One Request, Five Observers: What Websites, Providers, DNS and VPNs Learn When Loading a Page
The phrase “I have HTTPS, so my provider sees nothing” sounds convincing until one asks what exactly counts as “nothing.” Site name, specific article, message text, external IP, account, browser language and connection time are different data points that appear at different points along the route and reach different parties. This turns most privacy debates into exchanges of half-truths.
Consider an ordinary request to https://news.example/articles/privacy?from=mail from a home connection, standard browser and correctly configured HTTPS site. Corporate networks, antivirus products that replace certificates and decrypting proxies are separate cases where the network administrator can see more.
Browser knows the full address before any packet is sent
Before the first network packet leaves, the browser already possesses the complete URL, including path and query parameters, plus any stored state such as cookies, site data and login tokens. It applies strict rules when deciding what to send to each origin. Scripts on the page can read language, timezone, screen size and graphics API results, yet localStorage remains isolated by origin, HttpOnly cookies stay invisible to JavaScript, and the site cannot enumerate all open tabs or full history.
DNS resolver learns only the domain name
To reach the server the browser must resolve the domain. An unencrypted DNS query can be observed by the local network and ISP. The resolver itself sees the domain and client IP but never the URL path or credentials. DNS over HTTPS and DNS over TLS encrypt the query between device and chosen resolver, shifting trust to that resolver while the ISP sees only the connection to the resolver service.
ISP observes metadata but not HTTPS content
Once the IP address is known, the browser performs a TLS handshake followed by the encrypted HTTP request. The provider normally sees client and destination IPs, port 443, traffic volume, duration, unencrypted DNS queries and the Server Name Indication (SNI) unless Encrypted Client Hello (ECH) is used. Even with ECH the destination IP, volume and timing remain visible. One IP address frequently hosts many domains behind a CDN, so IP alone does not reliably identify the site.
Destination site receives the richest set of signals
The site (or its CDN) decrypts the traffic and obtains the client IP, full URL path and parameters, HTTP headers including Referer (subject to Referrer-Policy), cookies, authorization data, User-Agent information and any values collected by page scripts. Account login creates a stable identifier that survives IP changes. Browser fingerprinting combines language, timezone, screen dimensions and rendering behaviour to probabilistically link visits.
Third-party resources introduce additional observers
A single page often loads images, fonts, analytics scripts and widgets from multiple domains. Each third party receives its own request headers, cookies and identifiers. Removing cookies for one site therefore does not eliminate tracking performed by other origins.
VPN changes the route but adds a new observer
With a full-tunnel VPN the home ISP sees only the encrypted connection to the VPN server. The destination site sees the VPN exit IP. The VPN provider itself becomes the new observer that knows the user’s real IP and all destination addresses. HTTPS still protects content from the VPN, provided the user has not installed a trusted interception certificate.
A comparison of visibility with and without VPN:
- Site: home or mobile IP → VPN exit IP
- ISP: direct connections and sometimes DNS/SNI → connection to VPN and tunnel metadata
- VPN service: not involved → user IP, final destinations and DNS depending on configuration
- DNS resolver: domain and client IP → domain and VPN exit IP if DNS travels inside the tunnel
- Cookies and account: remain in the browser in both cases
- Browser fingerprint: largely preserved in both cases
Incognito mode clears local state, not network visibility
Incognito opens a temporary session whose cookies and storage are discarded when the window closes. Network observers, the destination site and any active VPN still see the same traffic metadata. Chrome documentation explicitly states that sites, the ISP and network administrators may continue to observe activity.
Effective privacy therefore requires first defining the precise information one wishes to hide and from whom, then selecting the appropriate combination of HTTPS, secure DNS, VPN routing, separate browser profiles and reduced third-party scripts.
Related articles
Building Prizrak: How a Developer Created a Federated Messenger That Masks All Traffic as Legitimate HTTPS
A developer created Prizrak, a federated messenger with end-to-end encryption where all traffic, including calls, is indistinguishable from ordinary HTTPS connections. The project addresses three common limitations of existing messengers: centralized control points, mandatory phone numbers, and detectable encrypted traffic. It uses real TLS 1.3 handshakes to actual domains, multi-port listening, and a hidden token mechanism inside the encrypted channel. When servers cannot reach each other directly, messages are delivered through a network of storage nodes modeled after Ceph's RADOS system. Voice and video calls run on a native media stack with custom STUN-like functionality and careful UDP buffer sizing to avoid packet truncation. An integrated two-hop VPN reuses the same stealth transport while keeping messenger traffic outside the tunnel.
GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use
This comprehensive engineering guide explains how to deploy GrapheneOS on supported Google Pixel devices to eliminate corporate telemetry collection. It follows three core principles: rejecting proprietary ecosystems, applying Zero Trust through cryptography and open-source audits, and enforcing strict compartmentalization via isolated user profiles. The tutorial covers official installation via the Web Installer, basic owner profile hardening with PIN shuffling and automatic reboot, and the use of Obtainium for direct FOSS app management from GitHub repositories. Detailed recommendations include privacy-focused tools such as KeePassDX, Aegis Authenticator, AmneziaVPN, Signal, and Fossify applications, along with VPN kill-switch configuration. Regional profiles are created for sandboxed Google Play, Aurora Store, RuStore, and Huawei AppGallery to safely run banking, marketplace, and social apps without cross-profile tracking.
Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection
A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.
WhatsApp Introduces Parental Controls for Teen Privacy Settings
WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.