A team at Johns Hopkins and Texas A&M settled an argument in mid-2025 that security teams had been having for over a decade: browser fingerprinting isn’t a theoretical privacy risk. It’s an operational one, currently in use, currently defeating cookie deletion, and currently defeating opt-outs under privacy law. For anyone conducting online research – threat intelligence analysts, fraud investigators, open-source intelligence (OSINT) practitioners, law enforcement – that finding closes off a comforting assumption that a lot of investigative tradecraft has quietly rested on for years: that hiding the network address is close enough to hiding the investigator.
It isn’t, and the gap between “close enough” and actual operational security is exactly where virtual machines and VPNs fall short.
That gap matters for threat intelligence, fraud investigations, open-source intelligence (OSINT), law enforcement and other investigative work where revealing an analyst’s identity, location or organization can compromise an investigation.
Managed attribution addresses the problem differently. Instead of changing only the device environment or network path, it gives investigators deliberate control over the identifying signals they expose while conducting research.
VPN vs. virtual machine vs. managed attribution
| Capability | Virtual machine | VPN | Managed attribution |
|---|---|---|---|
| Isolates the local operating environment | Yes | No | Yes, when combined with remote isolation |
| Masks originating IP | Not inherently | Yes | Yes |
| Controls browser fingerprint | Limited | No | Yes |
| Supports geographic attribution | No | Typically IP only | Yes |
| Protects the endpoint from hostile web content | Limited/local isolation | No | Yes, with remote browser isolation |
| Creates consistent investigative personas | No | No | Yes |
| Supports centralized policy and oversight | Depends on deployment | Limited | Yes |
What does a virtual machine protect during an online investigation?
A virtual machine creates a software-based environment that runs on top of a physical host, and it does genuinely useful work: malware analysts detonate samples inside VMs specifically because the blast radius stays contained. But a VM isolates the workstation, not the identity behind it. Run a VM on a standard corporate laptop and the machine still reaches the internet through the same network interface, the same corporate egress point, and frequently the same organizational IP range it always used. A target investigating who’s looking at their infrastructure doesn’t see a mysterious stranger. They see the same organization, wearing a slightly different hat.
That distinction is exactly the kind of thing a target capable of checking web logs has an incentive to check. A VM changes what’s running on the machine. It does nothing about what the machine is still telling the internet on the way out.
What does a VPN hide during online research?
A virtual private network encrypts a connection and routes it through a remote server, which does mask the originating IP address. That’s genuinely useful for protecting traffic on untrusted networks. It was never designed to anonymize an investigator against a target that’s paying attention.
Two problems compound here. First, the endpoint itself remains exposed. If the site under investigation is hosting malware, that risk doesn’t care what IP address is connecting to it; it cares what’s rendering the page. Second, and more consequential for anyone relying on a VPN’s privacy promises: those promises are frequently unverifiable, and occasionally false. In July 2026, a Russian VPN service marketed under the name SplitVPN – formerly NotVPN – was breached, and researchers found a database table recording nearly 58 million device-to-server connection events, dated right up through the day of the breach. The service’s own marketing had promised, in plain language, that it would never store connection logs. It stored tens of millions of them anyway.
That’s not an indictment of every VPN provider. Several undergo genuine independent audits. But “no-logs” is a claim the user has no way to verify from the outside, and the SplitVPN breach is a fresh reminder of what happens when that claim turns out to be marketing rather than architecture. An investigator trusting a VPN’s privacy policy is trusting a third party’s word, backed by nothing the investigator can inspect.
Why does browser fingerprinting matter to investigators?
Browser fingerprinting uses characteristics exposed by a browser and device to help distinguish one visitor from another. Signals can include browser and operating system details, language, time zone, screen characteristics, installed fonts and other attributes.
Recent research has reinforced why this matters. Researchers studying commercial fingerprinting found evidence that browser fingerprints can be used for re-identification even after users clear cookies.
For investigative teams, the implication goes beyond advertising privacy.
A target that can observe and correlate browser characteristics may be able to recognize returning research activity, identify unusual traffic patterns or connect multiple investigative sessions.
A VM can change the computing environment. A VPN can change the network path. Neither automatically controls the complete fingerprint the browser presents to a target.
That is why browser fingerprint management should be part of the threat model for sensitive online investigations.
Why VMs and VPNs fall short
Here’s where the Johns Hopkins and Texas A&M research becomes directly relevant to investigative work, not just consumer ad-tracking. The study itself measured commercial fingerprinting used for advertising, but the underlying mechanism transfers directly: if ad networks can already extract identity-level signal from a fingerprint, a target with a fraction of that sophistication can do the same to anyone returning to its site. The research team built a measurement framework called FPTrace to test whether browser fingerprints – the accumulated signature of screen resolution, time zone, installed fonts, device model, and dozens of other attributes a browser hands over on every page load – were actually being used to re-identify visitors, not just theoretically capable of it. The answer was yes, consistently, and the tracking persisted through cookie clearing. A VM changes the machine. A VPN changes the network path. Neither one touches the fingerprint the browser is broadcasting on every single page load, to every single site, including the one an investigator is trying to research without being noticed.
This is the layer that matters most for anyone doing sensitive online research, because it’s the layer a target can act on. Independent tradecraft writing on the subject draws a useful distinction here between three related but distinct goals: non-attribution, which aims to leave no trace at all and is, for practical purposes, nearly impossible on the modern web; misattribution, which deliberately points suspicion at someone else and carries its own legal and ethical baggage; and managed attribution, which is the deliberate, holistic curation of what a browser and device project to the outside world. Managed attribution doesn’t try to make the investigator invisible. It tries to make the investigator unremarkable – indistinguishable from ordinary traffic, blending into an environment rather than standing out against it.
Done properly, that means controlling language settings, time zone, keyboard configuration, browser and operating system signatures, and geolocation, all at once, all consistently, not just the IP address a VPN happens to mask. It’s a broader and more deliberate discipline than either a VM or a VPN was ever built to provide.
Learn more about how managed attribution improves online investigations >
What is managed attribution?
Managed attribution is the deliberate control of the identifying characteristics an investigator presents while operating online.
Rather than attempting to become completely invisible, investigators can manage how their activity appears to websites, platforms and other users. That can include coordinating:
- IP address and geographic location
- Browser and operating system characteristics
- Language
- Time zone
- Keyboard and regional settings
- Other browser fingerprint attributes
The objective is consistency. An investigator researching activity in another region should not unintentionally present a collection of contradictory signals that exposes organizational affiliation, actual location or investigative intent.
For CTI, OSINT, fraud and law-enforcement teams, managed attribution provides a systematic approach to operational security rather than relying on an accumulation of point tools.
How VMs and VPNs fall short
While VMs and VPNs have their place in the tech stack for average users, they show their limitations when used for anonymous research or investigative purposes.
One misconception with VMs is that by using a different operating system, you’re adding a layer of privacy, security, and anonymity. This is not the case, especially if you’re just running a VM on your standard workstation that you do your normal work on, as you’re still using the same network card. This means that you’re still presenting yourself to the internet as your work computer and not the VM.
VPNs are a little different in that you are now representing yourself on the internet as coming from a different network or IP space. While this may provide some anonymity and privacy, there are still concerns about using the same endpoint you do your normal work on for research/investigative purposes, even with the VPN in place. For example, if you investigate a malicious website, your endpoint is still at risk.
Additionally, pairing a VPN service with a VM doesn’t really add any significant protections, even if the VM is network-based. You could be using a corporate VM or virtual desktop infrastructure (VDI) that appears to be coming from the corporate network. Malicious actors are sophisticated enough to identify that corporate network and ban that IP space from accessing their sites.
Learn more: What VPNs and incognito mode still give away in your online identity >
One last consideration with VPN services is that they state they do not monitor or collect logs of users using their service, but oftentimes, this is false. Some VPN providers capture session or connection data and have the potential to sell that information or potentially leak that information to malicious actors.
The target’s infrastructure is part of the threat model
Investigative security isn’t determined solely by the tools running on an analyst’s device.
The target itself can log connections, timestamps, browser characteristics and other activity. That information may persist long after the investigator leaves the site. It can also become exposed later through a breach or configuration error.
In 2025, for example, researchers discovered an exposed database associated with a cybercrime forum containing millions of login events. Records included IP addresses and timestamps, with some indicating whether connections used proxies or VPNs.
For investigators, the lesson is straightforward: assume the destination can record what it sees.
That changes the security objective. Instead of merely preventing malware from infecting an endpoint, investigative infrastructure should minimize the useful information a target can collect about the analyst, organization and investigation.
What should a secure digital investigation environment provide?
Sensitive digital investigations require more than anonymous browsing. A purpose-built environment should address the investigation across its lifecycle:
Protect: Isolate web activity and potentially malicious content from organizational endpoints and infrastructure.
Mask: Control the digital fingerprint, location and other attribution signals presented to targets.
Accelerate: Give analysts integrated tools to access, capture, analyze and report findings without repeatedly moving sensitive material among disconnected systems.
Manage: Give organizations centralized access controls, policy enforcement and auditability so investigative activity remains secure and compliant.
Together, these capabilities address both analyst operational security and the organizational requirements surrounding sensitive investigative work.
How Silo Workspace supports secure online investigations
Silo Workspace is a unified workspace for entering the threat environment while protecting the organization behind the investigation.
Instead of executing investigative web activity directly on an analyst’s endpoint, Silo isolates activity in cloud-based environments. Managed attribution capabilities allow investigators to control how they appear online, including geographic and browser characteristics.
But secure access is only the beginning of the workflow.
Silo brings the investigation lifecycle — Access, Capture, Analyze and Report — into a unified environment. Analysts can enter target environments under controlled attribution, collect relevant material, analyze findings and move toward finished intelligence while organizational policies and oversight remain in place.
That makes Silo more than an alternative to a VPN or VM. It is purpose-built infrastructure for digital investigations where identity protection, system isolation, investigative integrity and analyst speed all matter.
VPNs and VMs still have a role — just not the same role
VMs and VPNs remain useful technologies.
A VM is valuable when workload or operating-system isolation is the requirement. A VPN is useful when traffic encryption and IP routing are the requirement.
The problem arises when either is expected to provide capabilities it was not designed to deliver.
For routine activity, those limitations may be acceptable. For sensitive investigations against potentially hostile targets, teams need to account for endpoint security, network attribution, browser fingerprinting, geographic consistency, evidence handling and organizational governance together.
That’s the role of managed attribution within a purpose-built digital investigation environment: protect the analyst, mask identifying signals, accelerate the investigation and give the organization control over how investigative activity is conducted.
Frequently asked questions
What’s the difference between a VM and a VPN?
A virtual machine isolates a software environment from its physical host, while a VPN encrypts network traffic and routes it through another server to mask the originating IP address. Both address specific security problems, but neither inherently manages the complete browser fingerprint or digital identity presented during an online investigation.
Why isn’t a VPN enough for sensitive online research?
A VPN masks an originating IP address, but websites can still observe browser, device and behavioral signals that may help identify or correlate visitors. VPNs also do not inherently isolate endpoints from malicious web content. Sensitive investigations therefore require controls beyond network routing alone.
Does a virtual machine hide your IP address?
Not inherently. A virtual machine creates an isolated software environment, but its internet traffic still needs a network connection. Without separate network controls, that traffic can exit through the same organizational infrastructure used by the host environment, potentially exposing information about the investigator or organization.
What is managed attribution in OSINT?
Managed attribution is the deliberate control of the digital identity an investigator presents while conducting online research. It coordinates signals such as IP address, geolocation, browser characteristics, operating system, language and time zone so analysts can research targets without unnecessarily exposing their real identity, location or organization.
How is Silo Workspace different from a VPN or VM?
A VPN primarily changes the network path, while a VM primarily isolates a computing environment. Silo Workspace combines cloud-based isolation and managed attribution with tools supporting the broader investigation lifecycle, helping teams securely access, capture, analyze and report information while maintaining organizational policy, oversight and operational security.