Internet & Web
How to Use a VPN: What It Really Does and Doesn't Do
A VPN is a useful tool, not a magic privacy shield. Here is an honest, jargon-free guide to what a VPN protects, where it falls short, and how to use it well.
Internet & Web
A VPN is a useful tool, not a magic privacy shield. Here is an honest, jargon-free guide to what a VPN protects, where it falls short, and how to use it well.
A VPN does exactly two useful things: it wraps your device's internet traffic in an encrypted tunnel to a server the VPN company runs, and it swaps your real IP address for that server's address. Everything else you have heard about VPNs is either a consequence of those two facts or marketing that outruns them. Get those two mechanics straight and you will know when a VPN helps, when it does nothing, and when it actively gets in your way.
The tunnel is built with a protocol. The three you will meet are WireGuard, OpenVPN, and IKEv2/IPsec. WireGuard is the modern default in most apps: it is roughly 4,000 lines of code (OpenVPN is hundreds of thousands), which makes it faster and easier to audit, and it uses the ChaCha20 cipher. OpenVPN typically runs AES-256-GCM and is the battle-tested older option. IKEv2 shines on phones because it reconnects almost instantly when you move between Wi-Fi and cellular. If your app lets you pick (usually under Settings > Protocol), leave it on WireGuard or "Automatic" unless a specific network blocks it.
Here is the nuance the ads skip: most of your traffic is already encrypted. Any site with https:// and a padlock encrypts the page contents end to end via TLS. So on public Wi-Fi, an eavesdropper on the same network already cannot read your Gmail password or your bank balance. What they can still see without a VPN is which domains you visit, leaked through DNS lookups and the TLS SNI field. The VPN's real job on that cafe network is hiding those destinations and covering the shrinking number of apps that still use unencrypted connections.
A VPN does not remove trust from the equation, it relocates it. Without one, you trust the cafe router and your internet provider not to snoop on your DNS. With one, all of that traffic instead flows through the VPN company, so they now sit in the position to log where you go. That single fact is why the provider you choose matters more than any feature list.
This is where false confidence gets expensive.
.exe or click a fake login page, the VPN faithfully encrypts and delivers that traffic. It has no idea the content is dangerous. You still need OS and browser updates plus a healthy suspicion of unexpected links.Treating a VPN as total protection is the single most common and costly mistake people make.
Because every packet flows through the VPN company, "no-logs" has to be more than a slogan. The meaningful signal is an independent audit: a firm like Cure53, KPMG, Deloitte, or PwC inspecting the servers and publishing findings. Providers such as Mullvad, Proton VPN, ExpressVPN, and NordVPN have commissioned public audits; that is the bar to look for, not a homepage banner.
A few concrete things worth checking:
Free VPNs deserve real caution. Running server bandwidth costs money, and apps that charge nothing have been repeatedly caught logging activity, injecting ads, or reselling browsing data. The narrow exception is a free tier from a company whose paid product is the real business, such as Proton VPN's free plan. Be equally wary of any service promising "perfect anonymity" or claiming to make you "untraceable" — that is a marketing exaggeration, and a company that overstates the basics is not one you want holding all your traffic.
The install is genuinely simple:
The kill switch is the setting most people forget. If the tunnel drops for a moment — common when a laptop wakes from sleep — the kill switch blocks all internet until the VPN reconnects, so your traffic never leaks over the open connection. You will find it in NordVPN under Settings > Kill Switch, in Proton VPN under Settings > Kill Switch, and similarly named elsewhere. Split tunneling (Settings > Split Tunneling) does the opposite on purpose, letting you route, say, your banking app outside the VPN while everything else stays inside.
After connecting, open a browser and search "what is my IP." It should show the VPN server's location, not your city. Then visit a DNS-leak-test site (search "DNS leak test") and run the extended test — every server listed should belong to your VPN provider, not your home internet company. If your real ISP shows up, your DNS is leaking and the tunnel is only half doing its job; toggle the connection off and on, and enable the provider's leak-protection setting.
Turning it on for public Wi-Fi is an easy win. Shielding your browsing from your internet provider is reasonable. Shifting your apparent location for legitimate reasons works as expected. At home on a network you control the benefit is smaller, though leaving it on for consistency is fine. Just know the trade-offs: routing through a distant server costs speed, usually a 10-30% drop with WireGuard and more with OpenVPN, so pick a nearby server when you want maximum throughput. Banking sites sometimes flag a foreign IP as fraud and lock you out, and streaming services actively block known VPN address ranges. When a site misbehaves, disconnecting for a minute is almost always the fix.
A VPN is a good tool for a defined set of jobs — protecting traffic on untrusted networks, hiding browsing from your provider, and shifting your apparent location. It is not a cloak of invisibility, not antivirus, and not a substitute for strong passwords. Pair it with unique passwords, two-factor authentication, and prompt updates, and you have real, layered protection. Lean on it alone and believe the magic-shield pitch, and you may take risks you would otherwise avoid.
You can, and many people do for consistency. The main costs are a modest speed hit and the occasional site that blocks VPN IPs. If you want a middle ground, set the app to auto-connect only on Wi-Fi networks it does not recognize and stay off on your trusted home network.
Almost never — expect it to be slightly slower because your traffic takes a detour through an extra server. The rare exception is if your internet provider deliberately throttles a specific service like streaming or gaming, in which case hiding that traffic can restore normal speed. For raw speed, choose the geographically closest server and use WireGuard.
In most countries, including the US, UK, Canada, and across the EU, yes, VPNs are completely legal for everyday privacy. A handful of nations such as China, Russia, and Iran restrict or ban unapproved VPNs. Using one to commit a crime is still a crime regardless of the tunnel.
HTTPS encrypts what you send to and from a site, but it still exposes which sites you visit to your network and internet provider. A VPN hides those destinations too, which is its main added value on public Wi-Fi. It is a complement to HTTPS, not a replacement.
Keep reading
A crowded inbox drains attention all day. Here is a calm, repeatable system to clear the backlog and keep your email tidy without living inside it.
Forgotten subscriptions quietly drain money every month. Here is a calm, practical way to find every one of them, cancel cleanly, and keep the list short.