FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

VPN vs Tor: Tor Protected My Research—The VPN Got the Report Out

The newsroom portal rejected my upload before it reached one percent.

Access from this network is restricted.

I was sitting on the floor beside the only working outlet in a hotel room, with eighteen minutes left before an editor in London closed the evening edition.

The report contained notes from three interviews, a verified timeline and photographs I had spent the afternoon checking. I had researched the background through Tor Browser because I did not want the hotel network—or the sites I visited—to connect every search to my ordinary browsing identity.

That part had worked.

Submitting the finished report had not.

I refreshed the portal.

A CAPTCHA appeared.

I completed it.

Another CAPTCHA replaced it.

I requested a new Tor circuit, signed in again and selected the file.

The upload reached four percent, slowed and returned to zero.

I blamed the hotel Wi-Fi.

A speed test in my ordinary browser showed more than enough bandwidth. Tor Browser could still load text pages, but the newsroom portal treated every attempt as suspicious.

I closed Tor and opened the same portal in my normal browser.

It loaded immediately.

So did my email, cloud drive and messaging apps—directly over the hotel network.

I had found the fast route by removing the private one.

That was not the choice I wanted to make.

The short answer

I could not inspect the hotel’s internal filtering rules or the newsroom’s risk systems. The outcome was still decisive: Tor protected the anonymous research but could not complete the identified submission, the established VPN lost the session, and the smaller app delivered the report.

Tor and a VPN were protecting different moments

Before the deadline, the comparison had seemed simple.

Tor was the more private option.

A VPN was the faster one.

The useful distinction was not speed alone. It was the identity attached to the task.

Tor normally sends browser traffic through three relays. Its design prevents one relay from seeing both the user’s original connection and the final destination. A conventional VPN uses a provider-controlled route, making the provider a central point of trust. For stronger anonymity, Tor is the more appropriate tool. (Torproject)

That was why it suited my earlier research.

The hotel network could see that I was using Tor, but not which sites I visited. Those sites saw a Tor exit rather than the hotel’s address. I had kept the session separate from my usual browser and had not signed into personal accounts.

The newsroom submission was different.

I was signing into an account bearing my name.

The portal already knew who I was.

The editor expected a report attached to that identity.

Anonymity was no longer the task. Private, reliable delivery was.

Once that became clear, the comparison stopped being philosophical. Tor had protected the part where I wanted separation. The upload needed a connection that could carry an identified workflow without exposing it to the hotel network.

Tor’s exits created the wrong friction

Tor exit relays are publicly identifiable. Websites can recognise traffic arriving through them, and some respond with CAPTCHAs, restrictions or outright blocks because many unrelated users share the same exits. (Torproject)

That explained the newsroom portal.

Changing circuits gave me another exit address, but it did not change what kind of connection the portal saw.

The first circuit produced a CAPTCHA loop.

The second let me sign in and then rejected the upload.

The third loaded the dashboard so slowly that the session expired before the attachment window appeared.

Tor was also carrying the file through several relays rather than one direct route. That extra distance was acceptable while I was reading articles. Against a deadline, it became the obstacle. (Torproject)

Other users describe the practical limit in much the same way: browsing may work, while publishing or uploading fails because the destination distrusts Tor exits. (Reddit)

The portal in front of me had already reached that conclusion.

I did not need another circuit.

I needed the newsroom to receive the file.

A bridge solved a different problem

I wondered whether the hotel itself was interfering with Tor, so I tried a bridge.

Tor bridges and pluggable transports can disguise the connection into the Tor network. They are useful when an internet provider or local authority blocks known Tor relays. (Torproject)

The bridge connected.

The newsroom portal still displayed a CAPTCHA.

That result clarified the boundary.

The bridge made Tor less obvious to the hotel.

It did not stop the newsroom from seeing a Tor exit at the other end.

The tool had addressed the entrance to the network. My failure was happening at the destination.

The deadline dropped below twelve minutes.

At that point, insisting on Tor was no longer preserving the report’s privacy. It was preventing the report from leaving the laptop.

The rest of the workflow was outside Tor Browser

There was another limitation I had ignored.

Tor Browser protects the traffic inside Tor Browser. It does not automatically carry every other application on the computer. (Torproject)

My report did not live inside one tab.

The photographs were in cloud storage.

The editor was messaging through a desktop app.

The approval code arrived on my phone.

Even if the newsroom upload had succeeded in Tor Browser, the rest of the workflow would still have used separate routes.

A device-level VPN matched that work more naturally. It could carry the ordinary browser, cloud drive and messaging application together instead of protecting one part while leaving me to manage the others.

The privacy architecture was not as decentralised as Tor’s.

The workflow was far closer to the one I needed to complete.

That was enough reason to change tools.

The established VPN reached the portal and lost the session

I opened the major VPN provider I normally used while travelling.

It had a long public history, a large support operation and many nearby servers. I selected its automatic recommendation.

The newsroom portal opened without a CAPTCHA.

I signed in.

The attachment window appeared.

For the first time that evening, the upload moved quickly.

Ten percent.

Twenty-three.

Then the route disconnected.

The VPN app changed to Reconnecting, while the portal returned me to the login page.

I selected another server.

That route opened the dashboard but stalled when I chose the file.

A third connected successfully inside the VPN app, yet the editor’s messaging service remained offline.

The provider offered more locations than I could test before the deadline.

Each server created another login, another decision or another incomplete upload.

Tor had prioritised anonymity over practical delivery.

The established VPN was faster, but it still required me to supervise the route instead of sending the report.

I had six minutes left.

One route carried the whole submission

I closed the established provider and opened OnlydogVPN.

The smaller app did not begin with a country map. I selected the situation for working on a restrictive hotel network and connected.

Then I reopened the newsroom portal in my normal browser.

The login page appeared without a CAPTCHA.

I entered my credentials.

The approval code arrived on my phone.

The dashboard loaded.

I selected the report and photographs.

The upload began.

Ten percent.

Thirty.

The editor sent a message asking whether the final paragraph included the corrected date. The desktop app remained connected, so I answered without leaving the upload page.

Sixty-two percent.

Eighty-seven.

The portal processed the files and displayed their names beneath the report.

I pressed Submit for publication.

The status changed to:

Received by editor.

There were ninety-one seconds left.

The visible result came first: the identified account stayed signed in, the files reached the newsroom and the editor’s messages remained available during the transfer.

Only then did the connection design matter. The service uses an HTTP/3-based transport with added traffic obfuscation, giving the hotel network a less obvious VPN pattern while keeping the upload responsive.

I could not inspect the hotel’s internal filtering rules or the newsroom’s risk systems. The outcome was still decisive: Tor protected the anonymous research but could not complete the identified submission, the established VPN lost the session, and the smaller app delivered the report.


The supporting audio followed me out of the hotel

The editor replied with one final request: send the original audio clip used to verify a quotation.

The file was on my phone.

I began uploading it through the newsroom’s mobile link while walking toward the lift.

The hotel Wi-Fi weakened between floors.

The phone switched to mobile data.

The progress indicator paused.

Then it continued.

The VPN remained connected, and the upload finished before I reached the lobby. Its HTTP/3-based route recovered as the underlying network changed. (IETF)

The editor confirmed receipt.

That smaller result completed the workflow.

The report had left through the laptop.

The supporting evidence followed through the phone.

Neither transfer required another server search, another login or a direct connection through the hotel.

The service had solved the urgent task and then stayed useful when the network changed underneath it.

Tor remained the better tool for anonymous research

Finishing the report did not make Tor unnecessary.

I would still choose Tor Browser when the main goal was separating sensitive research from my ordinary identity.

I would use it to read material without revealing my usual IP address.

I would use it for onion services and for situations where no single provider should know both the beginning and end of the browsing route.

I would consider bridges when direct Tor access was blocked.

Those tasks are built around anonymity and censorship resistance.

The newsroom upload was not.

The moment I signed into a named account, opened a normal messaging application and moved files among several services, the priority changed.

I needed one private route across the whole workflow, and I needed it to remain fast enough to finish.

Using Tor for that stage had not made the submission anonymous. The account identified me before the file began moving.

It had only made an identified task harder to complete.

A VPN was not Tor with better speed

The reverse distinction mattered too.

A commercial VPN should not be described as Tor with fewer delays.

A VPN provider controls the connection route and may be able to associate it with the account or device using the service. Tor distributes that knowledge across separate relays.

For someone facing targeted surveillance, that difference can matter more than convenience.

The correct tool depends on what needs to remain hidden.

When the browsing identity must remain separate and the destination should not see the real IP address, Tor is the stronger starting point.

When the user is already identified and needs several ordinary applications to work reliably on an unfamiliar network, a VPN is usually the more practical fit.

The mistake is expecting one tool to perform both jobs equally well.

The task decided which tool belonged

The smaller service has fewer locations and a shorter public history than the largest VPN providers.

Neither limitation affected the submission.

Tor gave the research the stronger anonymity model, but its shared exits triggered the newsroom’s defenses and its multi-relay route could not sustain the upload.

The established VPN reached the portal, then lost the session on the hotel network.

The smaller app carried the browser, editor messages and file transfer through one usable route, then preserved the phone upload when Wi-Fi gave way to mobile data.

I had started the evening asking whether a VPN or Tor was more private.

The report went out when I separated the two jobs: Tor for the research I did not want linked to me, and the smaller VPN for the work I was prepared to sign.

Questions this experience may leave you with

What was actually causing the problem?

I could not inspect the hotel’s internal filtering rules or the newsroom’s risk systems. The outcome was still decisive: Tor protected the anonymous research but could not complete the identified submission, the established VPN lost the session, and the smaller app delivered the report.

Why did the obvious fixes fail?

The report went out when I separated the two jobs: Tor for the research I did not want linked to me, and the smaller VPN for the work I was prepared to sign.

What should you check first?

The VPN remained connected, and the upload finished before I reached the lobby. Its HTTP/3-based route recovered as the underlying network changed. ( IETF ) (IETF)

What finally changed the result?

The editor sent a message asking whether the final paragraph included the corrected date. The desktop app remained connected, so I answered without leaving the upload page.

What is worth remembering?

Tor gave the research the stronger anonymity model, but its shared exits triggered the newsroom’s defenses and its multi-relay route could not sustain the upload.