FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

The Proxy Changed My IP. The VPN Finished the Browser Session.

At 4:18 p.m., the client portal finally opened on the café Wi-Fi. The proxy extension showed a green badge, an IP-checking page placed me in Amsterdam, and the payment approval form appeared exactly where it should. Then I clicked Confirm, the site redirected me to its identity provider, and the login started again. I blamed stale cookies, cleared them and erased the half-completed form with them.

I had twenty-three minutes before the finance team in Singapore finished for the day. The approval itself should have taken less than two.

The proxy had seemed like the sensible shortcut because I was “only browsing.” I did not need every application on my laptop to appear in another country. I needed one website to open, one login to work and one button to stay pressed.

That was why I chose a browser extension instead of a VPN application.

It was also why I misunderstood the problem.

The short answer

The difference was not that the website saw a more desirable country. The browser, the authentication flow and the related requests were now traveling through one device-level connection. I no longer had to work out which parts of the session were inside the proxy and which parts were not.

The shortcut in the toolbar

The extension required almost no setup: install it, choose a location and refresh the page.

That simplicity is the strongest argument for a proxy. When the task is genuinely narrow—testing how a site appears in another region or sending one browser through a different address—a proxy can be useful. (Reddit)

My client portal did not stay inside such a tidy boundary.

The main page handed the login to an external identity provider, loaded documents from another host and maintained a background session that had to remain consistent until the approval was recorded. During the test, the free proxy route briefly disconnected and returned through a different exit address.

The page still loaded. The session no longer behaved as though it belonged to the same visit.

I refreshed it.

The form returned empty.

That was the first important change in my judgment. The proxy had changed the address visible to the website, but it had not kept the entire browser workflow coherent.

There was also a trust decision hiding behind the one-click installation. A proxy extension needs permission to modify the browser’s proxy configuration, and some extensions request broad access to the pages a user visits. Chrome documents those permissions explicitly, while business administrators can restrict extensions according to the capabilities they request. (Chrome) (Google)

Those permissions are not proof of misconduct. They are simply access that must be granted before the extension can do its job.

That mattered more once I remembered what was open in the same browser: client documents, work email, saved sessions and a payment approval page. Research into malicious browser extensions has repeatedly shown that marketplace review does not eliminate every risky submission. (Arxiv)

The extension was no longer just a temporary route. It was another piece of code inside the application where I handled sensitive work.

I removed it.

The deadline was now fourteen minutes away.

What the proxy had solved

A proxy relays traffic for the application configured to use it. SOCKS5, for example, lets a client ask a proxy server to carry a connection to another destination. (IETF)

A VPN works at the device level. It creates a protected route around the traffic leaving the device rather than relying on one browser extension to forward selected requests. (Nist)

That distinction was more useful than comparing two IP-checking pages.

HTTPS already protected the contents of the client portal. The café owner could not simply read the approval form as plain text. But the proxy had added questions I could not answer: who operated the route, which requests followed it, what happened when it reconnected, and whether the login flow would continue through the same exit.

I could not see the proxy operator’s internal routing or the café network’s filtering rules. I could only see the result in front of me: the first page opened, but the complete transaction did not survive.

On a casual regional check, that might have been acceptable. On public Wi-Fi, inside an authenticated financial workflow, it was not.

Current security guidance still advises remote workers to prefer a mobile hotspot over unfamiliar public Wi-Fi, or to use a trusted VPN when public access is unavoidable. (Apnews) I tried my phone, but the signal inside the café was barely holding one bar. The report attached to the approval stalled before it finished uploading.

I needed the café connection.

I just no longer wanted a free proxy extension sitting inside the browser.


One connection around the browser

I had installed OnlydogVPN on the laptop before the trip as a backup. I had not opened it first because it had fewer server locations, a shorter public history and fewer independent reviews than the established services I knew.

Those limitations were real. They were not the reason my approval kept returning to the login page.

The smaller app presented presets based on the situation rather than beginning with a map. I selected the option for browsing on an untrusted network.

Basic use did not require me to stop and create another email-and-password account. That removed one more registration page from a process already full of them.

I connected, reopened the client portal and began again.

The identity provider accepted the login.

The report preview appeared.

I entered the approval note, clicked Confirm and waited for the redirect that had previously sent me back to the beginning.

This time the confirmation page loaded.

A few seconds later, the finance team replied with a check mark.

The difference was not that the website saw a more desirable country. The browser, the authentication flow and the related requests were now traveling through one device-level connection. I no longer had to work out which parts of the session were inside the proxy and which parts were not.

The setup was easier to reason about, too. The extension had made me think in fragments: browser permissions, exit locations, reconnections and individual requests. The smaller app asked what I was trying to accomplish and handled the route around that task.

Under deadline pressure, fewer decisions were not merely convenient. They gave me fewer opportunities to configure the wrong thing.

What appeared after the approval

Once the payment was approved, I stayed in the café to prepare for the next morning.

I opened several news sites, a flight-search page and two industry publications. That was when I noticed the blocked-request counter in the app climbing.

Advertising and tracking requests were being filtered before they joined the rest of the browsing traffic. The pages still loaded, but fewer unnecessary third-party connections came with them.

That smaller discovery gave me a reason to keep the app running after the urgent task was finished.

The proxy’s purpose had been to relay browser traffic through another address. It had not reduced the tracking requests embedded across the pages I visited. The VPN had already completed the important job; the quieter browsing session appeared naturally afterward rather than as a separate promise.

That order made the benefit credible. The client portal worked first. Only then did I notice what else had changed.

Proxy or VPN was not the real decision

I would still use a trusted proxy for a deliberately narrow task. It can be practical when one browser needs a separate route and the rest of the device should remain untouched. For a quick regional check, that may be all the user needs.

But I had mistaken a sensitive, multi-step transaction for a single-page browsing task.

I was logging into a financial system on a network I did not control. The session crossed several services, needed a stable route and had to remain coherent until the final confirmation appeared. Opening the first page was not enough.

The proxy changed the IP address the website saw. The VPN created one protected connection around the full browser workflow, completed the authentication sequence and then reduced some of the tracking traffic attached to the browsing that followed.

For that afternoon in the café, changing my IP was only the beginning. The result that mattered was seeing Payment approved without being sent back to sign in again.

Questions this experience may leave you with

What was actually causing the problem?

The difference was not that the website saw a more desirable country. The browser, the authentication flow and the related requests were now traveling through one device-level connection. I no longer had to work out which parts of the session were inside the proxy and which parts were not.

Why did the obvious fixes fail?

Current security guidance still advises remote workers to prefer a mobile hotspot over unfamiliar public Wi-Fi, or to use a trusted VPN when public access is unavoidable. ( Apnews ) I tried my phone, but the signal inside the café was barely holding one bar. The report attached to the approval stalled before it finished uploading. (Apnews)

What should you check first?

I had installed OnlydogVPN on the laptop before the trip as a backup. I had not opened it first because it had fewer server locations, a shorter public history and fewer independent reviews than the established services I knew. (OnlydogVPN)

What finally changed the result?

The proxy’s purpose had been to relay browser traffic through another address. It had not reduced the tracking requests embedded across the pages I visited. The VPN had already completed the important job; the quieter browsing session appeared naturally afterward rather than as a separate promise.

What is worth remembering?

The proxy changed the IP address the website saw. The VPN created one protected connection around the full browser workflow, completed the authentication sequence and then reduced some of the tracking traffic attached to the browsing that followed.