What a VPN actually protects, and what it doesn't

The advertising promises invisibility. The technology delivers something much narrower and quite useful: it hides which sites you are asking for from the network you are sitting on, and shows them to the company you are paying instead.

Illustration of an encrypted tunnel running from a laptop to a distant server, watched from outside

Almost every claim made for consumer VPNs is a claim about who can see what. That makes the category unusually easy to assess, because the question has a definite answer: for any given observer — the café's router, your broadband provider, the website itself, an advertising network — either a VPN changes what they see or it does not.

Work through the list and a shape emerges. A VPN does one job well, does a second that mattered far more ten years ago than it does now, and does nothing at all about most of the reasons people install it.

The short answer

What a VPN is, mechanically

Strip away the marketing and a consumer VPN is a single, boring idea. Your device builds an encrypted connection to a server the provider runs, and then sends all of its internet traffic inside that connection. The provider's server unwraps each request and makes it on your behalf, using its own address, then wraps up the reply and sends it back.

Two consequences follow, and they are the only two that matter.

First, anyone watching the network between you and that server sees a single stream of encrypted data going to one address. They no longer see a sequence of separate connections to separate places. Second, every website you visit sees the provider's address rather than yours, and therefore guesses your location from the exit server's location rather than your own.

What HTTPS already protects

The most common reason people give for installing a VPN is public Wi-Fi: the fear that someone at the next table can read what you type. That fear was well founded in about 2012. It has aged badly, because the web encrypted itself in the meantime.

When Google published its plan to make secure connections the default in Chrome, it summarised the trajectory of its own HTTPS transparency data: page loads over HTTPS climbed from "around 30-45 % in 2015" to "the 95-99 % range around 2020", and noted that the residual gap is mostly private addresses rather than public sites: measuring public sites alone moves Linux from 84 % to nearly 97 %. Google has said it will turn on "Always Use Secure Connections" for over a billion users in Chrome 147 in April 2026, and make it the default for everyone in Chrome 154 that October.

Concretely: on a modern connection the café's router cannot read your messages, your passwords or the contents of any page, with or without a VPN. The encryption is negotiated between your browser and the site, and the network operator sits outside it.

What is encrypted and what is visible on an ordinary HTTPS connection On an ordinary HTTPS connection the page content, the URL path, form data, cookies and the reply are all encrypted and unreadable to the network. Visible anyway are the destination server's IP address, the server name in the TLS handshake unless Encrypted Client Hello is in use, the DNS lookup unless encrypted DNS is in use, and the size and timing of the packets. ONE ORDINARY HTTPS REQUEST Encrypted Page content URL path Form data Cookies, tokens The reply The network sees none of this, with or without a VPN. Visible anyway Destination IP Server name (SNI) The DNS lookup Packet size Packet timing This is the column a VPN moves — not the one on the left.
The left column is already handled by the site's own encryption. A VPN acts only on the right-hand column, and only for observers between you and the VPN server.

The two real leaks a VPN closes

The right-hand column is where the argument for a VPN lives, and two entries in it are serious.

The first is DNS. Before your browser can connect to a site it has to turn the name into an address, and that lookup has historically travelled unencrypted to whichever resolver your network handed you — usually your provider's. Encrypted DNS fixes this where it is enabled, and browsers now ship it, but Mozilla's own documentation is careful to note that encrypted DNS is not the end of the story, because the name can leak elsewhere.

That elsewhere is the second leak: the Server Name Indication field in the TLS handshake. The IETF's specification for Encrypted Client Hello, the mechanism designed to close it, describes the problem in plain terms — the plaintext SNI extension, "which leaks the target domain for a given connection, is perhaps the most sensitive information left unencrypted in TLS 1.3". Encrypted Client Hello protects the server name and other fields such as the list of protocols offered, but it is not universally deployed, and the same document is candid about what survives even where it is: "the target domain may also be visible through other channels, such as plaintext client DNS queries or visible server IP addresses".

A VPN closes both leaks at once for everyone upstream of it, which is genuinely valuable if the party you are worried about is the network operator. In the United Kingdom, for example, the Investigatory Powers Act 2016 allows the Secretary of State to require operators to retain communications data — defined by the government as "the 'who', 'where', 'when', 'how' and 'with whom' of a communication but not the content" — including internet connection records, "a record of an event held by a Telecommunications Operator about the service to which a device has connected to on the internet". The Act caps such a notice at 12 months of retention. If your objection is to that record existing at your provider, a VPN does move the record somewhere else.

Advertisement

What a VPN never hides

Here the gap between the product and the advertising is widest. A VPN operates on the network layer, and has no opinion about anything above or below it.

It does not hide you from services you sign into: if you are logged in, the account is you, whatever address the request arrives from. It does not remove cookies, advertising identifiers or the browser fingerprint assembled from your fonts, screen size and graphics stack, so it does not stop a site linking today's session to yesterday's. And it blocks neither trackers, nor malware, nor a convincing phishing page.

Consumer Reports, reviewing 16 providers drawn from an initial list of 51 in December 2021, catalogued the claims this leads to. CyberGhost offered to let users "turn yourself digitally invisible"; NordVPN said "your data will never be compromised"; Kaspersky assured customers that "hackers can never intercept and steal your data"; Hotspot Shield promised activity conducted "anonymously". The report's verdict was that "a number of VPNs do not refrain from making sweeping claims, or using potentially misleading or overly broad language". Only three of the sixteen — IVPN, Mozilla VPN and Mullvad — were credited with describing their own limits honestly.

The FTC reached a similar place from the regulator's side, warning that "the fact that an app promises security or privacy doesn't necessarily make it trustworthy", that some VPN apps "use protocols that don't encrypt your traffic" at all, and that "a VPN app generally isn't going to make you entirely anonymous".

Trust moves; it does not disappear

This part is structural rather than a matter of any one company's conduct. Your traffic has to be decrypted by somebody to reach the internet. Without a VPN, the party who sees which sites you ask for is your access provider; with one, it is your VPN provider. The question is never whether someone holds that view, but who, and under which country's law.

Where the boundary of knowledge sits, with and without a VPN Without a VPN, the local network and the internet provider both see which domains you request, and the website sees your own address. With a VPN, the local network and the internet provider see only an encrypted connection to the VPN server, the VPN provider sees which domains you request, and the website sees the VPN server's address. WHO SEES THE DOMAIN YOU ASKED FOR Without a VPN You Local network Internet provider Website (sees your IP) With a VPN You Local network Internet provider VPN provider (and the site) Plum: can see the domain. Teal: sees only an encrypted stream to one address. One box always knows. A VPN chooses which box it is — it does not remove the box.
The diagram is the argument. Choosing a VPN is choosing which company holds the record, and which jurisdiction can compel it.

Which is why a provider's logging policy is the specification that matters, and why it is only as good as its ability to survive contact with a court. There is at least one well-documented test. On 18 April 2023 officers from Sweden's National Operations Department arrived at Mullvad's office with a search warrant, intending, in the company's account, to seize computers with customer data. Mullvad's published statement says it explained that "such customer data did not exist", demonstrated how the service works, and the officers left without taking anything.

That is the standard to judge claims against: not a promise on a landing page, but an architecture in which there is nothing to hand over. Consumer Reports found several providers advertising no-logging while still storing identifying material on the device — in one case a username alongside "all IP logs (with time stamps)" — and asked the question worth keeping: "if VPNs are not transmitting (using) that information, why was it collected on the local device at all?"

Threat by threat

The honest summary of the category fits in a table.

What you are worried aboutDoes a VPN help?Why
Someone on the café Wi-Fi reading your messagesBarely — already handledHTTPS encrypts the content end to end; a VPN adds nothing to it
The café or hotel logging which sites you visitYesIt sees one encrypted stream to the VPN server instead
Your broadband or mobile provider building a browsing recordYesSame reason; the record moves to the VPN provider
A website knowing your rough locationYesIt sees the exit server's address, not yours
Advertising networks profiling youNoCookies, identifiers and fingerprints are unaffected
Being identified by services you useNoYou are signed in; the account is the identity
Malware, phishing and scam pagesNoNothing about the tunnel inspects what travels through it
Watching a streaming catalogue from another countryOften notProviders detect and refuse it — Netflix returns error E106, "You seem to be using a VPN or proxy"
A government that can compel your VPN providerDepends entirelyOn what is retained, and under which jurisdiction

A different design: splitting the knowledge

It is worth knowing that the single-hop VPN is not the only shape this can take, because the alternative makes the trade-off visible. Apple's iCloud Private Relay routes browsing through two relays operated by different parties. Apple's documentation describes the division: your address "is visible to your network provider and to the first relay, which is operated by Apple", while "your DNS records are encrypted, so neither party can see the address of the website you're trying to visit"; the second relay, run by a separate content provider, "generates a temporary IP address, decrypts the name of the website you requested, and connects you to the site". The stated goal is that "no single party — not even Apple — can see both who you are and what sites you're visiting".

Single-hop VPN compared with a two-relay design With a single-hop VPN, one operator knows both your address and the site you requested. With a two-relay design, the first relay knows your address but not the site, and the second relay knows the site but not your address, so no single operator holds both halves. WHO HOLDS BOTH HALVES Single-hop VPN One operator knows your IP and the site Two relays, two operators Relay 1: your IP, not the site Relay 2: the site, not your IP Splitting the two halves between parties removes the need to trust either one with the whole picture.
The two-relay approach is narrower than a VPN — it covers browsing rather than everything on the device — but it is designed so that no one operator can assemble the full record.

It is not a replacement for a VPN, and it carries the usual cost of hiding an address: Apple notes that "without access to your IP address, some websites may require extra steps to sign in or access content". The point is the principle. A single-hop VPN asks you to trust one company completely; a split-knowledge design asks only that two companies are not co-operating.

If you do want one

There are sound reasons to run one. Not wanting a hotel chain, an airport operator or an employer's guest network to accumulate a list of the sites you use is a reasonable preference, and so is reaching your home or work network from elsewhere — the job the technology was built for. If the goal is to avoid an untrusted network altogether, mobile data is often the better tool, and a local data eSIM takes minutes to add. If the worry is your own household network, the fixes are at the router, not in a tunnel.

Where a VPN is the right answer, five checks do most of the work.

  1. Read the logging policy for what is retained, not what is promised. Connection timestamps and source addresses are the entries that matter; "no logs" as a slogan is not an answer.
  2. Prefer providers that publish independent audits and warrant history, and treat a documented refusal — because there was nothing to give — as worth more than any marketing claim.
  3. Check the jurisdiction of the company and of the exit servers you will use, since that is what determines who can compel the record.
  4. Pay for it. The FTC's warning about free apps funded by advertising or data sharing is the clearest signal in the category.
  5. Insist on encrypted DNS inside the tunnel and a kill switch that drops traffic if the tunnel fails, because a VPN that fails open quietly undoes the one thing it was doing.

Then hold the expectation at the right level. A VPN is a plumbing change with one clear effect: it decides which company sees the list of places you go. That is worth having if you have a view about which company that should be. It is not invisibility, it is not security software, and no amount of "military-grade" in the advertising will make it either.

Sources

Share this guide X WhatsApp LinkedIn Email