novatrenOnline safety, explained
Guide

Public Wi-Fi and VPNs: what actually changes

A VPN is a useful tool that is sold with claims it cannot support. Here is the honest version of what it does on a cafe network.

No partner links on this page. This guide is reference material and carries no commercial links. The site as a whole is funded by partner links on our buyer's guides — see the affiliate disclosure.

Start with what HTTPS already does

The threat model that sold VPNs to consumers — somebody on the same network reading your webmail as it goes past — was largely closed by the move to HTTPS everywhere. Essentially all significant sites are now encrypted in transit, browsers warn loudly when a page is not, and the contents of your session are unreadable to anyone on the network in between.

What remains visible to the network you are connected to is metadata: which hostnames you are resolving and connecting to, roughly when, and roughly how much. Not the contents of the page, not what you typed. That distinction is the whole basis for deciding whether a VPN is worth paying for.

Two rows showing the same journey from a laptop through cafe Wi-Fi to a website. Without a VPN the access point and network operator can see which sites are visited while HTTPS hides the contents. With a VPN the traffic is wrapped in an encrypted tunnel so the access point sees only the VPN, while the VPN provider now sees the destinations.
Figure 1. A VPN moves who can see your destinations. It does not delete the visibility. Original diagram drawn by us.

What a VPN genuinely gives you

What it moves rather than removes

Your traffic still emerges somewhere. That somewhere is the VPN provider, and it now occupies exactly the position of visibility the cafe used to have. You have not removed the need to trust an intermediary; you have chosen a different one. Whether that is an improvement depends entirely on the provider's logging policy, its jurisdiction, its funding model and whether any of that has ever been independently audited.

This is the reason to be sceptical of free VPN apps in particular. Running a global network of exit servers is expensive. If the product is free, the revenue is coming from somewhere, and the most valuable thing passing through the service is the traffic itself.

What it does not do at all

Practical rules for public Wi-Fi

  1. Check that connections are encrypted. If a browser warns that a site is not secure, take the warning seriously on a network you do not control.
  2. Turn off automatic connection to open networks. A device that joins any network named “Free Wi-Fi” is making the decision for you.
  3. Use your phone's tethering when it matters. Mobile data is usually the simpler answer for banking on the move than any VPN subscription.
  4. Never install a “certificate” a network asks you to install. That is the one action that genuinely does let a network read your encrypted traffic.
  5. Keep two-factor authentication on, which protects you regardless of what the network can see.

The short version

A VPN is worth having if you often use networks you do not control, or if you have a specific reason to keep your destinations away from your internet provider. It is worth choosing carefully, because you are transferring trust rather than eliminating it. It is not a security product in the sense that an antivirus engine is, and no VPN subscription substitutes for updates, backups and a password manager.

Sources