The techniques targeting network traffic fall into two clear groups, and the distinction is more useful than any list: those acting along the route, and those acting at the ends.
A VPN covers the route. It does not cover the ends — and the ends are your device and the site you are contacting.
It expands on the recommendation a VPN for sensitive traffic.
Group 1 — Along the route
These are the techniques requiring somebody to be between you and the destination. A VPN neutralises them by moving the exit point.
Observing the destinations
How it works. Whoever runs the network — or the access provider — records which services you communicate with, when and for how long.
What they get. A profile of habits, without reading any content.
What a VPN does. It stops it for that observer: they see only a flow towards the server. It moves it to the VPN provider, though, which has all of that information.
Analysing name resolution requests
How it works. The requests translating site names into addresses are often separate from the traffic and historically unencrypted. Whoever watches them has the complete list of destinations.
What a VPN does. It brings them inside the tunnel — if it is correctly configured. It is the gap the test pages check.
Selective blocking or slowing
How it works. Whoever controls the network identifies the destinations and applies limitations.
What a VPN does. It makes the destinations invisible, so selective blocking becomes difficult. Blocking the VPN server as a whole remains possible.
Interposition
How it works. The techniques described in the unit on interception: a fake network, redirecting the destination, passive listening.
What a VPN does. The traffic inside the tunnel stays unreadable and unalterable even if somebody gets in between. But the tunnel is established after joining the network, so a fake network remains the point of entry — and the portal stays uncovered.
Group 2 — At the ends
These are the techniques a VPN has no effect on at all, and they are the majority of those that actually affect people.
Phishing
What it does. It convinces you to hand your credentials to a site imitating the real one.
Why a VPN does not help. The tunnel delivers your data to the fraudulent site perfectly securely. Encryption has no opinion about the recipient.
It is by far the most widespread threat, and a VPN is irrelevant to it.
Unwanted software on the device
What it does. It captures what you type, or reads the content before it gets encrypted.
Why a VPN does not help. It acts before the tunnel, on the device. The tunnel faithfully carries traffic generated by an unwanted program too.
Tracking through your account
What it does. The services you sign in to with your credentials know who you are, regardless of where you connect from.
Why a VPN does not help. It changes the address you arrive from, not the identity you declare. If you sign in to your account, it is you.
Browser recognition
What it does. The combination of a browser’s technical characteristics allows it to be recognised between visits.
Why a VPN does not help. Those characteristics travel inside the tunnel and arrive intact.
Scams
What they do. They convince a person to perform an action: a payment, a communication, an installation.
Why a VPN does not help. There is nothing technical to stop. You perform the action.
The summary that counts
| Threat | Does a VPN help? | What actually helps |
|---|---|---|
| Observing destinations | Yes | A VPN, well chosen |
| Analysing name resolution | Yes, if configured | A VPN with protection on |
| Selective blocking | Yes | A VPN |
| Interposition on traffic | The content was already protected | HTTPS; a VPN adds little |
| Phishing | No | Checking the domain, a second factor |
| Unwanted software | No | Updates, app permissions |
| Tracking through an account | No | Separating accounts and sessions |
| Browser recognition | No | Browser settings |
| Scams | No | Awareness and verification |
The five rows with “No” cover the great majority of the incidents that happen to people. It is the most useful information in this unit, and it explains why a VPN is not the first measure to adopt for almost anybody.
Why the threats moved to the ends
It is worth explaining, because it is the same dynamic observed in the earlier units.
Attacking the route once took modest effort and gave a rich result: the traffic was in the clear, and being on the same network was enough.
With encryption everywhere that ratio has reversed. The route became expensive to attack and poor in results — you get metadata, not credentials.
The ends, on the other hand, have stayed as they were:
| End | Why it stays accessible |
|---|---|
| The device | There the data is in the clear, before and after encryption |
| The person | No technology stops somebody answering a request |
| The destination site | It receives the data in the clear after decrypting it |
The middle row is the one that counts most: anybody wanting credentials today does not intercept them, they ask for them. It is cheaper, it works at far greater scale, and it requires no proximity at all.
Hence the consequence guiding this whole series: technical tools have solved almost all the technical threats. What remains is addressed with skills and habits — checking a domain, not handing over credentials, recognising an anomalous request.
A VPN is a technical tool for a residual technical problem. It is useful to people who have that problem; it replaces none of the skills covering the rest.
The added risk: the provider itself
It should be stated, because it is specific to this recommendation.
Adopting a VPN introduces a new party into the chain, with complete visibility over who you are and where you go. If that party is not trustworthy, the measure does not reduce the exposure: it concentrates it.
The forms this takes:
Reselling the data, typical of free services, where the traffic is the product.
Applications with undeclared functions, a concrete risk with lesser-known services — because to work, a VPN requires very broad permissions on the device.
Compromise of the infrastructure, which exposes every user’s traffic together.
Requests from the authorities, which follow the provider’s jurisdiction.
None of these risks exists if you do not use a VPN. It is why adopting one is a decision, not a generic precaution.
The techniques no tool helps against
A group worth naming because it appears in neither of the two earlier categories: the techniques acting on the person.
The urgent request. A message asking for immediate action — a payment, a confirmation, a code — exploiting time pressure. No encryption comes into play, because there is nothing to encrypt: there is a decision to take.
Impersonation. Somebody presenting themselves as a colleague, a supplier, technical support. The channel can be perfectly secure: it is the person at the other end who is not what they say.
The request for a verification code. The case where the second factor gets bypassed not technically but by asking the person to read it out. It works because the code really does arrive, so the request looks consistent.
The pressure of authority. A message presenting itself as coming from an official body, in a tone that discourages checking.
These techniques have one thing in common: the protection is verification, not a tool. Stopping, contacting the other party through a channel you know, giving codes to nobody.
It is why, throughout this series, skills count as much as configurations — and why none of the seven measures listed below is sufficient on its own.
How a proportionate defence is put together
Putting the units of this series together, in order of effectiveness against what actually happens:
| Priority | Measure | Against what |
|---|---|---|
| 1 | Unique passwords + a vault | Providers’ breaches, reuse |
| 2 | A second factor | Compromised credentials |
| 3 | Updates | Unwanted software |
| 4 | Checking the domain | Phishing |
| 5 | Login alerts | Late detection |
| 6 | Network configuration | Fake networks, reconnections |
| 7 | A VPN | Observation of destinations |
A VPN is last not because it is useless, but because it covers the one threat the six before it do not touch — and that concerns a minority of people.
Anybody with concrete reasons to protect their destinations places it higher. For everybody else, this is the order.
The case where the VPN becomes the target
A consideration that completes the picture, and that matters for anybody with concrete reasons for confidentiality.
A VPN concentrates many people’s traffic at a single point. That has a positive effect — your traffic mixes with other people’s, making it harder to isolate — and a negative one: that point is, by definition, interesting.
| Situation | Effect |
|---|---|
| Many users on the same server | Your traffic is less distinguishable: positive |
| A single point seeing everything | One target instead of many: negative |
| Your own server, one user | The traffic is entirely traceable to you |
| Occasional VPN use | The moment you turn it on is itself a signal |
The last row is the least intuitive and the most useful for anybody with real needs: turning the protection on only when doing something delicate signals that something delicate is being done. The change in behaviour is visible even if the content is not.
Anybody with concrete reasons keeps it on all the time, precisely for that — not for greater protection, but because a constant condition produces no signals.
For everybody else, occasional use is perfectly fine: if nobody is watching your patterns, there is no pattern to mask.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Telling threats along the route from those at the ends |
| Skills | Knowing which five common threats a VPN does not touch |
| Secure Behaviour | Adopting measures in order of real effectiveness |
Reference level: FL3 — Autonomous.
Summary
- A VPN covers the route, not the ends — and the ends are where almost everything happens.
- Phishing, malware, account tracking and scams: a VPN has no effect at all.
- Adopting one introduces a new party with complete visibility.
- In a proportionate defence it comes last, after six more effective measures.
One thing to do today. Look at the priority table and find the first row you have not yet sorted out. That one is worth more than any subscription.
Related content
- A VPN for sensitive traffic — the recommendation this expands on
- How a VPN works — why it covers the route and not the ends
- Traffic interception — the techniques along the route in detail
- Impact of unprotected traffic — what a VPN actually protects
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



