The Tool That’s Both Oversold and Underexplained
VPNs (Virtual Private Networks) are among the most heavily marketed consumer security products, with advertising that implies they provide comprehensive protection against every online threat. The actual protection a VPN provides is specific and limited: it encrypts the connection between your device and the VPN server, and it makes your traffic appear to originate from the VPN server’s IP address rather than your own. Understanding specifically what this provides — and what it doesn’t — produces calibrated decisions about VPN use rather than responses to marketing that exaggerates the benefits.
VPNs have legitimate uses for the specific threats they address: hiding browsing activity from ISP surveillance, accessing content that’s geographically restricted to specific regions, securing traffic on public Wi-Fi networks, and enabling secure remote access to private networks. For these specific purposes, VPNs work as described. For the broader privacy and security promises that VPN marketing implies — protection from all tracking, anonymous internet use, comprehensive security — VPNs provide at best partial and often minimal benefit.
What a VPN Actually Does
A VPN creates an encrypted tunnel between your device and the VPN server: all your internet traffic travels through this tunnel, encrypted, to the VPN server, which then forwards it to its destination on the regular internet. To the websites and services you visit, your traffic appears to originate from the VPN server’s IP address, not your own. To your ISP, only the encrypted connection to the VPN server is visible — not which sites you’re visiting or what you’re doing there.
This creates a trust shift rather than privacy: instead of your ISP being able to see your browsing activity, the VPN provider can see it. The VPN provider’s no-logs policy (claiming not to record which sites you visit) becomes the relevant trust assumption. Well-audited no-logs VPNs (Mullvad, ProtonVPN, ExpressVPN with independent audits) provide reasonable assurance that the VPN provider isn’t recording and selling browsing data; poorly documented VPN providers — particularly free VPNs with opaque business models — may be less trustworthy than the ISP the VPN is supposed to protect against.
What a VPN Doesn’t Do
A VPN doesn’t make you anonymous online: websites can identify you through browser fingerprinting (the unique combination of your browser version, plugins, screen size, timezone, and other characteristics that persist regardless of IP address), login sessions (you’re identified as yourself when logged in regardless of the connection path), and cookies (which persist across sessions and identify you across sites they’re embedded on). The VPN changes your visible IP address; it doesn’t change any of the other identification mechanisms.
A VPN doesn’t protect against malware, phishing, or other endpoint attacks — threats that originate on your device or that you’re tricked into enabling. A phishing site that steals your password delivers the same attack whether you’re using a VPN or not; malware installed on your device has the same access to your files regardless of VPN use. The marketing that implies VPNs provide ‘protection’ against these threats conflates network-level traffic encryption with endpoint security, which are different layers of protection addressing different threats.
When VPNs Are Actually Worth Using
Accessing geographically restricted content is the most universally applicable VPN use case: streaming services that have different content libraries in different countries, news sites that block users from specific regions, and professional tools that are region-restricted are all accessible through a VPN server in the target region. This use is legally murky in some cases (streaming services’ terms of service typically prohibit circumventing geographic restrictions) but is a widespread and low-risk application of VPN technology.
Privacy from ISP surveillance is worth pursuing in countries or regulatory contexts where ISP data collection is routine and unregulated — the US, which lacks comprehensive ISP privacy regulation, is a relevant example. Users who find ISP browsing data collection objectionable have a reasonable case for VPN use to prevent this specific surveillance. In the EU, where GDPR provides some protection for ISP data handling, the case is weaker but not absent.
Choosing a VPN If You Decide to Use One
The VPN selection criteria that matter: jurisdiction (is the VPN headquartered in a country with strong privacy laws and outside major surveillance alliance agreements?), independent audit history (has the no-logs policy been verified by an independent auditor rather than just claimed?), transparency report (does the VPN publish data about government data requests received and how they were handled?), and business model (does the VPN charge money for the service, supporting a legitimate business model, or is it free with an unclear monetisation model?).
Mullvad ($5/month, based in Sweden, independently audited, accepts cash payment, no account email required) is the recommendation for users who want maximum privacy from the VPN provider itself. ProtonVPN (based in Switzerland, independently audited, generous free tier) is the recommendation for users who want a trusted free option or are looking for integration with ProtonMail for a complete privacy-focused suite. ExpressVPN and NordVPN (both with independent audits, strong track records, larger features sets) are appropriate for users who want wider server selection and more feature depth.
