What a VPN Actually Does, and Whether You Need One
Short answer
A VPN encrypts everything leaving your device and routes it through a server run by the VPN company, so your internet provider sees only that you connected to that server. It changes who can see your browsing, not whether you can be identified. HTTPS already encrypts the contents of almost every site you visit, so the security case is far narrower than the adverts suggest.
On this page
Almost everything written about VPNs is written by people who sell them, which is why the same four claims appear everywhere: anonymity, military-grade encryption, safety on public Wi-Fi, and protection from hackers. Two of those are real but narrow. Two are largely obsolete.
A VPN is a plumbing change, not a shield. It takes the traffic that would normally leave your device and go straight to your internet provider, wraps it in encryption, and sends it to a server somewhere else first. That server unwraps it and makes the request on your behalf.
That single change does some genuinely useful things and a lot of things people believe it does but it does not.
What actually happens to your traffic
Without a VPN, a request to a website goes: your device → your router → your internet provider → the site. Your provider sees every domain you visit, and can log it. The site sees your home IP address, which maps roughly to your city and definitively to your provider.
With a VPN running, the chain becomes: your device → your router → your provider → the VPN server → the site. The traffic between your device and the VPN server is encrypted as a single opaque stream.
The consequences are specific:
| Who | Without a VPN | With a VPN |
|---|---|---|
| Your internet provider | Every domain you visit | Only that you talk to one server |
| The website | Your home IP, your rough location | The VPN server’s IP and location |
| Someone on the same Wi-Fi | Which domains you visit | Nothing readable |
| The VPN company | Nothing — not involved | Every domain you visit |
That last row is the one the adverts skip. You have not removed the observer. You have swapped your internet provider, who is regulated and generally uninterested in you, for a company whose entire business is built on the claim that it does not keep logs. Some of them are audited. You still cannot verify it yourself.
Why HTTPS changed the argument
The classic VPN sales pitch is the coffee shop: someone on the same network “stealing your password”. That threat was real in roughly 2012, when a large share of the web still ran on plain HTTP and the contents of a page travelled in readable text.
Browsers now refuse plain HTTP by default, flag it as insecure and in many cases upgrade it automatically. On an HTTPS site, the connection is encrypted between your browser and the site’s server. Nobody in between — the café, your provider, a router on the path — can read the page, your login details or anything you submit.
What they can still see on HTTPS is metadata: the domain name you are connecting to, via the DNS lookup and the server name in the connection handshake. So a snooping network knows you visited a bank, a health service or a job site, but not which account or what you did there.
A VPN hides that metadata. That is a real benefit, and it is a much smaller one than “hackers will steal your identity”.
The jobs a VPN genuinely does well
Four of them, in rough order of how often they matter:
Reaching a private network remotely. This is what VPNs were invented for. A work VPN puts your laptop logically inside the office network so you can reach file servers and internal tools that are not exposed to the public internet. The same applies to a VPN server running on your own router at home.
Hiding your browsing from your internet provider. In many countries, providers are permitted to log and in some cases monetise browsing data. If that bothers you, a VPN shifts that visibility to a company you chose rather than one your building is wired to.
Hiding domain metadata on untrusted networks. Hotel, airport and conference Wi-Fi often logs, injects or inspects traffic. A VPN removes all of it from view.
Appearing to be somewhere else. Useful for seeing a site as it renders in another country, or reaching a service while travelling. Streaming services actively fight this, which is its own problem.
What a VPN does not do
Said plainly, because the marketing is relentless:
- It does not make you anonymous. The moment you log into an account, the service knows exactly who you are. Cookies and browser fingerprints follow you across IP changes. A VPN changes your network address, not your identity.
- It does not stop malware. Downloading an infected file through an encrypted tunnel delivers an encrypted infected file. Some providers bundle a blocklist feature; that is a separate product bolted on.
- It does not stop phishing. Entering your password on a fake login page works identically through a VPN.
- It does not give you better encryption than you already had. “Military grade” means AES-256, which is what your browser uses for HTTPS and what your phone uses for its storage.
- It does not improve your connection. It can only make it slower; the question is by how much. Why a VPN slows your internet covers the arithmetic.
Protocols, briefly
You will see two names in any VPN app’s settings: WireGuard and OpenVPN. Both are open-source and well studied.
WireGuard is newer, much smaller in code size, connects in under a second and is noticeably faster on the same hardware. OpenVPN is older, slower, and better at disguising itself as ordinary HTTPS traffic on networks that block VPNs. IKEv2 also appears, and is good at surviving a switch between Wi-Fi and mobile data.
Pick WireGuard unless it fails to connect, then try the others. The difference between providers on the same protocol is mostly server location and capacity, not technology.
Do you need one?
An honest decision table:
| Your situation | Worth a VPN? |
|---|---|
| Working remotely on company systems | Yes, and IT will give you one |
| Your provider logs or sells browsing data | Reasonable, if you trust the alternative |
| Regularly on hotel or airport Wi-Fi | Mild benefit, mostly metadata |
| General “online safety” at home | No real benefit over HTTPS |
| Trying to be anonymous | A VPN is the wrong tool |
If you do run one, check it is doing what you think. Testing for DNS and IP leaks takes about two minutes and catches the common case where the app says connected and your real address is still visible.
Realistic expectations
For most home users, a VPN changes one thing: which company can see a list of the domains you visit. If you have a reason to prefer one observer over the other, that is a legitimate reason to run one. If you are buying it to be safe from hackers, you are paying a subscription for something HTTPS already does.
The setup cost is low and the running cost is a few percent of your speed on a nearby server. The honest limit is that no VPN can protect you from the things that actually compromise most people: reused passwords, phishing emails and software left un-updated. A password manager and two-factor authentication buy more safety per pound than any VPN subscription does.