~4m8:40
Station One

A VPN With No Logs Still Gives Away Your Browsing History

Sep 22, 2026

Read: ~4m · You save: 5 min

A VPN With No Logs Still Gives Away Your Browsing History

Think your VPN keeps you private? Think again. Discover how traffic analysis can reveal your browsing history, even with no-log policies. What are the real risks?

Millions of Americans have followed official advice from the Department of Defense, the FBI, the Federal Trade Commission, and the National Security Agency (NSA) to protect their online privacy by using a Virtual Private Network (VPN). This advice, often summarized as "Use a VPN," has led consumers to spend billions of dollars annually on these services. However, a recent memo from Congress's research staff, highlighted in a letter from Senator Ron Wyden to the NSA director on September 2nd, reveals that even encrypted VPN traffic can inadvertently disclose a user's browsing history.

The core issue lies not in breaking encryption, but in analyzing traffic patterns. This method, known as traffic analysis, can reveal the origin, destination, timing, and volume of data packets. By correlating these elements, a user's browsing history, including the specific websites visited and the times of access, can be reconstructed and linked to their identity. This technique was reportedly solved by a lab for American intelligence officers as early as 1995.

How VPNs Function and Their Limitations

When a VPN is activated, all internet traffic is first routed through a company's server before reaching its intended destination. This process masks the user's actual IP address, replacing it with the VPN server's address. This is particularly effective on public Wi-Fi networks, preventing individuals on the same network from intercepting sensitive data like passwords.

However, the VPN company itself then holds the record of the user's internet activity. While some VPN providers, like the Swedish company Mulvad, reportedly store no customer data—as evidenced by a 2024 search by Swedish police that yielded no customer information—the fundamental vulnerability of traffic analysis remains.

The process can be visualized as two data streams: one from the user's device to the VPN server, and another from the VPN server to the target website. Both streams carry encrypted traffic, meaning the content is unreadable to anyone intercepting them. However, the timing and size of data bursts transmitted across both streams can be recorded. A data burst leaving the user's device and a subsequent burst of the same size leaving the VPN server heading to a website can be matched, thereby linking the user's device to that specific website. This matching process, performed over an extended period, can reconstruct a user's browsing history without ever decrypting the traffic.

The memo suggests that a VPN relying on a single server offers minimal protection against entities capable of subpoenaing the VPN company or breaching its systems. Even with sealed messages, the record of which sites were accessed and when remains visible to anyone monitoring both data streams. This information can be critical for various individuals, from reporters identifying sources to defense contractors tracking project access, or even for individuals reviewing their own late-night searches.

The "Harvest Now, Decrypt Later" Threat

A significant concern highlighted by the memo is the "harvest now, decrypt later" strategy employed by adversaries. This involves recording encrypted traffic with the expectation that future advancements in computing power will eventually allow for decryption. Consequently, data captured today could compromise privacy for years to come.

The potential for adversaries to record traffic is amplified by the presence of foreign intelligence services within telecommunications networks. In September 2025, the NSA and allied agencies issued a warning about Chinese state operators infiltrating backbone routers of major carriers, the infrastructure responsible for inter-network traffic. This indicates that the means to intercept traffic at a large scale already exist.

VPNs and Warrantless Surveillance

Adding another layer of concern, six members of Congress, including Senator Wyden, wrote to the Director of National Intelligence in March regarding the implications of VPN use for protection against warrantless surveillance by the U.S. government. The NSA's declassified targeting rules presume individuals whose location is unknown to be non-U.S. persons, whose traffic can be collected in bulk without a warrant. Since a primary function of a VPN is to obscure a user's location, the members questioned whether following government advice to use a VPN could inadvertently strip Americans of their protection against warrantless surveillance by their own government.

The response received in July stated that VPNs are useful for "basic hygiene" but cautioned that VPN companies can log browsing activity. Senator Wyden's recent letter argues that this response addressed the company's logging practices but overlooked the vulnerability of the data streams themselves.

Onion Routing and Tor

The solution to traffic analysis was developed in 1995 by three researchers at the Naval Research Laboratory. Their goal was to enable U.S. intelligence officers to use the internet from hostile environments without their traffic identifying them. While encryption secured the content, the traffic patterns remained a giveaway. Their solution, termed "onion routing," involved routing traffic through multiple relays, with each relay only knowing the preceding and succeeding hop. This layered approach ensured that no single point in the path simultaneously held both the user's identity and their destination.

To prevent the network from being exclusively used by spies, the technology was made public, leading to the creation of Tor (The Onion Router). The intention was for intelligence traffic to be indistinguishable within the broader public internet traffic. Despite the development of this solution 31 years ago by the Navy's own lab, the NSA continues to recommend VPNs that rely on a single server.

The Silent Failure of VPNs

Unlike other safety products that provide observable indicators of function or failure (e.g., squealing brakes, functioning locks, or smoke alarms), VPNs can fail silently. The vulnerabilities lie in the unseen data streams. The entities best positioned to verify the effectiveness of these VPNs are the same agencies now being asked to provide written assurances.

A VPN subscription offers certain benefits: websites log a rented IP address instead of the user's, and on public Wi-Fi, the encryption of content provides a layer of security. The user's internet provider also loses the record of visited sites.

However, the subscription does not guarantee complete privacy. The list of visited sites is transferred to the VPN company, making it vulnerable to subpoenas or breaches. The timing and volume of traffic remain visible to anyone monitoring the data streams, allowing for the reconstruction of browsing history. Furthermore, the "harvest now, decrypt later" threat means that current data could be compromised in the future.

The question of whether using a VPN to mask location qualifies an individual as "foreign" under NSA rules, potentially subjecting them to warrantless surveillance, remains unanswered.

Alternative Solutions

For users concerned about traffic pattern concealment, alternative solutions exist. Tor offers a free, multi-hop routing system. Apple's Private Relay, included with iCloud, provides privacy for Safari browsing. Some paid services route traffic through two of their own servers instead of one.

Senator Wyden has given the NSA until October 14th to publicly answer three questions regarding VPN effectiveness. The outcome of this inquiry could lead to a revision of advice from four government agencies or, if the answers remain classified, leave the public without definitive information on the security of their VPN usage.

The Government's VPN Advice and Its Limitations

Government agencies like the DoD, FBI, FTC, and NSA advised Americans to use VPNs for online protection. Senator Ron Wyden questioned this advice, highlighting a memo that reveals how traffic metadata (origin, destination, time, size) can still reveal browsing history without breaking encryption. This traffic analysis technique was known as early as 1995.

  • US government agencies (DoD, FBI, FTC, NSA) recommended using VPNs for online protection.
  • Senator Ron Wyden raised concerns about the adequacy of VPNs.
  • A memo revealed that traffic metadata (origin, destination, time, size) can expose browsing history.
  • Traffic analysis, a method to reconstruct browsing history, was understood by 1995.

How VPNs Work and the Role of the VPN Provider

Using a VPN routes all traffic through a company's server, which logs the user's address. While this protects against local network snooping (e.g., on public Wi-Fi), the VPN company itself now holds the browsing data. Companies like Mulvad, searched by Swedish police in 2024, reportedly had no customer data to seize due to their no-log policy.

  • VPNs route traffic through a company server, masking the user's IP address from websites.
  • This provides protection against local network threats on public Wi-Fi.
  • The VPN company becomes the holder of the user's browsing data.
  • Mulvad, a VPN provider, reportedly had no customer data seized during a 2024 police search.

Traffic Analysis and Future Decryption Threats

Traffic analysis uses the size and timing of data packets to link a user's device to visited websites, even if the traffic is encrypted. This 'harvest now, decrypt later' strategy allows adversaries to store traffic data and decrypt it in the future. The NSA and allies warned in 2025 about Chinese state operators compromising backbone routers, creating a vulnerability.

  • Traffic analysis can reconstruct browsing history by matching packet size and timing between user and server.
  • The 'harvest now, decrypt later' strategy involves storing encrypted traffic for future decryption.
  • In 2025, the NSA warned of Chinese state operators compromising telecommunications backbone routers.

VPNs and Warrantless Surveillance Concerns

Concerns are raised about whether using a VPN could compromise Americans' protection against warrantless surveillance. The NSA's rules presume individuals with unknown locations are non-US persons, allowing bulk traffic collection without a warrant. Congress questioned if VPN use, which aims to obscure location, could inadvertently subject users to this surveillance.

  • A key concern is whether VPN use affects protection against warrantless surveillance.
  • NSA rules may classify individuals with unknown locations as non-US persons, subject to bulk data collection.
  • VPNs aim to obscure user location, potentially triggering these surveillance rules.
  • Congress is seeking clarification on whether VPN use impacts Fourth Amendment protections.

The Origins of Onion Routing and Tor

The original solution to traffic analysis was 'onion routing,' developed in 1995 by the Naval Research Laboratory to protect intelligence officers. This method uses multiple relays, so no single point knows both the origin and destination. The Tor network, made public to anonymize intelligence traffic within general traffic, is an example.

  • Onion routing, developed in 1995, was designed to prevent traffic analysis.
  • It works by routing traffic through multiple relays, obscuring the end-to-end path.
  • The Tor network is a public implementation of onion routing.
  • Making Tor public aimed to hide intelligence traffic among general internet traffic.

Current Recommendations vs. Advanced Solutions

Despite the existence of solutions like Tor, the NSA continues to recommend single-server VPNs. While VPNs offer benefits on hostile Wi-Fi by masking IP addresses, they fail silently against traffic analysis. Senator Wyden has given the NSA until October 14th to publicly answer questions about VPN effectiveness.

  • The NSA still recommends single-server VPNs, despite known traffic analysis vulnerabilities.
  • VPNs are effective for masking IP addresses on public Wi-Fi.
  • The failure of VPNs against traffic analysis is silent and undetectable by the user.
  • Senator Wyden has set an October 14th deadline for the NSA to respond to questions about VPNs.