VPNs: What They Actually Protect You From (and What They Don’t)

The Most Misrepresented Product in Consumer Tech

VPN marketing has created a widely held set of beliefs about what a VPN does that bear limited relationship to what VPNs actually protect against in 2026. Ads for major VPN services feature dramatic scenarios: hackers in coffee shops stealing your data, your ISP selling your browsing history, surveillance agencies tracking your every move. The implication is that a VPN is a comprehensive security solution that protects against these threats. The reality is more specific and more limited: a VPN does some things well and other things not at all, and the things it does well are increasingly less relevant for most users’ actual threat models.

This doesn’t mean VPNs are useless — they have genuine use cases that justify the subscription cost for some users. It means that buying a VPN based on marketing claims rather than on a clear understanding of what it actually does is likely to result in paying for protection you don’t need while remaining exposed to the threats you’re actually concerned about.

What a VPN Actually Does

A VPN creates an encrypted tunnel between your device and the VPN provider’s servers. All traffic between your device and the VPN server is encrypted and passes through that server before reaching the rest of the internet. The practical effects: your ISP sees only that you’re connected to a VPN server, not the specific sites and services you’re accessing. The websites you visit see the VPN server’s IP address, not your real IP address. And anyone intercepting traffic between your device and the VPN server sees only encrypted data.

On a public Wi-Fi network (coffee shop, airport, hotel) without a VPN, traffic between your device and the network router is encrypted for HTTPS sites (the overwhelming majority of modern websites) but passes through infrastructure you don’t control. With a VPN, that traffic is encrypted end-to-end to the VPN server. This was a more meaningful protection in 2015 when many websites weren’t HTTPS; in 2026, when HTTPS is near-universal and browsers flag non-HTTPS sites prominently, the public Wi-Fi use case for VPNs has diminished significantly.

What a VPN Doesn’t Protect Against

A VPN does not make you anonymous. The VPN provider knows which sites you’re visiting — you’ve shifted trust from your ISP to your VPN provider, not eliminated the visibility of your browsing. If the VPN provider logs your traffic and is subpoenaed, or is compromised, or is operated by a government, your browsing history is exposed. ‘No-log’ VPN policies are difficult to verify independently, and the number of VPN providers that have been caught logging despite claiming not to is not small.

A VPN provides no protection against: malware on your device, phishing attacks, tracking cookies and browser fingerprinting (which follow you regardless of IP address), data breaches at the websites you use, account compromises from reused passwords, or targeted attacks at your own accounts. The attackers responsible for the vast majority of consumer cybersecurity incidents (credential stuffing, phishing, malware) are unaffected by whether you have a VPN.

The Legitimate VPN Use Cases

Accessing geo-restricted content is the most common practical VPN use case: streaming libraries that are different in different countries, accessing services that aren’t available in your region, or bypassing geographic blocks on specific websites. A VPN lets you appear to be in a different country. This is explicitly against the terms of service of most streaming services; enforcement is inconsistent, and the cat-and-mouse between VPN providers and streaming services is ongoing.

Traveling to countries with internet restrictions (China, Russia, certain Middle Eastern and Central Asian countries) is a genuine use case where VPNs provide meaningful access to the open internet, though the legal status of VPN use varies by jurisdiction. Remote access to employer networks via VPN is a standard business practice that’s distinct from consumer VPN services.

Choosing Honestly

If your primary VPN motivation is streaming content from another country: a subscription to a streaming VPN service makes sense, with the understanding that it’s a convenience tool, not a security one. If your motivation is security on public Wi-Fi: HTTPS handles most of what you’re actually exposed to without a VPN; a VPN provides marginal additional protection for a modest cost if you’re a frequent traveler on untrusted networks.

If your motivation is privacy from your ISP: a VPN shifts your ISP’s visibility to the VPN provider’s. How much better that trade-off is depends on your VPN provider’s trustworthiness, which is harder to verify than your ISP’s regulatory obligations. For most people’s actual threat model, strong passwords, a password manager, MFA on important accounts, and regular software updates provide more practical security improvement than a VPN subscription at the same cost.

ALL LATEST ARTICLES

Related Articles