# Mention kill switch leaks caused by OS limitations

**URL:** https://discuss.privacyguides.net/t/mention-kill-switch-leaks-caused-by-os-limitations/34195
**Category:** Site Development
**Created:** 2025-12-26T13:59:36Z
**Posts:** 17
**Showing post:** 4 of 17

## Post 4 by @ignoramous — 2025-12-26T15:52:20Z

> [@Anvil](#):
>
> I thought I’d make this proposal to add more information about the limitations of what VPN kill switches can do on certain platforms to avoid misleading people into thinking 100% of traffic will go through the tunnel regardless of OS.

There’s 2 issues here:

1. The VPN apps _not_ implementing “killswitch” supported by OSes (regardless of whatever valid justification).
  - This, presently, is PG’s minimum criteria for recommended VPNs.

2. The VPN apps _not_ being able guarantee that no traffic will leak (which they can never, unless they have privileged access, which they don’t on most OSes including Android and iOS).

Issue #2 on Android, for instance, is a limitation stemming from sandboxes an app might be subject to.

Both issue #1 & #2 are a genuine concern, if your threat model says, “Use VPN to hide traffic from ISP”, when no such thing is _possible_ [without installing VPN software on the router](https://discuss.privacyguides.net/t/remove-protonvpn/33980/15) & hoping the router itself does not have “holes”. This puts in to question the 4 points PG today presents as justification for using a VPN, which are:

> Should I use a VPN? **Yes** , almost certainly. A VPN has many advantages, including:
> 
> 1. Hiding your traffic from **only** your Internet Service Provider.
> 2. Hiding your downloads (such as torrents) from your ISP and anti-piracy organizations.
> 3. Hiding your IP from third-party websites and services, helping you blend in and preventing IP based tracking.
> 4. Allowing you to bypass geo-restrictions on certain content.

Point #1 is not possible on some platforms (like iOS and Android), either due to missing implementation on the VPN provider’s official client or due to the OS not extending such guarantees to userspace (as in the case of Android and … iOS?).

None of the recommended providers meet Point #2, but may be, there are other providers that do: [Clarification on "torrenting" in the VPN page · Issue #3176 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/issues/3176)

For VPN client apps, Point #3 (hiding client IP from _3p_ apps and websites) only holds if the providers implement the OS-provided killswitch.

Point #4 is debatable as some services know VPN IP ranges and will not let you access geo restricted content. Usually, residential proxies are needed to bypass geo-restricted content, but those have nothing to do with VPN providers themselves, and rather involve a very shady network of operators that run proxies on compromised IoT and other Internet-connected devices like Projectors / TVs / Streamboxes / Access Points / etc. Not anything that’s ethical by any stretch of my imagination, but YMMV.

---

_[View the full topic](https://discuss.privacyguides.net/t/mention-kill-switch-leaks-caused-by-os-limitations/34195)._
