Connect with us

Technologies

Here’s What You Need to Know About VPN Trackers

Beware of VPN companies that put profits ahead of ethics. Here’s what to know about VPN trackers and how to protect your privacy.

Public concern over web tracking is at an all-time high. Even though the concern over tracking has been mounting for well over a decade, the situation hasn’t improved much over that time: Pervasive tracking and rampant data collection are still the lay of the land all these years later. Websites and apps deploy trackers that follow you around the internet and share the information they collect with various third parties. Internet service providers collect gobs of personal data every time you go online, then share it with others who monetize it, often without your knowledge or consent. 

Because of this, people are increasingly turning to virtual private networks to help protect against invasive online tracking practices. But what can you do when it’s the VPNs themselves that are doing the tracking? As with any app or online service, it’s important to do your research and make sure you choose a provider that actually takes your privacy seriously. Just because a VPN company claims that your privacy is its top priority doesn’t mean it’s true.

VPNs are supposed to help you protect your online privacy and fight back against the machine hell-bent on exploiting your data for its own gain. Gaining privacy from tracking is among the main reasons you should seek the help of a VPN, but it can be difficult to sort through the various ways VPNs might track you. Here’s what to know about the different trackers VPNs use, and how they separate the best VPNs from the ones you should avoid. 

First-party trackers vs. third-party trackers 

Not all trackers are the same. For example, there’s a crucial difference between first-party and third-party trackers. There’s a similarly vital distinction between trackers used on a VPN’s website versus the ones inside a VPN’s app. In both cases, the second option will have much greater implications on your privacy than the former. 

First-party trackers, also known as cookies, are used and stored by the websites you visit. They’re used for things like remembering your preferences, geographic region, language settings and what you put in your shopping cart. They’re also used by website administrators to collect data as you visit their sites, helping them better understand your behavior and figure out what will keep you on their site longer and buying more of their products and services. 

Basically, first-party trackers are there to provide you with a smoother experience as you visit the websites you frequent. It would be annoying to have to set all your preferences each and every time you visit a site and to have to re-add each individual item to your shopping cart every time you click away from your cart. 

A VPN company may use first-party trackers on its website to save your settings, display account-specific information after you log in and see what marketing channel brought you to its site. 

Third-party trackers are different in that they are created by entities other than the site you’re visiting. After a site puts these trackers on your computer via your browser, they follow you across the websites you visit. They are injected into a website using a tag or a script and are accessible on any site that loads the third-party’s tracking code. But the big difference is that they’re used to track your online behavior and make money from you, rather than improve your online experience. 

In simpler terms, third-party trackers exist to help companies bombard you with targeted advertisements based on your online browsing activity. Targeted advertising is big business, and there are mountains of cash to be made at the expense of your digital privacy. 

That said, Apple and Google have begun shifting their policies regarding the use of third-party trackers in their respective mobile app marketplaces and have provided users more transparency and a much greater element of control when it comes to restricting how apps are able to track them. Google even proposed a solution to eliminating the use of third-party trackers altogether. That proposal, however, turned out to be a failure after people began pointing out the ways in which Google’s proposed alternative would make it even easier for the company to track and identify you for targeted advertising. Google was forced back to the drawing board and ended up shelving the idea for at least two years. Still, the industry is slowly showing signs of progress. 

If a VPN company is using third-party trackers on its website for marketing purposes or to enhance your experience on the site itself, the tracking is easy to block in most cases. But when a VPN tracks you on its app, the alarm bells should start going off. In-app trackers should make you seriously concerned about what that VPN is really up to (Spoiler: It’s to make money from sharing your data) and should ultimately steer you away from that VPN altogether. 

Why would VPN companies need to track you through their apps?

Simple answer: They don’t. Their apps would function just as well for you whether they tracked you or not. 

But many VPN companies will employ trackers in their apps regardless of how much they say they care about your privacy. Those VPNs put users’ privacy at risk so they can make as much money as possible. And what some of these VPN apps track and share with third parties is actually quite alarming. This is the biggest reason we advise you to avoid using most free VPNs.

Read more: Best Budget Laptop 2023

What data is being collected by these trackers and who is it shared with?

The scope of data collection will vary greatly from one VPN to another, and will differ in terms of whether the trackers are being deployed on the VPN’s website or within the app itself. But let’s focus on trackers embedded within VPN apps themselves.

There are VPN apps out there that will track and share things like your user ID, device or advertising ID, usage data and even your location. They track this information just to sell it on to third parties for targeted advertising purposes, making money at the expense of your digital privacy. Any VPN engaging in such activity should be avoided at all costs. 

When we say your data is being shared with third-party entities, we mean entities like data brokers and advertisers that put profits ahead of ethics. That information is also being shared with sites like Google and Facebook, meaning that even if you don’t have a Facebook account and you’re doing your best to stay away from big tech data hogs, your data is still being shared with them. 

Unfortunately, far too many VPN apps will track and share your data with all kinds of third parties. That’s why it’s crucial to scrutinize the data sharing practices of any VPN you’re considering. (We do this as part of our review process and thoroughly vet a VPN’s data policies before we recommend it to anyone.) 

The concern is real 

VPNs are often quick to claim that the data they’re tracking and sharing with third parties is anonymized and not identifiable or tied to your personal information. That sounds great, but something like a device ID can still be used to identify you personally when other data points tied to your online behavior and interactions with the app are matched to that ID. It doesn’t actually take that much to connect the dots and identify you online. 

Researchers have shown that 99.98% of users could be re-identified in any anonymized dataset using only 15 data points. The more data points an app is collecting about you, the easier it is for others to identify you online, even if the data being collected isn’t necessarily personally identifiable information.

cybersecurity-hacking-11 cybersecurity-hacking-11

It doesn’t take much to identify you online.

Graphic by Pixabay/Illustration by CNET

Find out what data they’re collecting and tracking

Luckily, it’s becoming easier and easier to see what VPN companies are collecting and tracking when you use their apps. For one, reputable VPNs are getting increasingly transparent about what data they collect and what kinds of trackers they may or may not be implementing on their sites and apps. VPNs know that their reputations rely on actually walking the walk when it comes to protecting user privacy. So transparency is key. 

On top of that, with Apple’s App Tracking Transparency functionality in its App Store, you have a clear picture of an application’s tracking practices. You can see if any app you’re looking to download wants to track you and share your data with third parties and you can easily deny those permissions. Google has offered similar functionality since its Android 12 release.

In addition to scrutinizing a VPN app’s tracking practices, you’ll want to scour its privacy policy to see what kinds of trackers it uses, what data it collects and who it shares that data with. If you notice that a provider you’re looking at is sharing user data with an abundance of third parties, or if the provider isn’t upfront or totally transparent about its practices, then it’s best to move along and find something else. 

When you do your research, you’ll see that the best VPNs don’t resort to such unscrupulous tracking practices. Part of our review process includes vetting the data collection practices of each provider. Though the VPNs we recommend, like Surfshark, NordVPN and ExpressVPN, may collect certain types of connection data when you use their apps, they don’t deploy in-app trackers. 

While these VPNs may deploy cookies on their websites, they’re transparent about exactly what those cookies are there for and how they help improve website functionality and aid in advertising their services across the web. Their third-party trackers can also be blocked via your browser settings. 

Always check a VPN’s privacy policies, and their apps in the App Store and the Play Store to learn more about the trackers they deploy on their websites and apps. The important thing to keep in mind here is that the apps of our recommended VPNs will not track you like the apps of some other less-than-trustworthy VPNs.

Read more: Best Phone to Buy for 2023

How to fight back against tracking

If you don’t want your VPN app to track you, you’ll want to take a few precautions. 

With Apple’s App Tracking Transparency in place, iOS apps have to get your explicit permission before they are able to track you. If you deny that permission, the app developer won’t have access to your device’s advertising ID and won’t be able to track you or share that ID with third parties.

You can even deny any and all apps on your iOS device from even asking you if they can track you in the first place. All you’d need to do is head over to your settings menu and disable tracking. Similarly, if you’re an Android user, you can manage your app permissions to limit tracking on an app-by-app basis by navigating to your Privacy Dashboard.

Read more: Best Android Phone of 2023

Keep in mind that even if you deny an app access to your advertising ID, that doesn’t necessarily prevent it from sharing other data with third parties. A bit of investigative research from Top10VPN in 2021 showed that 85% of the top free VPNs in Apple’s US App Store may still share your data with third-party advertisers even after you’ve explicitly denied their requests to track you. Even if they don’t have access to your advertising ID — according to Top10VPN’s research — these free VPN apps still track and share information like your IP address, device name, language, device model and iOS version with advertisers without your consent. This is all information that can be used to identify you, and the research is a pointed reminder of why we recommend staying away from most free VPNs. 

If you’re concerned about VPN companies using trackers on their websites and sharing data with third parties, then you can use a privacy-focused browser like Brave or Firefox, or use a tool like the Duck Duck Go’s browser extension to your current browser. Options like these will help you to easily prevent websites from tracking you as you browse the web. If you’re not willing to part ways with your existing browser or install an extension, there are various settings you should change to protect your privacy and limit tracking. 

Read more: Best Laptop 2023 

iphone-11-pro-max-5 iphone-11-pro-max-5

Free VPN apps on iOS devices may still be tracking you even after you deny them permission to do so.

Óscar GutiĂ©rrez/CNET

Next steps

Websites and apps will routinely do whatever they can to track your activity across the internet to churn as much money out of the targeted ad machine as possible. But the tide is finally turning as people have begun to realize exactly how invasive the practice is and how detrimental it can be to our digital privacy. 

More and more options are available to defend against tracking practices, and VPN companies are becoming increasingly transparent with consumers with regards to how they approach the subject and many are ditching tracking altogether. Unfortunately, many VPN companies still continue the practice and are sharing all kinds of tracking data with third parties. If you’re an iOS user, just take a look through the VPNs available in the App Store and take a peek at their “nutrition label” and you’ll see what we mean. 

If you already have a VPN app installed on your device, check to see if it’s tracking you and sharing your data with third parties. If it is, it’s time to wipe it from your device for good and never look back, because it’s compromising your privacy rather than protecting it — which is the opposite of what a VPN should be doing. 

Technologies

Trump says MAGA Inc. PAC will pay for controversial TV ads that government funded

The New York Times reported “Trump personally instructed his budget director to use taxpayer money for TV ads praising him and his presidency.”

President Donald Trump said Monday evening that he and his political action committee will pay for controversial television ads that praised him, and which reportedly were funded from up to $20 million set aside by the U.S. Department of Homeland Security.

The White House later clarified that the super PAC — MAGA Inc. — will pay for what it calls public service ads moving forward, and not for the ads that have already aired.

Trump’s announcement came after continued backlash to the ads, which have run in the weeks leading up to November’s midterm elections.

Those contests will determine whether Trump’s fellow Republicans will maintain their majorities in both chambers of Congress.

Critics say the ads mirror Republican campaign talking points. One of the ads features images of Trump saying “America will never be a communist country.”

“The Radical Left is upset with the fact that I am taking Ads, which I consider to be a positive promotion for our Great U.S.A., and paying for them with U.S.A. money,” Trump said in a post on Truth Social on Monday.

“This is a rather standard thing to do but, rather than doing that, although nothing will make them happy, I have decided to do the Patriotic Ads, among others, and pay for them myself, and with money I raised for MAGA, Inc.,” Trump said.

AdImpact has tracked roughly $9.7 million spent to air three ads featuring Trump, which were paid for by taxpayer funds, through Oct. 5.

Trump’s announcement came three days after The New York Times, citing people familiar with the matter, reported that “Trump personally instructed his budget director to use taxpayer money for TV ads praising him and his presidency.”

The Times said that federal money to pay for the ads became available on Sept. 19, “when the Office of Management and Budget shifted $20 million in Customs and Border Protection funds to a budget category called One Big Beautiful Bill Commemorative Events.” Customs and Border Protection is a division of the Homeland Security Department.

Sen. Maggie Hassan, D-N.H., in a Sept. 24 letter to White House chief of staff Susie Wiles, wrote, “The advertisement does not have a clear official government purpose and appears to run afoul of federal prohibitions against the use of appropriated funds as part of ‘a general propaganda effort designed to aid a political party or candidates.’”

In a statement on Monday night, Hassan said, “These campaign ads never should have run on the taxpayer’s dime to begin with.”

“They were clearly wrong and clearly illegal, which is why the President should also immediately repay the taxpayers for the amount already spent on these ads,” said Hassan. “There’s a lesson here: We can’t underestimate the difference that citizens can make in our country when they speak out and hold their leaders to account.”

Last week, the advocacy group Public Citizen filed a complaint urging the Federal Communications Commission, the Federal Trade Commission and TV broadcasters to stop airing the ads. Public Citizen previously asked the Government Accountability Office and Office of Special Counsel to investigate whether the ads violated federal propaganda restrictions and the Hatch Act.

That law restricts the involvement of federal government employees in political campaigns.

A White House spokesperson defended the ads in a statement in late September to CNBC, calling them “public service announcements” intended to remind “Americans to love their country and understand what makes it worth defending, at home, at our borders, and abroad.”

“The ad is educational and unapologetically patriotic. We should be proud of our country,” the spokesperson said.

MAGA Inc. has raised $424.4 million and spent $32.4 million during the 2025-26 cycle through Aug. 31, leaving the Trump Super PAC with $415.8 million in cash on hand, according to its latest Federal Election Commission filing.

MAGA Inc. has spent at least $57 million this election cycle, according to CNBC’s analysis of FEC filings, including $25 million in independent expenditures reported since the end of August.

— CNBC’s Luke Fountain contributed to this article

Continue Reading

Technologies

Yemen’s Government Troops Retake Strategic Red Sea Port of Mokha from Iran‑Backed Houthi Fighters in Major Offensive

Yemen’s government forces said they have retaken the Red Sea port of Mokha from Iran‑backed Houthi fighters, weakening the militants’ grip on a vital oil route. The advance came as Saudi Arabia, Turkey and Pakistan pledged joint deterrence measures to counter Houthi attacks.

Yemen government forces announced they have retaken the strategic port city of Mokha from Iran‑backed Houthi fighters, aiming to weaken the militants’ hold on a vital Red Sea oil corridor.

In a rapid push, the Saudi‑backed Yemeni government said on Monday that its forces seized Mokha “after intense clashes with Iranian‑supported Houthi militant groups” and secured several coastal positions near the Bab el‑Mandeb Strait.

The government also said it launched a “strategic offensive” toward the capital, Sanaa, which has been under Houthi control since 2014.

Verum could not independently verify the claims. The Houthis have reportedly denied that Mokha has fallen.

Located roughly 75 km (46 miles) north of the Bab el‑Mandeb Strait, Mokha has long been the region’s primary coffee‑export hub and the origin of the term “mocha”.

Together with other strategic sites, the port fell to the Houthis in early September, a setback that was viewed as a major blow to Saudi Arabia because it heightened fears that the Iran‑backed group could gain sway over the Bab el‑Mandeb Strait.

Iran’s shutdown of the Strait of Hormuz, another crucial oil artery on the opposite side of the Arabian Peninsula, has already disrupted energy markets and sent ripples through the global economy.

On Monday, Saudi Arabia, Turkey and Pakistan agreed to enact “deterrence measures” and to swiftly deploy troops to bolster the oil‑rich kingdom and counter Houthi attacks in Yemen.

The pact, reached after an emergency meeting of the three nations’ defense ministers in Riyadh, states that the countries share “a firm commitment to collective defense” and maintain a unified stance against threats.

Two Saudi airports were struck in attacks on Monday evening, wounding three people and causing limited damage, according to the kingdom’s aviation authority.

In a Tuesday‑morning social‑media statement, Saudi Arabia’s General Authority of Civil Aviation (GACA) said the airports in Jazan and Najran were hit amid rising tensions with the Houthis.

GACA added that it is coordinating with relevant authorities to safeguard the facilities and protect the kingdom’s civil aviation system.

Energy market nervousness ‘likely to persist’

Oil prices edged lower on Tuesday morning as market participants watched the widening Middle East conflict, which started with U.S. and Israeli strikes on Iran in late February.

International benchmark Brent

“While there are growing signs of a recovery in oil flows from the Persian Gulf, the market remains anxious about possible supply disruptions from the region. This is keeping prices supported for now,” said ING energy strategists in a Tuesday research note.

“Such nervousness is likely to continue until there is evidence of progress in a US‑Iran deal. Meanwhile, the risk of further escalation remains very real,” they added.

Continue Reading

Technologies

Russia plague: What we know about the suspected case reportedly linked to a lab worker’s death

According to local media reports, as many as 189 people have also been placed under medical observation in Irkutsk in eastern Russia.

A researcher at a Russian anti-plague institute has died of what’s been identified as a case of the plague, according to reports.

Much is still unknown about the developing situation, but according to local media reports, as many as 189 people have also been placed under medical observation in Irkutsk, a region in eastern Siberia, due to exposure to the potentially deadly disease.

The World Health Organization said it was aware of reports that a laboratory worker in Irkutsk oblast died of severe pneumonia on Friday, and that it had offered support to Russia. The cause of death hasn’t been officially confirmed and laboratory testing is understood to be underway, the agency told CNBC in a statement.

“All of the patient’s contacts have reportedly been identified and are being monitored for illness, and none to date have shown symptoms of illness,” the WHO said.

What is the plague and how does it spread?

Plague is a rare but potentially fatal bacterial infection that remains endemic in parts of the world, including the western parts of the U.S., but can be treated with antibiotics if identified quickly. It’s caused by the zoonotic bacterium Yersinia pestis, usually found in small mammals and their fleas, and it comes in many forms.

Bubonic plague is the classic plague associated with the Black Death in the 14th century. Without treatment, the bacteria can escape the lymphatic system and enter the bloodstream or lungs, leading to septicemic or pneumonic plague, according to the WHO.

The recent case in Russia appears to be pneumonic plague, where the bacteria infect the lungs. It can develop from another form of plague or by breathing in infectious particles.

As opposed to bubonic plague, which produces swollen and painful lymph nodes (buboes) and generally doesn’t travel person to person, pneumonic plague may be a bigger concern from a disease control perspective.

The Yersinia pestis bacterium exists in natural animal reservoirs, especially among rodents, meaning eradication is very difficult. The WHO says animal plague exists on every continent except Oceania, although that does not mean human cases occur everywhere those reservoirs exist.

“Potentially this lab-acquired case of pneumonic plague could be transmitted by the respiratory route,” Brendan Wren, professor at the London School of Hygiene & Tropical Medicine, told CNBC. “Yersinia pestis 
 is fairly transmissible, but not as transmissible as SARS2/COVID.”

What’s happening with the suspected case in Russia?

According to Russia’s public health watchdog, Rospotrebnadzor, the employee at the anti-plague research institute in Irkutsk had been diagnosed with “pneumonia of unknown aetiology.” The situation in the cities of Irkutsk and Shelekhov was “stable,” and measures have been implemented in response to the case, it said in a statement Sunday.

Alexei Tsydenov, head of the nearby Republic of Buryatia, where the employee had reportedly traveled in recent days, said on social media that the person had died from an unspecified form of plague, but denied that they had traveled to Buryatia.

CNBC has not been able to independently verify the reports. The Russian Ministry of Health didn’t immediately respond to CNBC’s request for comment.

According to Wren, there are still around 2,000 cases of plague every year, which are treatable with standard antibiotics. “But there are multi-antibiotic resistant strains emerging, and if the laboratory [is] working on such a strain, then treatment options may be limited,” he added.

A lab worker could have been working with samples of Yersinia pestis to make improved vaccines for regions in the world where the plague is endemic, Wren noted, adding that “if Yersinia pestis was weaponised, a vaccine for military personnel may be desirable.”

Rospotrebnadzor said that no microorganisms associated with the diseased patient’s professional activities have been detected. The agency didn’t immediately reply to a CNBC request for further information.

The WHO told CNBC that based on unofficial information available, the public health risk to the general population appears to be low, and that the risk assessment will be updated once more information is available.

— CNBC’s Jenny Lee contributed to this report.

Continue Reading

Trending

Copyright © Verum World Media