Study finds that of 283 mobile VPNs in Google Play Store, 18% didn't encrypt traffic at all, while 75% used third-party data tracking libraries
Between an industry-wide push to encrypt all web traffic and the newfound popularity of secure chat apps, it's been a boom time for online privacy. Tweets: @freedomevpn , @sandraproske , and @mikko Tweets: F-Secure Freedome / @freedomevpn : Freedome is a “gem” in a sea of often shoddy VPN services. Thank you @WIRED, you're not so bad yourself http://fal.cn/Qamc pic.twitter.com/t1XyMoawB1 Sandra / @sandraproske : Well put @WIRED “Online privacy is like anything else in life: You get what you pay for.” https://www.wired.com/... Mikko Hypponen / @mikko : “The researcheres specifically lauded F-Secure Freedome, an app that encrypts what it says” — @WIRED http://www.wired.com/...
Context & Ripple Effects
This 2017 audit landed mid-boom: encryption was becoming the default promise of consumer software, and VPN apps were riding that wave in the Play Store. The researchers' finding cut against the marketing — nearly one in five of the 283 apps scanned didn't encrypt traffic at all, and three-quarters embedded third-party tracking libraries — while singling out F-Secure Freedome as one of the few services worth trusting, a pattern consistent with the earlier lesson that promised encryption means nothing until tested.
The follow-on coverage shows the problem wasn't a 2017 anomaly: [[a:932199|Verizon launched its own Safe Wi-Fi VPN whose privacy policy was a placeholder saying the opposite of its claims]], and by 2023 the [[a:838493|Washington Post found top VPN apps with 100M+ downloads still misleading users about their practices and disguising their ownership]].
First-order effects
- Users of the roughly 50 non-encrypting apps get no tunnel at all — their traffic is as exposed as if no VPN were installed — while the 75% carrying tracking libraries quietly monetize the very data users paid to protect.
- F-Secure Freedome gets an immediate commercial edge: researcher endorsement positions it as the vetted alternative in a market where the default is distrust.
Second-order effects
- Google shifts enforcement from app review to the OS itself — its [[a:948472|Android 9 policy forcing default traffic encryption pushed the figure from under 20% to 80% of apps within a year]], closing at platform level what Play Store vetting missed.
- Telecoms and incumbents read the trust gap as market entry: Verizon's Safe Wi-Fi launch shows carriers selling privacy as a feature, though its placeholder policy repeats exactly the credibility failure the study flagged.
Third-order effects
- If demand keeps outrunning quality control, the industry's exit from its Wild West phase runs through independent audits and transparency standards rather than store listings — the direction the later coverage argues for, and which the 2023 ownership-disclosure findings show remains unfinished.
- App stores and OS vendors consolidate into de facto security regulators for consumer privacy tooling, since platform-level defaults prove more enforceable than per-app promises.
The trend: Consumer privacy tools are scaling faster than any mechanism to verify their claims, shifting the burden of trust from app-store listings to platform defaults and independent auditing.