
VPN vs proxy vs Tor: how each hides traffic and how detection tells them apart
VPN vs proxy vs Tor: how each hides traffic, what each one still reveals, and how a detection layer tells them apart at the network level.
Blog / Network signals

VPN vs proxy vs Tor: how each hides traffic, what each one still reveals, and how a detection layer tells them apart at the network level.

iCloud Private Relay hides a Safari user's IP, but Apple publishes its egress ranges, so it is identifiable. What it is and how to read it for fraud.

What an IP fraud score means, how Talos, Scamalytics, and IPQS calculate it, why yours can be high through no fault of your own, and what a score misses.

How to detect geolocation spoofing: how it works, why a single IP check fails, and how layered signals expose the mismatch so your team can prevent fraud.

What iCloud Private Relay and Chrome IP Protection actually change for fraud detection: what degrades, what survives, and why masking is not evasion.

TLS fingerprinting identifies the software behind a connection from its TLS handshake. How it works, what JA3 and JA4 are, and what it reveals.

WebRTC fingerprinting uses a browser's real-time connection setup to expose network data, including a local or real IP behind a VPN. How it works.

What IP reputation is, how the 0 to 100 score is built, and why a clean IP score alone will not catch fraud. The lagging, shared, and recycled-IP problem.

What JA4 fingerprinting is, how it fixes JA3's weakness to TLS randomization, the JA4 string format and JA4+ suite, and what it can and cannot identify.

How proxy detection works for fraud prevention: 13 techniques, why residential proxies are hard to spot, and why an IP check alone is never enough.