What a VPN Protects—and What It Doesn't
- The Tunnel Protects One Stretch of the Trip
- The Local Network Loses the Destination View
- The ISP Sees a Tunnel and the Provider Becomes the Middle
- Destinations Lose the Home IP, Not the Identity
- Peer-to-Peer Connections Expose the Address More Directly
- A Work VPN Protects Access, Not Privacy From the Employer
- Simple Network Filters May Lose Their Grip
- Malware Travels Through Encryption Just Fine
- Phishing Doesn't Need to Break the Tunnel
- The Account Still Knows Who Signed In
- A VPN Doesn't Make the Browser Anonymous
- Test the Protection You Actually Need
- Give Every Risk Its Own Control
A VPN protects a route. It doesn't protect the person from every danger waiting at the other end. The hotel can lose sight of your destinations while a phishing page still steals the password. Same tunnel: one real defense, one untouched risk.
Open a laptop on hotel Wi-Fi without a VPN.
The hotel network carries each connection toward its destination. HTTPS may protect supported page contents in transit, while the network can still see useful connection metadata and destination IPs. A website sees the hotel's public IP plus the account, browser, and anything submitted.
Turn on a full-device VPN.
Covered traffic enters an encrypted connection to the VPN server. The hotel sees the tunnel, its timing, and its volume. The VPN provider handles the next hop. The website sees the server's public IP—but it still receives the login, browser signals, and form data.
That's the protection. Its boundaries matter as much as its benefits.
The Tunnel Protects One Stretch of the Trip
A consumer VPN usually encrypts covered traffic from the device to a provider-operated server. That makes the local network and ISP less able to inspect the destinations and contents carried inside that segment.
The protection begins only after the traffic enters the VPN interface. A split-tunneled app, excluded website, failed tunnel, or leak can take the ordinary route instead.
It ends at the VPN server. From there, traffic continues toward the destination, where HTTPS and the destination's own security still matter.
Think of the tunnel as one protected road between two visible places. The device and person still exist at one end. The VPN company sits at the other. Websites, accounts, and apps remain beyond it.
The Local Network Loses the Destination View
On shared Wi-Fi, the network owner controls equipment between the device and internet. A working VPN can prevent that equipment from seeing the same set of covered destinations and contents.
That helps in hotels, airports, cafés, conferences, and apartment networks. It also covers supported non-browser apps that HTTPS advice often leaves implicit.
The network doesn't go blind. It sees that the device is online and exchanging encrypted traffic with a VPN server. Timing, duration, and volume remain visible. It may also see excluded or failed-open traffic directly.
Modern HTTPS already protects most supported web contents in transit. The VPN adds a broader route around the local observer; it doesn't make certificate warnings safe or turn an impostor hotspot into the right network.
The FTC's current public Wi-Fi guidance emphasizes encrypted websites, updated software, and strong account security. Those protections still matter when a VPN is on; the tunnel doesn't replace them.
The ISP Sees a Tunnel and the Provider Becomes the Middle
Without a VPN, the ISP carries traffic toward each destination. HTTPS can hide supported contents, while destination IPs and useful connection metadata remain available to the network.
With a VPN, the ISP mainly sees an encrypted connection to the VPN server for covered traffic. It still knows the subscriber account, assigned IP, total data use, and connection to that server.
The VPN company now receives the source connection and forwards traffic onward. Depending on its design, it may observe source addresses, destination IPs, timestamps, volume, diagnostics, account data, or payment records. HTTPS can still protect supported contents from the intermediary.
Trust didn't vanish. It moved from the ISP's ordinary route to a company you selected.
- Connects everyday data collection to real choices about freedom, power, and control
- Explains why privacy matters even when you have nothing to hide
- Turns a broad social issue into practical questions you can apply to your digital life
A book about data and power can help frame that choice, but it can't audit a provider. Read the actual privacy policy, identify the legal entity, check retention periods, and treat any audit as evidence limited to its date and scope.
Destinations Lose the Home IP, Not the Identity
On the direct route, websites and internet peers normally see the public IP assigned to the home, office, hotel, or mobile connection. A VPN substitutes the server's public IP for covered traffic.
That keeps the ordinary address away from the destination and changes an IP-based location estimate. Shared exit servers can place many customers behind the same visible source.
The IP is only one clue.
Sign into an account and the service knows the account. Cookies can recognize the browser after the address changes. Browser fingerprints, device identifiers, GPS permission, payment records, and information typed into forms can connect sessions too.
Without the VPN, the destination sees the home IP plus those clues. With it, the destination sees the VPN IP plus those clues. The address changed; identity evidence elsewhere may not.
Peer-to-Peer Connections Expose the Address More Directly
In peer-to-peer systems, participants may exchange public IP addresses as part of making direct connections. A VPN can substitute its server address, keeping the home address from those peers when the traffic is correctly routed.
That benefit depends on coverage and failure behavior. If the app is excluded, binds to the wrong interface, or continues after the tunnel drops, peers may receive the ordinary address.
Use only lawful content. Check whether the provider permits the traffic, then test the app's route and kill switch with harmless activity. Don't assume a changed browser IP proves a separate peer-to-peer client follows it.
A Work VPN Protects Access, Not Privacy From the Employer
A company VPN creates a protected route to internal systems that shouldn't sit openly on the internet. It usually authenticates the employee and may enforce device policy, logging, and inspection.
Compare the job.
A consumer VPN routes covered traffic to a provider server and onward to public destinations. The local network sees the provider tunnel, the provider operates the middle, and websites see the provider IP.
A work VPN routes covered work traffic to an employer gateway. The local network sees that gateway connection, the employer can monitor or inspect supported traffic, and internal services see the company route plus the employee's account.
The company tunnel isn't meant to hide personal activity from the company. Use managed devices and profiles for their intended work.
Simple Network Filters May Lose Their Grip
When local equipment sees the VPN server instead of each covered destination, the tunnel may avoid a simple block based on a domain or IP address.
That benefit is conditional. Networks can block VPN protocols or known server addresses. Services can use account region, device location, payment details, or their own VPN lists.
Technical reach isn't permission. A tunnel doesn't override school or workplace policy, service terms, copyright, or local law.
Don't buy a long subscription around one access promise. Test the lawful task on the actual device and network during a real refund period.
Malware Travels Through Encryption Just Fine
A fake installer remains fake inside an encrypted tunnel. A malicious attachment doesn't become harmless because the hotel can't read it.
The VPN protects transport on one route. Malware runs on the endpoint, where it may read files, capture input, or use granted permissions before traffic is encrypted.
Some VPN apps sell separate threat-blocking features. Judge their covered platforms, filters, update process, and limitations as separate controls. The word VPN doesn't make antivirus or browser protection inherent.
Keep the operating system and apps current. Download from verified publishers. Use appropriate endpoint protection, and don't ignore browser or certificate warnings.
Phishing Doesn't Need to Break the Tunnel
A phishing page can arrive through a perfectly encrypted route. The browser reaches the impostor securely, and the person hands over the password.
The local network may see only the VPN tunnel. The VPN provider may see a destination IP. The phishing operator sees exactly what the victim submits. Encryption worked; the decision failed.
Check the domain and password-manager match before entering credentials. Use unique passwords and phishing-resistant multifactor authentication where supported.
The VPN can't repair a reused password, weak recovery flow, stolen session token, or approval prompt accepted by mistake.
- Connects through USB-C or NFC, covering many newer computers and compatible phones
- Adds a phishing-resistant physical check to passkeys and supported multi-factor logins
- Works without a battery, code display, or wireless pairing process
A FIDO security key can protect compatible account sign-ins against many phishing attempts. It doesn't hide the IP or encrypt Wi-Fi. Each control keeps its own job.
The Account Still Knows Who Signed In
Email, banks, social networks, stores, and subscription services identify the active account no matter which public IP reaches them.
A VPN can protect the route to that service and hide the home IP from it. It can't delete account history, payment information, contacts, shipping addresses, or prior sessions.
Use unique passwords, strong multifactor authentication, tested recovery methods, and alerts for important accounts. A known identity protected well is often the correct goal.
Don't confuse privacy from the hotel with privacy from the service you deliberately signed into.
A VPN Doesn't Make the Browser Anonymous
Cookies, local storage, tracking links, browser fingerprints, and behavior can connect visits after the IP changes. A phone can share GPS-derived location with an app while its internet traffic exits somewhere else.
The VPN provider may also know account and connection details. One company-operated server doesn't create the same distributed trust model as Tor.
Tor can fit some anonymity goals better by routing through multiple relays, but it has its own limits and requires careful browser and identity practices. One familiar login can still introduce the person.
If identification could cause serious legal, employment, or physical harm, don't build the plan from a consumer VPN checklist. Get threat-model help from a qualified digital-security organization.
Test the Protection You Actually Need
Write the expected result before testing.
For IP protection, record the ordinary public IP, connect the VPN, and confirm the destination sees the server's address. For DNS and IPv6, check that each takes the intended route.
For failure protection, close sensitive apps, keep one harmless repeating request open, and interrupt the tunnel using a documented method. The request should stop or go direct according to the policy you selected.
With fail-open behavior, the local network sees the direct destination connection, the VPN provider receives none of it, and the destination sees the ordinary IP. With fail-closed behavior, that covered request stalls until the tunnel reconnects.
A green badge reports what the app believes. A controlled test reports what the network did.
Give Every Risk Its Own Control
Use a VPN when the observer is the local network or ISP, when a destination shouldn't receive the ordinary public IP, or when an approved remote-access gateway is required.
Use endpoint protection for malware. Use careful verification and phishing-resistant sign-in for account theft. Use browser and account controls for tracking. Use deliberate identity practices and appropriate tools for serious anonymity.
Our guide to what a VPN can't do keeps the boundary explicit. The U.K. National Cyber Security Centre's VPN guidance likewise treats full routing, split tunneling, failure, and configuration as separate decisions.
Return to the hotel. The VPN can hide covered destinations from that network and replace the public IP seen by sites. It can't recognize a thief, clean a file, secure an account, or erase a login.
The tunnel earns trust when its job is precise. Give it every job, and the green shield becomes the risk.

