The last time I waited out a delayed flight, I counted nine open WiFi networks in the terminal, every one of them happy to let me on without a password. That convenience is the whole problem. A network that asks nothing of you asks nothing of the person sitting three seats away either, and that person may be reading what everyone else on the WiFi is sending. A VPN is the thing I switch on before I touch a network like that. In plain terms, it is a service that wraps your internet connection in encryption and routes it through a server somewhere else, so the people around you, and your internet provider, can no longer see what you are doing online.
That is the short answer. The longer answer is worth a few minutes, because a VPN does a handful of useful things and a handful of things people wrongly expect of it. Most people who spend any time on WiFi they do not control, or who would rather their internet provider not keep a running list of every site they visit, will get real value from one. A few people barely need one at all. By the end of this you will know which group you are in, and you will not have to take a marketing page’s word for any of it.
Table of Contents
What a VPN is
VPN stands for virtual private network, which is a phrase that explains almost nothing to a normal person, so set it aside. Picture instead what happens when you open a website without one. Your request leaves your laptop, passes through your router, then through your internet provider, and out across the open internet to the site you wanted. At every one of those hops, someone can see where you are going. Your provider logs it. The coffee shop running the WiFi can watch it. The website sees your real IP address, which is the number that identifies your connection and roughly where in the world you are.
A VPN changes the shape of that journey. Instead of going straight out to the open internet, your traffic first travels down an encrypted link to a server run by the VPN company. From there it continues to the website. Two things change as a result. First, everything between your device and that server is scrambled, so your provider and anyone on your local network see only that you connected to a VPN, not what you did afterward. Second, the website now sees the VPN server’s IP address instead of yours. As far as the rest of the internet is concerned, your traffic is coming from wherever that server sits, which might be a city across the country or a continent away.
So a VPN is two ideas bolted together: a private, encrypted pipe between you and a server you trust, and a new public address that stands in for your own. Hold on to those two ideas. Almost everything a VPN can and cannot do follows directly from them.
How a VPN works, in plain terms
The encryption is the part that does the heavy lifting, and you do not need to understand the math to trust it. Modern VPNs scramble your traffic with AES-256, the same encryption standard that banks and governments use to protect their own data. Some use ChaCha20 instead, which is just as strong and a little faster on phones. The practical upshot is the same. Someone who intercepts your connection on that airport WiFi gets a stream of noise rather than your email login or your bank session. The Electronic Frontier Foundation has spent years explaining why this kind of encryption is the foundation of staying private online, and it is the same principle a VPN puts to work for everything you do, not just one website at a time.
The other moving part is the protocol, which is the agreed method your device and the VPN server use to set up that encrypted pipe and keep it running. The one most good providers now default to is WireGuard, a newer protocol that is fast, lean, and easy to audit. Older options like OpenVPN still have their place, and a few providers wrap WireGuard in their own branding. I have written a separate plain-English breakdown of the trade-offs in my guide to VPN protocols, but for now the only thing you need to know is that the protocol is what makes a VPN fast and secure at the same time, and the good ones have mostly converged on the same modern choices.
There is one more job a VPN handles: your DNS requests. Every time you type a website name, your device asks a DNS server to translate it into a numeric address, and by default that question goes to your internet provider, handing them a tidy log of every site you visit. A proper VPN routes those lookups through its own encrypted tunnel instead, so that list never reaches your provider. When people talk about a VPN hiding your browsing, this is a large part of what they mean.
It helps to picture who can see what. Without a VPN, your internet provider sees every site you visit and can log it, the network you are on can watch your traffic, and each website records your real IP address. With a VPN switched on, your provider and the local network see only an encrypted connection to a single server and nothing past it, while the websites you reach see the server’s address in place of yours. Nobody in that chain gets the full picture anymore. The one party that could, in theory, is the VPN company itself, which is exactly why the choice of provider matters so much, and why I keep coming back to audits.
What a VPN does for you
Start with the reason I never travel without one. On any network you do not control, a hotel, an airport, a cafe, a conference center, a VPN encrypts everything you send, so a stranger sharing that WiFi cannot harvest your logins or read your messages. The US Federal Trade Commission still recommends a VPN for protecting yourself on public networks, and after years of living on hotel and cafe WiFi I would put it near the top of the list. This single use case justifies a subscription for most travelers and remote workers on its own.
Closer to home, a VPN takes your browsing history out of your internet provider’s hands. In many countries, including the United States, providers are allowed to collect and sell anonymized data about where their customers go online. Encrypting your traffic and moving your DNS lookups off their servers shuts that down. Your provider can still see that you are connected to a VPN, and how much data you are moving, but the contents and destinations go dark to them.
Then there is location. Because the websites you visit see the VPN server’s address rather than your own, you can choose to appear somewhere else. The everyday version of this is streaming. Connect to a server back home while you are abroad and your usual Netflix or BBC iPlayer library comes back, the one your subscription pays for. I have watched a lot of football from hotel rooms this way. The same trick occasionally saves money, since some airlines and retailers quote different prices depending on where they think you are, and a VPN lets you check.
There is a benefit that surprises people. Some internet providers slow down particular kinds of traffic, video streaming or file sharing especially, once they recognize what it is. Because a VPN encrypts the contents and hides the type of traffic you are moving, your provider can no longer single it out for the slow lane. If your evening Netflix tends to stutter at peak hours, a VPN sometimes smooths it out for exactly this reason. It will not conjure bandwidth you are not paying for, but it can stop your provider from rationing what you have.
Last, a VPN gets you around networks that block things. Some workplaces, schools, and entire countries filter what you can reach, and a VPN tunnels straight past most of that. This is the use case that matters most in places with heavy censorship, where a good VPN can be the difference between an open internet and a walled garden. It is also the use case providers are quietest about, for obvious reasons, but it is real and it works with the better services.
What a VPN can’t do
Here is where I part company with a lot of the marketing. A VPN does not make you anonymous. It hides your traffic from your provider and your local network, and it swaps your address for the server’s, but the VPN company itself can technically see your connection. That is why the only providers worth trusting are the ones whose no-logs promise has been checked by an outside auditor, rather than simply asserted on a homepage. You are not removing the need for trust; you are moving it from your internet provider to a company that has agreed to keep none of your records, and you want proof they mean it.
A VPN also does nothing about the tracking you opt into every day. Log into Google, Facebook, or Amazon and they know exactly who you are, VPN or not, because you told them. Cookies, browser fingerprinting, and your own logged-in accounts all keep working regardless of which server your traffic exits from. If your goal is to stop Big Tech building a profile of you, a VPN is a small piece of a much larger puzzle that also involves browser settings, account hygiene, and a lot of discipline.
And a VPN is not antivirus. It protects your connection, not your machine. Click a malicious link or install a dodgy app and the encrypted tunnel will faithfully carry the malware to you. A few providers bundle a threat-blocking feature that filters known bad domains, which helps at the edges, but it is no substitute for keeping your software updated and your guard up. One more thing it will not do: make anything legal that was illegal without it. A VPN changes who can see what you are doing; it does not change the law where you are. I get into the details of that in my guide on whether using a VPN is legal.
One limit catches people out: a VPN protects only the device it runs on. Switch it on for your laptop and your phone is still naked on that hotel WiFi. Most subscriptions cover several devices at once, and the good apps make it a single tap on each, so this is a small chore rather than a real limit. If you want every gadget in the house covered in one go, including the ones that cannot run a VPN app like a smart TV or a games console, you can install it on your router instead and protect the whole network from one place.
Will a VPN slow you down
A little, yes, and anyone who promises a VPN is completely free of cost to your speed is overselling it. Encrypting your traffic and sending it on a detour through a distant server takes time, so you give up a slice of raw speed in return for the protection. The good news is how thin that slice has become. With a modern protocol and a server in or near your own country, a strong provider holds the large majority of your speed, usually enough that browsing, calls, and HD streaming feel the same as they did before. The drop only becomes obvious when you deliberately connect to a server thousands of miles away, which is the price of appearing somewhere that distant.
For most people, on most days, the difference is small enough to forget about. If you do notice a drag, the fix is usually as simple as switching to a closer server or a faster protocol. I pulled apart what moves the needle, and how to win the speed back, in a separate piece on how much speed a VPN really costs you.
Do you need one
My take, after years of this, is that most people benefit from a VPN but not everyone needs one running every minute of the day. The clearest cases are easy to spot. If you regularly use WiFi you do not own, you want one. If you travel and want your home streaming to come with you, you want one. If the idea of your internet provider logging and selling your browsing bothers you, you want one. If you live somewhere that filters the internet, you need one, and you should choose carefully.
The weaker case is the person who only ever connects through their own home network, does not care whether their provider sees their traffic, and never travels. For that person a VPN is closer to optional than essential, and I would rather be straight about that than pretend everyone is in equal danger at all times. That said, the cost of a good VPN has fallen to a couple of dollars a month, and it runs in the background once it is set up, so the bar for it being worth having is low. Most readers will land on the yes side, often for the public WiFi reason alone.
If you are still weighing it, I wrote a fuller walkthrough of the decision in my guide on how to choose a VPN, which maps the features that matter to the things you want to do.
Free versus paid, briefly
The question I get more than any other is whether a free VPN will do. Usually the answer is no, and the reason is simple economics. Running a fast, global server network costs real money, and a company giving the service away has to make that money somewhere. Too often that somewhere is you: throttled speeds, tiny data caps, intrusive ads, and in the worst cases the sale of the very browsing data you installed the thing to protect. A free VPN that logs and sells your activity is worse than no VPN, because it gives you the confidence to drop your guard while doing the opposite of what it promised.
There is one honorable exception I point people to: ProtonVPN runs a free tier with no data cap and no ads, funded by its paid plans and its Swiss privacy company behind it. It is slower and limited to a few countries, but it is safe to use. Beyond that, the paid services are where the real value sits, and the prices are low enough that it is hard to justify the risk of the alternative. I lay out the full case, including how free providers make their money, in my comparison of free versus paid VPNs. When you do pick a paid one, the three things to check are an independently audited no-logs policy, modern protocols like WireGuard, and a jurisdiction you are comfortable with.
How to get started
Getting a VPN running is less work than most people expect. You pick a provider, install its app on your phone and your laptop, sign in, and tap connect. The app picks the fastest server for you, and from that moment your traffic is encrypted. The whole thing takes about five minutes, and I walk through it device by device in my guide on how to set up a VPN. Most apps let you set it to connect automatically whenever you join an unknown network, which is the setting I would turn on first.
If you want a recommendation rather than a research project, the one I hand to almost everyone who asks is NordVPN. It barely dents my speeds in daily use, its no-logs policy has been audited more than once, and it unblocks the streaming services I rely on no matter which country I wake up in. You can read why in my full NordVPN review, or browse the alternatives on my best VPNs list if you would rather compare. Either way, a VPN is one of the few pieces of software that makes your everyday internet safer without asking anything of you once it is installed. For most people, that is an easy yes.
30-day money-back guarantee, cancel anytime.



Leave a Reply
You must be logged in to post a comment.