Got tired of spotty kill switches so I switched my main house connection to a flashed router with a VPN client at the firmware level. The privacy win is obvious - everything behind it is covered without a second thought - but the speed tax was brutal at first. Spent a week tuning it. Running WireGuard, a direct app on my PC got me 480 down consistently. The same config on the router tanked it to 210, nearly a 55% drop. But after forcing the router to use only a single UDP port and disabling SPI firewall on the router itself, I pulled it back to 390. The big win was no more worrying about which app is leaking - my NAS, IoT junk, everything is just always on. The con is it adds complexity for streaming device exceptions, I have to toggle it for my Shield. For true privacy nuts, it's worth the headache. If you just need to unblock geo-stuff occasionally, the app's fine.