Priviy
privacy-basicsINFO

VPN Kill Switch: The Only Feature That Admits the Product Can Fail

A kill switch cuts your traffic when the tunnel drops. What it covers, the gap it cannot close at reconnection, why app-level and system-level are different products, and how to test yours in two minutes.

By Eric Gerard · Editor · Priviy4 min readPhoto via Pexels

Every other feature of a VPN describes what happens when it works. The kill switch is the only one that describes what happens when it does not.

That makes it the most honest item in the product, and the least tested.

What it does

When the tunnel drops, your applications do not stop. They fall back to the ordinary connection and carry on, quietly, with your real address attached. Most of them will not tell you.

The kill switch blocks traffic while the tunnel is not up. That is the entire feature, and its value is proportional to how often your tunnel drops, which is more often than the interface suggests: a laptop lid closing, a train tunnel, a wifi handover, a server restarting.

A red emergency stop unit mounted on a brushed metal wall, its yellow and red mushroom button sealed behind a clear cover marked LIFT HERE, with instruction text engraved beside it and a black emergency intercom to the right.
A red emergency stop unit mounted on a brushed metal wall, its yellow and red mushroom button sealed behind a clear cover marked LIFT HERE, with instruction text engraved beside it and a black emergency intercom to the right.

The cover is still closed, which is the point of the photograph. A stop button nobody has ever pressed and a stop button that does not work look exactly the same from the outside, and the difference only appears on the day it is needed.

App-level and system-level are not the same product

They are sold under the same name.

App-level closes the applications you nominated. Usually a browser, sometimes a torrent client. Everything you did not list keeps talking, and most people do not list everything, because most people do not know everything their machine talks to.

System-level blocks all traffic at the operating system firewall until the tunnel returns. It is the one people believe they have.

Checking which one you actually have takes thirty seconds in the settings, and it changes what the feature means for you.

The gap at reconnection

The switch blocks while the tunnel is down and unblocks when it comes back. The interesting part is what counts as coming back.

A careful implementation holds the block until the tunnel is verified, not merely started. A less careful one releases it earlier, leaving a short window where traffic flows before protection is genuinely restored.

You cannot read this off a feature list, and providers do not usually document it. Which is why the test below is worth more than the comparison table.

How to test yours, in two minutes

Do not click disconnect. That is the path the software handles gracefully, and testing it proves nothing.

  1. Connect the VPN.
  2. Start something producing continuous traffic that you can watch.
  3. Kill the tunnel abruptly: end the VPN process, or drop the network interface for a moment.
  4. Watch whether the traffic stops immediately.

You are testing the failure the software did not plan for, which is the only failure that matters. A switch that survives a polite disconnect and not an abrupt one is worse than no switch, because it is trusted.

A crowded wall-mounted electrical panel: a row of modular circuit breakers on a rail, nine white meters below them, and dozens of black, green, yellow and red cables running in every direction under a metal cable tray.
A crowded wall-mounted electrical panel: a row of modular circuit breakers on a rail, nine white meters below them, and dozens of black, green, yellow and red cables running in every direction under a metal cable tray.

Every breaker on this board is labelled and nobody knows which one cuts what until somebody flips it. Documentation is a claim. Flipping it is a measurement, and the two are only occasionally the same.

What it costs, and why that cost is the feature

It will block something you wanted, at a bad moment. A video call that dies because the tunnel hiccuped. A file upload that stops halfway.

That is the switch working correctly. The alternative was the upload continuing without protection, which is exactly what you enabled it to prevent.

If you find yourself turning it off to get things done, you have learned something true about your own priorities: you prefer availability to privacy in that situation. That is worth knowing about yourself before an incident rather than after, and it may mean your threat model is smaller than your settings suggest.

What it does not do

It does not hide anything while the tunnel is up. Your login, your cookies, your browser fingerprint are all untouched by it.

It does not fix a leak that happens through the tunnel, such as DNS queries escaping around it or WebRTC handing your address to a page directly. Those are different failures with different fixes, and a working kill switch will sit there quietly while they happen, because from its point of view nothing is wrong.

Frequently asked questions

What does a VPN kill switch actually do?
It blocks your device's traffic when the tunnel is not up. Without one, a dropped connection means your applications quietly carry on over the ordinary connection, exposing your real address to whatever they were talking to. The switch is the answer to a question the rest of the product does not ask: what should happen when this stops working.
What is the difference between an app-level and a system-level kill switch?
An app-level switch closes specific applications you nominated, usually a browser or a torrent client. A system-level switch blocks all network traffic at the operating system's firewall until the tunnel returns. They are marketed under the same name and they are not the same product: the first leaves everything you did not list running freely, and most people do not list everything.
Does a kill switch protect me at reconnection?
That is the gap worth knowing about. The switch blocks traffic while the tunnel is down, then unblocks once it is up again. The risk sits in the moments around that transition, and its size depends entirely on the implementation. A well built switch keeps the block in place until the tunnel is verified rather than merely started. This is not something you can read off a feature list, which is why testing yours matters more than choosing on the basis of the checkbox.
How do I test a VPN kill switch?
Connect the VPN, start something that produces continuous traffic, then cut the tunnel abruptly rather than clicking disconnect: kill the VPN process, or pull the network for a moment. Watch whether the traffic stops. Disconnecting politely through the interface is not the test, because that is the path the software handles gracefully. You are checking the failure it did not plan for.
Should the kill switch always be on?
On the device where it matters, yes, and expect it to cost you something. It will occasionally block a connection you wanted, usually at the worst moment, and that is the feature working. If you find yourself turning it off to get something done, you have learned that your real preference is availability over privacy, which is worth knowing about yourself before an incident rather than after.
Choix éditorial
4.5 / 5

Store your files privately → pCloud

Swiss privacy · 10 GB free · optional zero-knowledge Crypto

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre