor VPN fit fix
- Browser fingerprinting. Your user agent, screen size, timezone, installed fonts, language, and canvas rendering dey combine into value wey often unique, and e dey follow you across every IP address wey you use. Tor Browser dey fight this by making all im users look the same to each other and by resizing the window with fixed steps. Your normal browser behind SOCKS proxy still keep im fingerprint and cookies.
- Logging in. Once you sign in to account wey know your name, network layer no matter again. One login from home and another one through Tor to the same account go tie both sessions together.
- Anything wey the endpoint record anyway: wetin you type, wetin you buy, and wetin you search for.
- End-to-end correlation. Person wey dey watch your line and the exit at the same time fit align timing and packet volume, then match both ends. Tor talk am clearly say e no protect against adversary wey fit see both sides.
You fit use Tor and VPN together?
Tor over VPN mean say VPN go connect first, then Tor go run inside am. Your ISP go see only the VPN, and the guard relay go see the VPN address instead of your own. But you don put company wey hold your name and card in front of system wey design to avoid exactly that. E fit make sense for one situation: when using Tor for your network line dangerous and you no get better option.
VPN over Tor, where traffic commot from Tor network then enter VPN account, harder to set up and usually worse. That account get your payment record attached, so you don tie stable identity to traffic wey anonymous just one moment before.
If your goal na only to hide Tor use from your ISP, the supported answer na bridge: entry point wey no dey inside public consensus, together with pluggable transport like obfs4 or Snowflake wey make the traffic hard to classify. Tor Browser come with both, and no third company need your name.
FAQ
Tor na just free VPN?
No. VPN dey send your traffic through one server wey one company run, and the company fit see your real address and every destination. So e dey replace your ISP with provider wey you choose. Tor dey send am through three relays wey different people run. The guard relay see you but e no see the site, while the exit relay see the site but e no see you. Tor dey use TCP only, e slower well-well, and plenty websites dey block am or challenge am. So e no be direct replacement for VPN everyday use.
ISP fit know say I dey use Tor?
By default, yes. Relay addresses dey published for the public consensus, so your provider fit see say you dey connect to known guard relay. E no fit see which sites you reach. To hide the use itself, Tor Browser get bridges with pluggable transport like obfs4 or Snowflake. Dem dey connect through entry point wey no dey the public list. VPN wey dey before Tor also hide am from your ISP, but e give that same information to the VPN operator instead.
If I run VPN for my own VPS, e go make me anonymous?
No. You rent the server with your name and card, so the provider billing records already link that address to you. Request to the provider alone fit make dem show those records. Na only you dey use the address, so everything wey leave am belong to one person and fit remain linkable as long as you keep the server. Self-hosted VPN strong as privacy tool against local network, but e weak as anonymity tool against anybody wey fit question your provider.
Why websites dey block me or show CAPTCHAs when I use Tor?
Because exit relay addresses dey public and plenty people dey share dem. Abuse from any of those users go attach to the address wey you dey borrow. Content delivery networks dey give those addresses bad score and answer with challenge, a 403 Forbidden, or signup form wey no gree submit. Nothing for your side fit remove this. New circuit go give you different exit, and sometimes that one get better reputation.
If I use VPN, DNS queries still fit leak?
E fit, and e common. With full tunnel and no resolver set for the tunnel interface, your client go continue use resolver wey e learn from local network. Route to that resolver dey on-link, so e go beat tunnel default route. Your queries go then leave as cleartext while everything else dey encrypted. Run resolvectl status and confirm say the DNS server listed for the link wey carry your default route na the tunnel resolver, no be your local router.