VPNs & Online Privacy

VPN History: What a VPN Really Does, and What It Can't

By Tony · FreedomTech · 11 min read · Updated June 2026

The plain-English history What a VPN can't do Proton vs Mullvad
VPN history shown as an encrypted tunnel of light running between two glowing servers on a dark screen.

The VPN history worth knowing doesn't start with a clever piece of code. It starts with a law that quietly changed what every internet provider in this country has to do with your data.

Since 13 October 2015, under the Telecommunications (Interception and Access) Act, every Australian telco and ISP has been required to keep two years of your metadata: who you contacted, when, for how long, from where, and what kind of service you used. A long list of agencies can reach into that store without a warrant. That is the default you already live under, whether you ever agreed to it or not.

A VPN is one of the few consumer tools that closes part of that window. It is also one of the most oversold products on the internet, wrapped in promises of invisibility that simply are not true. So let's do this properly. Where VPNs came from, what they genuinely protect, what they cannot, and the two we trust enough to set up for customers every week.

2 years
of your metadata kept by every Australian ISP since 13 October 2015, reachable by agencies without a warrant. Source: Department of Home Affairs, data retention obligations.

The short version

  • A VPN encrypts the link between your device and a server, hiding your browsing from your ISP and masking your location from the sites you visit.
  • It does not make you anonymous. It moves your trust from your ISP to the VPN company, so who you pick matters enormously.
  • The honest test of a VPN is independent audits, a real no-logs record, and open-source code. Free VPNs that fail this test are the product, not the customer.
  • We recommend ProtonVPN (excellent free tier) and Mullvad (paid, faster), and we set them up properly on the hardware we build.
Where It Came From

A short VPN history, from office tool to privacy staple

The technology you might use tonight to watch a show or dodge a tracking ISP was never built for any of that. It was built so people could work.

In 1996 a Microsoft engineer named Gurdeep Singh-Pall built PPTP, the Point-to-Point Tunneling Protocol, the first VPN protocol most people ever touched. The job it did was dull and important: let an employee dial into the office network from somewhere else and work as if they were sitting at their desk. No spies, no streaming, no privacy crusade. Just remote access for businesses.

That early protocol did not age well. PPTP was eventually shown to be weak, and it fell out of serious use once it became clear the encryption could be broken, a fact the Snowden files only underlined. The lesson stuck: a privacy tool is only as good as the cryptography behind it, and the only way to trust that cryptography is to let people inspect it.

The next leap came from a single nervous traveller. In 2001 a programmer called James Yonan was bouncing his work traffic through internet cafes across Russia and Central Asia, and he got spooked that someone on the wire was watching or tampering with his connection. So he wrote OpenVPN, released that May, and gave it away as open source. For nearly two decades it was the gold standard, trusted precisely because anyone could read the code and check it.

Then in 2015 Jason Donenfeld released WireGuard, a leaner and faster design that was folded into the main Linux kernel in March 2020. Less code to hide bugs in, modern cryptography, quick connections. It is now the protocol most good VPNs reach for first.

But the moment that turned VPNs from a corporate utility into something ordinary people cared about was June 2013, when Edward Snowden handed journalists proof that intelligence agencies were collecting the communications of millions of regular people at scale. Privacy stopped being abstract. A tool invented so accountants could read their email from a hotel suddenly became a tool for everyone who didn't fancy being watched by default. Today, on most estimates, around 1.6 billion people use one. That, in short, is the VPN history that matters: a corporate convenience the wider world turned into a personal defence.

The Honest Version

What a VPN does, and what it can't

Strip away the marketing and a VPN does one mechanical thing. It builds an encrypted tunnel between your device and a server run by the VPN company, then sends your traffic out from there. Your ISP can see that you are connected to that one server. It cannot see where you go after that. The websites you visit see the VPN server's address, not yours.

That is genuinely useful. It is also a long way short of disappearing.

What it does well

  • Hides which sites and services you use from your ISP and telco.
  • Masks your real IP address and rough location from the sites you load.
  • Protects you on hotel, cafe and airport Wi-Fi, where strangers share the network.
  • Lets you choose the country you appear to browse from.

What it can't do

  • Make you anonymous. You shift trust to the VPN, you do not erase yourself.
  • Help you while you are logged into Google, Facebook or your bank. They know it's you.
  • Stop cookies, browser fingerprinting or account-level tracking following you around.
  • Fix a phone that is already feeding everything to Google in the background.

A VPN is one layer of privacy, not a cloak of invisibility. Anyone who tells you a VPN makes you untraceable is selling you a feeling, not a fact.

The Real Job

So what is a VPN actually for?

Once you accept that you cannot hide or disappear behind one, the honest uses come into focus, and they are worth having. Nothing in the VPN history above changes that ceiling, but it does explain the jobs a VPN genuinely does well.

The first is closing the window your provider has on you. Australia's retention scheme stops short of forcing ISPs to log your full browsing history, but your ISP can still see where you go, build a picture of your habits, and in plenty of countries sell it. A VPN takes that view away from them. The connection metadata that does get retained at the provider level no longer maps neatly to your daily browsing.

The second is public Wi-Fi. The free network at the airport or the cafe is shared with everyone else sitting there. A VPN wraps your traffic so a stranger on the same network cannot pick through it.

The third is location flexibility, choosing where you appear to connect from, which has its uses and its limits.

What a VPN is not for is hiding serious wrongdoing from a lawful investigation. That brings us to the most useful real-world test the industry has ever had.

The Trust Question

Not all VPNs are equal, and "trusted" is just a word

$1.68M
in fines paid in September 2021 by three men, one of them the chief information officer of one of the world's most advertised VPNs, to settle US charges over hacking and surveillance work for a foreign government. Source: NBC News.

Here is the part the glossy ads skip. When you use a VPN, that company becomes your new internet provider. It can see what your ISP used to see. So the only question that matters is whether you can trust it, and a worrying number of VPNs do not deserve a scrap of it.

Take that headline figure. In September 2021 the chief information officer of ExpressVPN, one of the most heavily advertised VPNs on the planet, was named as one of three former US intelligence operatives who agreed to pay 1.68 million US dollars to settle charges over Project Raven, a hacking-for-hire operation run for the United Arab Emirates. The targets allegedly included journalists, dissidents and human rights activists. His personal share was 335,000 US dollars. The company kept him on and said its trust in him remained strong. Read that back slowly: a man who helped a government surveil its critics was running the systems at a company that sells people privacy.

It gets murkier when you look at who owns what. A lot of the so-called independent VPNs plastered across YouTube and podcasts are not independent at all. ExpressVPN, CyberGhost, Private Internet Access and ZenMate all sit under one parent, Kape Technologies. And Kape did not start out protecting anyone. It began as a company called Crossrider, whose browser-extension platform was flagged for years by security firms like Malwarebytes and Symantec for pushing adware that hijacked people's browsers, across Chrome, Firefox, Internet Explorer and even Mac. The removal tools named the detection after the company.

Kape argues outside developers misused the platform, and it rebranded in 2018 in part to bury the association. Either way, the company now selling privacy to millions made its name on software people paid others to scrub off their machines. That same parent also owns popular VPN review websites that, no surprise, tend to rank its own VPNs at the top. The illusion of choice, where a glowing five-star review can just be an advertisement wearing a lab coat.

The cleanest cautionary tale on the free side is Onavo. It was a free VPN that promised to keep your data safe, and millions installed it on that promise. It was owned by Facebook, and its real job was to watch which apps and sites you used and feed that back to Facebook. Apple pulled it from the App Store in August 2018 for breaking data-collection rules, and it was wound down the next year, but not before it had been installed on tens of millions of devices. A free VPN that harvests you is not protecting you. You are the product.

So how do you tell a real one from a betrayal in waiting? Three things, and they are not negotiable: independent audits by outside security firms, a genuine no-logs record that has been tested, and open-source code so the claims can be checked by anyone. Here are the two that pass.

ProtonVPN, tested and passed

Proton was founded by scientists who met at CERN, and it brought the peer-review instinct with it. Every Proton app is open source, so a flaw or a hidden log would be visible to anyone who looked, and plenty do. Its no-logs policy has been put through four consecutive independent audits by the security firm Securitum, in 2022, 2023, 2024 and again in August 2025, each one finding no user logging. Based in Switzerland, which has no data-logging mandate. You don't have to take their word for it, which is exactly the point. You can read the audit results yourself.

Mullvad, proven the hard way

Mullvad runs its servers from RAM, keeps no logs, and does not even ask for your name or email, just a random account number. Marketing claims are cheap, so here is the proof. On 18 April 2023 Swedish police arrived at Mullvad's Gothenburg office with a warrant, intending to seize computers holding customer data. There was nothing to take. After Mullvad showed them how the service worked, they left empty-handed. That single raid told you more than a decade of advertising.

The Mullvad raid is also a quiet lesson in limits. A VPN that keeps no logs cannot hand over what it never had, but it was never going to make a person vanish either. It does its one job, honestly.

"A VPN moves your trust. It does not erase you. Choose who you trust accordingly."
What We Set Up, And Why

The VPN we put on your phone and your computer

We don't sell VPN subscriptions, so we have no reason to push you toward one brand over another. We just set up the tools we would use ourselves. There are two.

ProtonVPN's free tier is a genuine recommendation, not a compromise. You get the same audited, no-logs protection as paying customers. The only trade-off is speed, because the free plan only puts you on a handful of distant servers, which for us in Australia usually means Japan or the USA. When your server is on the other side of the world, even a local site takes the long way around.

Picture loading a shop down the road while connected through Japan. Your request leaves your phone, goes up to your telco, flies across the ocean to the Proton server in Japan, then comes all the way back to the Australian shop's server. The page then makes the same trip in reverse, shop to Japan to your telco and finally back to you. The shop might be twenty minutes up the road, but your traffic just crossed the planet and back. Nothing breaks and nothing leaks. It is simply slower, and that is the whole price of free.

Mullvad is the paid pick. Nearby servers, faster speeds, and it runs cleanly on Linux Mint, which is why it is the one we pre-install on our crypto computers. It is our recommendation for phones and computers alike when you want speed alongside the privacy.

One last thing, and it is the thread running through all of this. A VPN works best on hardware that isn't quietly working against you. There is little point hiding your traffic from your ISP if your phone is still pouring your life into Google's servers, or your laptop is reporting home to an operating system you don't control. That is the bigger picture we cover in our guide to Big Tech, surveillance and where the real power sits. A VPN is the last layer you add, not the first. The foundation underneath it is a phone and a computer that aren't leaking in the first place, and that is exactly what we build and configure here in Australia.

We do our homework on everything we put our name to. Who owns a tool, who has been caught doing what, and whether a no-logs claim actually survives an audit. That is the difference between a recommendation and an advertisement. A VPN protects your traffic, but it cannot rescue a device that is leaking underneath it. Get the device right first, and let us do the digging.

Common Questions

VPN history and use, the questions we get asked

Does a VPN make me anonymous? +
No. A VPN hides your browsing from your ISP and masks your IP from websites, but it moves your trust to the VPN company rather than erasing you. Cookies, browser fingerprinting and any account you log into can still identify you. Treat it as one layer, not a cloak.
Is using a VPN legal in Australia? +
Yes. Using a VPN is completely legal in Australia. What you do while connected still has to be legal, the same as without one. A VPN is a privacy tool, not a free pass.
Does a VPN get me around the metadata retention law? +
Partly. Your ISP can see you are connected to one VPN server but not where you go after that, so your normal browsing is hidden from them. Your VPN provider could see it instead, which is exactly why a tested no-logs record matters. It does not override a lawful investigation of the provider itself.
Should I use a free or a paid VPN? +
ProtonVPN's free tier is genuinely fine on privacy, the only trade-off is slower speeds from distant servers. A paid option like Mullvad gives you nearby servers and faster connections. Avoid unknown free VPNs, since many fund themselves by harvesting and selling your data.
Do I still need a VPN on a deGoogled phone? +
They solve different problems and work best together. A deGoogled phone stops the device itself leaking your life to Google, while a VPN hides your traffic from your ISP and on public Wi-Fi. We set ProtonVPN up on the phones we configure.
What is the safest VPN protocol? +
WireGuard is the modern, fast default and OpenVPN is the proven older standard. Both are solid. In practice the honesty of the provider, its audits, no-logs record and open-source code, matters far more than the protocol you pick.

Privacy that starts with the hardware

A VPN is one layer. We build the foundation it sits on, deGoogled phones and Linux privacy computers, configured in Australia and ready to use out of the box.

Join the conversation

Questions, or just keen to talk privacy with like-minded Australians? Visit our Telegram community.

Join our Telegram

FreedomTech · The Privacy Experts · freedomtech.com.au