Why a Commercial VPN Is Not Enough Against a State Adversary
If your adversary is a government with real technical capability and legal authority over infrastructure, a consumer VPN subscription is not adequate protection and should not be treated as part of a plan. The reasons are structural rather than a matter of choosing a better provider: a single company sits at the join of your traffic, is subject to law somewhere, and cannot protect you from an adversary that watches both ends of your connection or reaches your device directly.
This post is written for people who might be in that position — journalists, activists, people organising under repressive conditions, people whose safety depends on getting this right — and for the much larger group who are not, but who deserve to know where the line is.
The three structural limits
Traffic correlation. An adversary that can observe network traffic in more than one place does not need to break the encryption. It can compare the timing and volume of what enters the tunnel near you with what leaves the VPN server elsewhere, and match them. This is a well-established analytical technique, it scales, and a VPN’s single hop does very little against it. Providers cannot fix this with better cryptography, because the leak is in the shape of the traffic rather than its contents.
Compulsion of the provider. Every provider is incorporated somewhere and operates servers somewhere, and both create legal exposure. A provider can be ordered to begin retaining data about a specific user, and can be barred from disclosing that it was ordered. A no-logs policy describes what a company chooses to do today; it is not a technical barrier against being told to do something else tomorrow. That is the point of what a no-logs claim is worth, and it matters far more here than for ordinary users.
Your device. A well-resourced adversary attacks the endpoint, because it is easier than attacking the network. Targeted malware delivered by message, exploit of unpatched software, or physical access at a checkpoint all defeat a tunnel completely — the traffic is decrypted at the endpoint by definition, as device-side threats explains.
Any one of these is sufficient. Together they mean the security of your situation does not rest on which subscription you bought.
Additional exposures specific to this threat model
Using a VPN is itself observable. Connections to known endpoints are identifiable, and in some jurisdictions unusual traffic patterns attract attention or are restricted outright. In a place where privacy tooling is treated as suspicious, the tool can increase the attention on you rather than reduce it.
Account and payment records exist. Somebody paid for the subscription with something, and support tickets, email addresses, and billing details are records that connect a person to an account.
Server locations are under local law. A provider registered in one country routinely operates hardware in many others, each with its own legal environment and its own physical-access risks. See what infrastructure claims really mean for how much of this is architectural and how much is assertion.
Ownership is not always transparent. Structurally, a provider’s corporate control can change, and consumer-facing brands are not always independent of one another. For an ordinary user this is a minor consideration; for someone in genuine danger, relying on a company whose ownership you cannot verify is a poor foundation.
What actually helps
Get advice from people who do this professionally. The most important step is not a purchase. Organisations exist specifically to support journalists, activists, and at-risk communities with digital safety: press freedom organisations, digital rights groups, legal aid and human rights organisations, and the security teams that support newsrooms and NGOs. They provide situation-specific guidance, which is the only kind worth having here. General web writing — including this site — cannot substitute for it, because the correct answer depends on your jurisdiction, your adversary, and your circumstances.
Prefer tooling designed for anonymity over tooling designed for convenience. Systems built so that no single operator sees both ends of your connection exist, are maintained by dedicated projects, and are documented by the digital rights community. They have their own limits and their own operational requirements, and they should be adopted with guidance rather than from a blog post.
Treat device security as the priority. Patching promptly, minimising installed software, using platform lockdown modes where offered, and having a plan for physical seizure will matter more than any network measure.
Compartmentalise. Separate devices, accounts, and identities for separate activities limits what any single compromise reveals. This is operational practice rather than a product, and it is where most real protection comes from.
Plan for coercion and for the moments when tooling is unavailable — at a border, at a checkpoint, when a network is shut down. Organisations that specialise in this have concrete protocols.
What a VPN is still good for
None of this makes VPNs useless. They are a reasonable tool for a specific, ordinary job: hiding your destinations from an untrusted local network or your internet provider, as what a VPN protects against sets out. Most people’s threat model is exactly that, and for them a VPN is a proportionate purchase.
The failure is one of framing. An industry that advertises to everyone using the vocabulary of high-risk work — anonymity, invisibility, freedom — sells a consumer product into situations it cannot support. The result is that the people with the most to lose are the most likely to be misled about what they have bought.
If you are in that group: please get advice specific to your situation before you rely on anything, and do not let a subscription stand in for a plan. If you are not, build a threat model and buy for the threat you actually have.