Skip to main content
FixMyTech

What a VPN Actually Does, and Whether You Need One

By

Published

9 min read

Share

Short answer

A VPN encrypts everything leaving your device and routes it through a server run by the VPN company, so your internet provider sees only that you connected to that server. It changes who can see your browsing, not whether you can be identified. HTTPS already encrypts the contents of almost every site you visit, so the security case is far narrower than the adverts suggest.

On this page

Almost everything written about VPNs is written by people who sell them, which is why the same four claims appear everywhere: anonymity, military-grade encryption, safety on public Wi-Fi, and protection from hackers. Two of those are real but narrow. Two are largely obsolete.

A VPN is a plumbing change, not a shield. It takes the traffic that would normally leave your device and go straight to your internet provider, wraps it in encryption, and sends it to a server somewhere else first. That server unwraps it and makes the request on your behalf.

That single change does some genuinely useful things and a lot of things people believe it does but it does not.

What actually happens to your traffic

Without a VPN, a request to a website goes: your device → your router → your internet provider → the site. Your provider sees every domain you visit, and can log it. The site sees your home IP address, which maps roughly to your city and definitively to your provider.

With a VPN running, the chain becomes: your device → your router → your provider → the VPN server → the site. The traffic between your device and the VPN server is encrypted as a single opaque stream.

The consequences are specific:

Who Without a VPN With a VPN
Your internet provider Every domain you visit Only that you talk to one server
The website Your home IP, your rough location The VPN server’s IP and location
Someone on the same Wi-Fi Which domains you visit Nothing readable
The VPN company Nothing — not involved Every domain you visit

That last row is the one the adverts skip. You have not removed the observer. You have swapped your internet provider, who is regulated and generally uninterested in you, for a company whose entire business is built on the claim that it does not keep logs. Some of them are audited. You still cannot verify it yourself.

Why HTTPS changed the argument

The classic VPN sales pitch is the coffee shop: someone on the same network “stealing your password”. That threat was real in roughly 2012, when a large share of the web still ran on plain HTTP and the contents of a page travelled in readable text.

Browsers now refuse plain HTTP by default, flag it as insecure and in many cases upgrade it automatically. On an HTTPS site, the connection is encrypted between your browser and the site’s server. Nobody in between — the café, your provider, a router on the path — can read the page, your login details or anything you submit.

What they can still see on HTTPS is metadata: the domain name you are connecting to, via the DNS lookup and the server name in the connection handshake. So a snooping network knows you visited a bank, a health service or a job site, but not which account or what you did there.

A VPN hides that metadata. That is a real benefit, and it is a much smaller one than “hackers will steal your identity”.

The jobs a VPN genuinely does well

Four of them, in rough order of how often they matter:

Reaching a private network remotely. This is what VPNs were invented for. A work VPN puts your laptop logically inside the office network so you can reach file servers and internal tools that are not exposed to the public internet. The same applies to a VPN server running on your own router at home.

Hiding your browsing from your internet provider. In many countries, providers are permitted to log and in some cases monetise browsing data. If that bothers you, a VPN shifts that visibility to a company you chose rather than one your building is wired to.

Hiding domain metadata on untrusted networks. Hotel, airport and conference Wi-Fi often logs, injects or inspects traffic. A VPN removes all of it from view.

Appearing to be somewhere else. Useful for seeing a site as it renders in another country, or reaching a service while travelling. Streaming services actively fight this, which is its own problem.

What a VPN does not do

Said plainly, because the marketing is relentless:

  • It does not make you anonymous. The moment you log into an account, the service knows exactly who you are. Cookies and browser fingerprints follow you across IP changes. A VPN changes your network address, not your identity.
  • It does not stop malware. Downloading an infected file through an encrypted tunnel delivers an encrypted infected file. Some providers bundle a blocklist feature; that is a separate product bolted on.
  • It does not stop phishing. Entering your password on a fake login page works identically through a VPN.
  • It does not give you better encryption than you already had. “Military grade” means AES-256, which is what your browser uses for HTTPS and what your phone uses for its storage.
  • It does not improve your connection. It can only make it slower; the question is by how much. Why a VPN slows your internet covers the arithmetic.

Protocols, briefly

You will see two names in any VPN app’s settings: WireGuard and OpenVPN. Both are open-source and well studied.

WireGuard is newer, much smaller in code size, connects in under a second and is noticeably faster on the same hardware. OpenVPN is older, slower, and better at disguising itself as ordinary HTTPS traffic on networks that block VPNs. IKEv2 also appears, and is good at surviving a switch between Wi-Fi and mobile data.

Pick WireGuard unless it fails to connect, then try the others. The difference between providers on the same protocol is mostly server location and capacity, not technology.

Do you need one?

An honest decision table:

Your situation Worth a VPN?
Working remotely on company systems Yes, and IT will give you one
Your provider logs or sells browsing data Reasonable, if you trust the alternative
Regularly on hotel or airport Wi-Fi Mild benefit, mostly metadata
General “online safety” at home No real benefit over HTTPS
Trying to be anonymous A VPN is the wrong tool

If you do run one, check it is doing what you think. Testing for DNS and IP leaks takes about two minutes and catches the common case where the app says connected and your real address is still visible.

Realistic expectations

For most home users, a VPN changes one thing: which company can see a list of the domains you visit. If you have a reason to prefer one observer over the other, that is a legitimate reason to run one. If you are buying it to be safe from hackers, you are paying a subscription for something HTTPS already does.

The setup cost is low and the running cost is a few percent of your speed on a nearby server. The honest limit is that no VPN can protect you from the things that actually compromise most people: reused passwords, phishing emails and software left un-updated. A password manager and two-factor authentication buy more safety per pound than any VPN subscription does.

Frequently asked questions

Does a VPN make me anonymous?
No. It hides your traffic from your internet provider and hides your home IP address from websites, but it does nothing about accounts you log into, cookies, or browser fingerprinting. Logging into an account identifies you regardless of which server your traffic came from.
Is public Wi-Fi actually dangerous without a VPN?
Far less than it was a decade ago. Almost every site now uses HTTPS, which encrypts the page contents end to end, so someone on the same network cannot read your email or capture your banking password. They can still see which domains you connect to, which is the gap a VPN closes.
What is "military-grade encryption"?
A marketing phrase for AES-256, which is a public standard that your browser already uses on every HTTPS site and your phone uses for disk encryption. No provider has better encryption than any other, because they all use the same handful of well-studied algorithms.
Can my employer or school still see what I do on a VPN?
Not the contents of the traffic, if the VPN is running correctly. But on a device they manage they can install certificates, monitoring software or policies that see everything before it enters the tunnel, and many managed devices block VPN apps entirely.
Does a VPN stop adverts and tracking?
Only the crudest IP-based kind. Most tracking relies on cookies and fingerprinting, which travel with your browser regardless of the route your traffic takes. A content blocker in the browser does far more for tracking than a VPN does.

All VPN guides