
VPNs Are a Symptom, Not a Feature: Why the Internet Is Broken

- VPNs solve real problems, but their existence signals deeper failures in trust, privacy, and internet governance.
- People use VPNs to compensate for insecure network assumptions, surveillance-heavy business models, and artificial access barriers.
- The long-term fix is not a better workaround, but infrastructure and policy that make trust, privacy, and open access the default.
A VPN is one of the few security tools that ordinary people install on purpose. It ships inside browsers and operating systems and gets recommended in the same breath as a password manager. Yet ask what it is actually for, and the honest answer is that it patches three very different problems at once, and not one of them is technical in origin. Each one traces back to a choice that could have gone the other way. In every case, the VPN is what we reached for instead of the fix.
VPN is short for Virtual Private Network. It is a tool that routes your internet connection through a server located elsewhere (e.g. your workplace or a different country). Because of this routing, a VPN can mask your actual location, making it seem as if you are browsing from somewhere else. At the same time, because VPNs may be located inside an office network, they can also provide access to internal resources that are not available to the public internet.
The three reasons are worth separating, because the fix each one points to is different, and so is whoever decided we would not get it.
Internal Access: When the Network Cannot Be Trusted
The most familiar use of a VPN is reaching work systems from outside the office, and the thinking behind it is older than it looks. It is the remote-access half of the perimeter model, the oldest idea in network security: draw a wall around the corporate network, treat everything inside it as trusted and everything outside as hostile, and when staff need to reach it from elsewhere, run them through an encrypted tunnel so they emerge on the trusted side. Google’s engineers once compared that model to a medieval castle, in which “anyone who makes it past the drawbridge has ready access to the resources of the castle”. The workplace VPN is the drawbridge, lowered to wherever the employee happens to be sitting.
The trouble is what happens once the wall is breached, which the same engineers put plainly: at that point “an attacker has relatively easy access to a company’s privileged intranet”. Once enough organisations had learned this the hard way, the idea of a safe interior no longer held. Google’s answer, published in 2014 as an architecture called BeyondCorp, was to stop trusting the internal network altogether. Its team argued that one should assume an internal network is “as fraught with danger as the public Internet”, and built accordingly: access depends on the user and their device, never on the network they connect from, and the corporate applications are placed on the public internet behind a proxy that authenticates and authorises every single request. Security stopped living in the network and moved into the applications themselves.
BeyondCorp: A New Approach to Enterprise Security — Rory Ward and Betsy Beyer’s account of the architecture Google adopted after concluding that a corporate intranet is “as fraught with danger as the public Internet”, replacing the trusted perimeter with per-request checks on the user and device, so that the network a request crosses no longer confers any privilege.
The industry gave the general idea a name, zero trust, and it has become the baseline for serious security engineering, both in industry and government. The defining move is exactly the one BeyondCorp made: trust drains out of the network and into the applications, so that every request is judged on who is asking and what device they are on, and the wire it travelled over counts for nothing. That is clearly better than the VPN, and where it is fully adopted it removes the VPN outright. But hold the two approaches side by side and the same admission shows through. The VPN copes with a hostile network by tunnelling through it; zero trust copes by refusing to trust any network at all. Neither one makes the network trustworthy, and, in fairness, that is genuinely hard. The internet was built without trust as a native property, with no inherent notion of identity and no encryption by default, and retrofitting those into a global network after the fact is a problem nobody has fully solved. But hard is not the same as unwanted, and it is not even the thing we are failing at, because it is not the thing we are attempting. The idea that the connection between you and the thing you are talking to might simply be safe by design has quietly dropped off the list of things anyone is building towards.
Privacy: When Watching You Pays Somebody’s Bills
The second reason is to keep an internet provider, a mobile carrier, or the websites you visit from building a profile of you. This one is often misread as having something to hide. It is usually the opposite, and it is the same argument I have made at length elsewhere: the worry is not that the browsing is incriminating, but that you cannot see what is being recorded, who is able to read it, how long it is kept, or what it will later be turned into. A VPN does not answer any of those questions. It moves the watching from a provider you rarely chose to a company you chose precisely because it promises not to look. That can be a genuine improvement, but it is a change of watcher, not an escape from being watched.
I tested this once, deliberately. In the last year of high school, I built my final project around proving that the profiling was real and not paranoia. I opened a browser with no history, no cookies and no cache, searched only for holidays to Madeira for about five minutes, and then read a few unrelated gossip sites. It did not take long: an advert for a trip to Madeira turned up within the first few pages of an ad-heavy gossip site. I ran it again in a second clean browser, searching dating sites instead of holidays, and the same pattern showed up just as quickly. I never established exactly which signal gave me away: a cookie, a browser fingerprint, an IP address logged somewhere in an ad exchange. That is rather the point. Nobody operating any of those sites was obliged to tell me. What the experiment did establish, to my own satisfaction, is that someone had paid for that advert to follow me. The travel company and the dating site were not being generous. They had bought access to something about me that neither had asked my permission to know.
And the watching is not an accident of technology. It is a business model, and it has been defended when challenged. In March 2017, the US Congress voted to repeal a Federal Communications Commission rule that would have required internet providers to get opt-in consent before selling customers’ browsing history to advertisers. The revealing part was the winning argument: not that the collection was harmless, but that platforms like Google and Facebook were already free to monetise the same behaviour, so restraining providers alone would be unfair. Offered the choice between extending privacy to everyone and extending the market to everyone, the legislature extended the market.
Congress just voted to let internet providers sell your browsing history — Reporting on the House vote to repeal FCC rules that would have required ISPs to get opt-in consent before sharing customers’ browsing data with advertisers.
Geo-Gatekeeping: When Access Is Sold, Not Granted
The third reason is to get around restrictions tied to where you happen to be: a streaming catalogue that differs by country, an app store that hides apps by region, content fenced off by distribution contracts that favour scarcity over reach.
The fragmentation is a commercial arrangement, the product of how the rights are sold. A film or series is licensed country by country, often to a different distributor in each, so the same title can have one owner in Denmark, another in Germany, and no home at all in a third market. Geo-blocking is that patchwork of deals enforced in software. The person reaching for a VPN here is usually not trying to take something for free, since they have paid for the subscription, but to reach content that exists and is licensed, only not where they happen to be.
The EU has already tried to fix a version of this, and the fix shows how narrow the political appetite for a real solution is. Since 2018, a regulation has required that if you subscribe to a streaming service in your home country, you can keep using it while travelling temporarily elsewhere in the EU.
Regulation (EU) 2017/1128 of the European Parliament and of the Council of 14 June 2017 on cross-border portability of online content services in the internal market — The EU regulation requiring portable online content services to let subscribers access their home-country content while temporarily travelling elsewhere in the Union.
That is a real fix for a narrow case: a subscriber on holiday. It does nothing for a resident of one country who wants the catalogue sold in another, and it does nothing for the pricing that segments the same film or show by market. You can pay in full for a streaming subscription and still find the catalogue narrowed to whatever your country has been licensed, and when you do reach the rest, subtitles are often limited to the local language, which quietly penalises anyone who has moved countries and not yet learned it. The fact that sites like JustWatch and PlayPilot exist mainly to help people work out what is available where is a fair measure of how normal the fragmentation has become. We addressed the traveller’s edge case and left the fragmentation itself in place.
The Workaround Becomes the Target
Across all three, the shape is the same. Somewhere upstream, someone decided that a broken network was cheaper to tunnel through than to fix, that watching people was worth more than not watching them, or that a market was worth more fragmented than open. The VPN is what an individual builds on top of that decision when they cannot undo it themselves.
The clearest sign of how entrenched this has become is what happens when a government meets the workaround head-on. In December 2025, rather than address the fragmentation underneath, the Danish Ministry of Culture proposed making it illegal to use a VPN to bypass geo-restrictions at all.
Regeringen vil forbyde VPN’er til at streame udenlandsk tv og åbne ulovlige hjemmesider — Coverage of the original proposal to criminalise using a VPN to bypass geo-restrictions.
Regeringen dropper dele af lovforslag om VPN-forbindelser — DR’s report on the ministry withdrawing the VPN section of the bill after public criticism, before it was ever put to parliament.
The proposal never passed; after enough public criticism, the ministry dropped the VPN section before the bill even reached parliament. Let me be clear about where I stand, since I have no wish to defend piracy: protecting copyright is the ministry’s job, and anyone who makes a film or a record deserves to be paid for it. My objection is not to the goal but to the method. A ban goes after where people end up, not why they set out, and in this case they set out because they paid for a service and got a thinner version of it than the subscriber one country over, who sometimes pays less for more. That is not a piracy problem. It is a sign that what they bought is not quite what they were sold.
Music went through exactly this and came out the other side, without anyone being banned from anything. Twenty years ago illegal downloading was a common way for people to get music. What ended it was not enforcement; it was Spotify. Once nearly every song ever recorded sat behind one affordable subscription, going around it stopped being worth the trouble, and the research bears it out: it was the legal option pulling people in, not prohibition pushing them out. Make the honest choice good enough and the workaround dies on its own.
Streaming Reaches Flood Stage: Does Spotify Stimulate or Depress Music Sales? — Luis Aguiar and Joel Waldfogel’s analysis of Spotify streaming, track sales and torrent piracy for 8,000 artists between 2012 and 2013, finding that streaming displaces piracy, in line with earlier research.
Film cannot copy that completely, and the honest reason is cost. A song is cheap to record, so a service can carry almost all of them; a film costs a fortune, and that money has to come back somehow, so no catalogue can plausibly hold everything ever made. That is a real limit. But it is not the limit people actually hit. The film they want exists, and they are paying for a service that may have it. It has simply been sold to another country, another platform, or a release window that has not opened yet. What is presented as one catalogue is the same films licensed piece by piece, so that where you live decides what you may watch — and what you may watch today may be gone next month. None of that is a law of nature. It is a commercial choice, and choices can be made differently.
That is where a ministry worried about piracy could do real work: not policing the workaround, but holding the transaction to the standards we expect of anything else people pay for. I do not know the exact mechanism, but the direction is clear enough — a right to see the full catalogue by country before subscribing, fair warning before a series you are halfway through disappears, some limit on hollowing out what you signed up for the week after you paid. None of it requires a ban. Banning the tool does not fix what made the tool necessary; it removes the option from the person who was never the problem.
VPNs are not the villain here. The tunnel, the paid detour, and the borrowed location are all sensible answers to constraints that are real. What is not sensible is how completely we have stopped asking why the constraints are there. When a workaround becomes this universal, it should send us looking for the fix underneath it, rather than settling in to live with the tool.
- This brief has been substantially rewritten. The earlier version made each of its three points through metaphor; this version keeps the same argument but grounds it in concrete, sourced cases, from Google's BeyondCorp to Denmark's abandoned VPN ban, and opens the privacy section from a personal experiment.
The views and perspectives expressed here are the author's own and do not represent any employer or affiliated organisation. The writing draws on public sources and the author's own experience, never on confidential information. Artificial intelligence is used on some posts to identify sources, draft structure, and assist with quality assurance; the final article is always the author's own work. The AI assists, but never authors.
Niclas Hedam
PhD, Computer Science
Niclas Hedam holds a PhD in Computer Science from the IT University of Copenhagen. He is passionate about educating others on the importance of safeguarding personal information online.

