SECURE BROWSING CyberArtical Editorial Team

VPNs, Tor and what the published guidance actually covers

Hands holding a tablet showing a VPN app's connect screen with a cloud icon

Comparisons of VPNs and Tor tend to be scored on a single axis: which one makes you more anonymous. That framing does not survive contact with the source material. NCSC publishes guidance on VPNs, and it is about protecting "data in transit" across untrusted networks — not anonymity. The agencies in this article’s sources publish no consumer guidance on Tor at all. Where this piece describes how Tor works, treat that as general explanation rather than sourced recommendation; it is flagged where it happens.

Before the comparison, the ground rules

  • NCSC scopes a VPN to secure connectivity between separate locations and the security of "data in transit" across an untrusted network.
  • NCSC: "only traffic which is routed over the VPN will be protected by it."
  • NCSC recommends a standard, not a product — "Our recommendation is that IPsec be used for VPN access" — and its guidance contains no endorsement of commercial consumer VPN services.
  • NCSC warns a third-party VPN client raises the risk that "some data may be sent outside the VPN" through poor operating-system integration.
  • Not sourced: no FTC, CISA, NCSC or FBI page in this article’s source set gives consumer guidance on Tor. Its description below is general explanation.

The honest short answer

If your goal is to keep the operator of an untrusted network from seeing which sites you use, or to reach a private network from elsewhere, a VPN is the tool with actual guidance behind it — and NCSC’s guidance describes a protocol and a deployment model, not a subscription.

If your goal is anonymity in a strong sense, neither is a solution you should reach for casually, and the reason is the same for both: the moment you sign into an account, the service knows who you are. Routing changes the path, not the identity.

What the agencies actually publish on each

This asymmetry is worth stating rather than smoothing over. NCSC has a VPN page. It defines the purpose, recommends IPsec as an open standard, specifies client certificates for machine authentication, and warns about third-party clients leaking traffic outside the tunnel. It is written for organisations deploying remote access.

There is nothing equivalent for Tor in the material this article draws on. That is not a judgement on Tor — it means any comparison presenting both sides as equally documented consumer advice is doing something the sources do not support. The honest position is that one side has published guidance and the other, here, does not.

Where a VPN’s protection begins and ends

  • Begins: at your device, for traffic that is routed into the tunnel. NCSC’s caveat is the important half — only traffic routed over the VPN is protected by it.
  • Ends: at the exit point. From there onwards the traffic travels as it normally would, and the destination site sees a connection from that exit rather than from you.
  • Shifts rather than removes: your internet provider stops seeing your destinations and the VPN operator starts. You have chosen a different party to trust, not eliminated the need to trust one.
  • Does not touch: accounts you log into, cookies, advertising identifiers, or a fraudulent site at the far end.

What Tor does differently, described plainly

General explanation, not sourced agency guidance. Tor routes traffic through several volunteer-run relays, each of which knows only the step before and the step after, so no single relay sees both who you are and where you are going. That is a different design goal from a VPN, which has one operator who by construction can see both ends.

The practical costs are real: it is slower, some sites block it, and it changes how ordinary web use feels. And it inherits the same fundamental limit — sign into an account over Tor and that account knows it is you.

Because this article’s sources say nothing about it, treat the above as background rather than a recommendation, and be sceptical of any consumer article that presents Tor as a simple privacy upgrade with an official stamp on it.

Choosing, if you actually have to

  1. Write down the specific thing you want to prevent, in one sentence. "More privacy" is not a specification.
  2. If the answer is "reach my home or work network from elsewhere", that is a VPN and always was. NCSC’s IPsec recommendation applies.
  3. If the answer is "stop the café or hotel network operator seeing my destinations", a VPN does that — though note the FTC now says public Wi-Fi is usually safe because most sites are encrypted, and its public Wi-Fi article does not recommend a VPN at all.
  4. If the answer involves protection from a specific, serious threat to your safety, this is not the article for it. That situation calls for guidance written for people at elevated risk, such as CISA’s Project Upskill material, not a product comparison.
  5. If you cannot complete step one, buy nothing. That is a legitimate outcome of this decision.

The assumption both tools break

The comparison usually rests on an unstated premise: that hiding the route is the same as hiding you. It is not. Almost everything that identifies you online is volunteered at the application layer — logins, cookies, the advertising identifier on your phone, the profile a service builds from what you do inside it.

The FTC’s tracking controls address that layer directly, and they are unglamorous: browser privacy settings, per-device ad opt-outs, the operating-system advertising identifier, app permissions, and settings on connected TVs. None of it is a purchase. All of it does more for what people mean by "privacy" than choosing between two routing technologies.

Sources: NCSC UK — Virtual private networks · FTC — Are public Wi-Fi networks safe? · FTC — How to protect your privacy online · CISA Project Upskill, Module 6

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from NCSC UK, the FTC and CISA. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories