CYBER WELFARE

Protect your Digital Privacy

Use a VPN for sensitive traffic: when it genuinely helps

This is probably the most misunderstood recommendation in the whole series, and for a precise reason: a VPN is the most heavily advertised security product there is, and the advertising has built expectations around it that the product does not meet.

The aim of this post is not to convince you to use one. It is to give you what you need to understand exactly what it does, in which situations it helps, and in which it adds nothing to what you already have.

What this recommendation says

Recommendation R11 establishes that a VPN should be used when the traffic is sensitive and the network is not trustworthy, and that the provider should be chosen with deliberate criteria.

A VPN creates an encrypted channel between your device and a server. All the traffic passes through it and comes out at that point instead of from your own connection.

The concrete result is twofold:

  • whoever runs the network you are connected to no longer sees which sites you contact, only that you are talking to the VPN server;
  • the sites you visit see the server’s address, not yours.

What it is not. It is not a tool for anonymity. It does not protect against viruses. It does not stop phishing. And above all it adds no encryption to the content, which is already encrypted by the sites.

Scope. Specific situations, listed below. It is not a measure to keep on permanently for everybody.

Why it matters — and when it does not

It is worth going straight to the most useful point: what changes and what does not.

AspectWithout a VPNWith a VPN
Content exchanged with sitesAlready encryptedAlready encrypted (encrypted twice)
Credentials typedAlready protectedAlready protected
Which sites you contactVisible to whoever runs the networkVisible to the VPN provider
Your address as seen by sitesYoursThe server’s
The Wi-Fi sign-in portalNot protectedNot protected: the tunnel starts afterwards
A fake networkThe risk is presentThe risk is present
Phishing, malware, scamsNot protectedNot protected

The highlighted rows are the ones advertising tends not to mention.

The real benefit is in the third row, and it is precise: a VPN moves the observation from whoever runs the network to whoever runs the VPN. It is a gain only if you trust the second more — which is often true on an airport network, but it is a judgement, not an automatic fact.

A concrete example

John is a journalist. He is working on an investigation and uses a hotel’s Wi-Fi for a week.

The content of his work is protected by the encryption of the sites he uses. But the list of services he contacts — which archives he consults, which organisations, how often — is visible to whoever runs the network, and says a great deal about the investigation without a line of it being read.

With a VPN, whoever runs the hotel’s network sees only an encrypted flow towards a single server.

Now the counter-example. Helen keeps a VPN on permanently on her phone because “it protects”. She browses, reads her mail, uses apps. In her situation the VPN changes almost nothing: the traffic was already encrypted, and the only effect is that the list of her sites has moved from her mobile operator to a company she knows far less about.

The point: the same technology is useful in the first case and neutral in the second. The difference is not technical — it is what you need to protect.

When to apply it

  • When the destination of the traffic is itself sensitive information: delicate professional activities, sensitive research, contexts where observation is a concrete concern.
  • To reach company resources, which is the original function and the most solid use case.
  • On networks you cannot choose and where you have no way of checking who runs them.
  • In contexts where internet access is systematically filtered or observed.
  • When you need services to believe you are elsewhere for legitimate reasons — reaching a service from your own country while abroad, for instance.
  • On third parties’ corporate networks, where traffic inspection is possible and undeclared.

And, just as importantly: it is not needed for browsing on an ordinary public network, it is not needed against scams, and it is not needed if your objective is protecting content.

How to apply it

  1. First clarify what you want to protect. If the answer is “my data”, the sites’ encryption already protects it. If it is “which sites I visit and from where”, then a VPN is the right tool.
  2. Rule out free services. VPN infrastructure has real costs: if you are not paying them, the provider monetises another way, and what it has to sell is the traffic you entrust to it.
  3. Check the logging policy and, if they exist, the independent audits. A declaration without detail is worth little.
  4. Turn on the block-if-it-drops option. If the tunnel breaks, this stops the traffic instead of letting it leave in the clear without telling you.
  5. Check it really is on before operations that count: many VPNs disconnect when the network changes.
  6. Connect to the Wi-Fi first, then turn the VPN on. The sign-in portal has to be completed without the tunnel, and it is the moment when every precaution described in the unit on public networks applies.
  7. Consider whether you need it always or only sometimes. Keeping it on permanently costs speed and battery, and for most activities it produces no benefit.

Common mistakes to avoid

  • Believing it protects the content. The sites already do: a VPN adds a second layer where there was one.
  • Using a free service. It is the case where the solution makes the problem it was meant to solve worse.
  • Thinking it gives anonymity. Anonymity takes much more; a VPN moves observation, it does not remove it.
  • Expecting protection from phishing. An encrypted tunnel delivers your data to a fraudulent site perfectly securely.
  • Turning it off when it slows things down. That is exactly the moment it stops doing its job.
  • Not checking it is on. A dropped VPN that was never restarted gives a security that is not there.
  • Using it for the Wi-Fi portal. It does not work: the tunnel starts after the connection is obtained.

The decisive criterion: who you are trusting

Since a VPN moves observation rather than removing it, choosing the provider is the choice.

Who sees your trafficWithout a VPNWith a VPN
Whoever runs the local networkYes, the metadataNo
Your internet providerYes, the metadataNo
The VPN providerDoes not existYes, all the metadata
The sites you visitYes, what you give themYes, what you give them

The third row is the substance of the decision. Your mobile operator is an identifiable party, with defined obligations and a reputation. A VPN provider can be equally serious — or it can be a company you know nothing about, based in a jurisdiction you are unfamiliar with.

That is not an argument against VPNs. It is an argument for choosing one deliberately, and using it when it is needed rather than out of habit.

The alternatives worth knowing about

Before a subscription, some options solving similar problems with fewer intermediaries.

Your phone’s data connection. If the problem is a network you do not control, using it removes the network from the picture. It does not hide the destinations from your operator, but it hides them from whoever runs whichever Wi-Fi you are on — which is often what was wanted.

Encrypting name resolution. Many browsers and operating systems now allow the requests translating site names into addresses to be encrypted. It is free, it is turned on in a setting, and it closes one of the two points from which destinations are observable. It does not cover everything a VPN covers, but it covers the most exposed part.

A VPN server run by you. For anybody with technical skills: you can host your own server on a cloud service. The advantage is that the observer is you; the disadvantage is that the traffic is traceable to a single user, so there is none of the dilution a service with many users offers.

Your home network as the exit point. Some routers allow you to connect to your home network from outside and exit from there. It is the simplest solution for anybody who only wants to avoid public networks, and it introduces no new party at all.

A privacy-focused browser. For specific activities there are tools designed for anonymity, with far stronger guarantees than a VPN’s and a different purpose. They are the correct tool when the stakes are high, and they are oversized for ordinary browsing.

How this connects to the Cyber Welfare Framework

PillarHow it contributes
AwarenessUnderstanding that a VPN moves observation rather than removing it
SkillsJudging a provider with concrete criteria
Secure BehaviourUsing it where it helps, and checking it is on

Digital maturity levels.

  • FL1 — Basic. No VPN, or a free one installed because “it protects”.
  • FL2 — Beginner. You know what it does and does not do; no free services.
  • FL3 — Autonomous. A VPN chosen with criteria, the drop-block on, deliberate use.
  • FL4 — Skilled. You tell when it helps from when it adds nothing; you check it is on.
  • FL5 — Expert-Guide. You help others avoid buying a tool for a problem they do not have.

R11 completes R9 and R10: HTTPS protects the content, device configuration protects the device, a VPN protects the destination. Three different things.

How to check you are applying it correctly

  1. Can I say in one sentence what my VPN protects that HTTPS does not already protect?
  2. Do I know which company runs the service I use, and where it is based?
  3. If the tunnel dropped right now, would the traffic stop or leave in the clear?

Quick checklist

  • ☐ I can tell what the VPN protects from what HTTPS already protects
  • ☐ I do not use a free service
  • ☐ I know the provider, its base and its logging policy
  • ☐ The block-if-the-tunnel-drops option is on
  • ☐ I check it is on before the operations that count
  • ☐ I know it does not protect against phishing and scams
  • ☐ I use it when it helps, not out of habit

For an overall measure of where you stand, you can take the digital resilience self-assessment.

In short

A VPN is a precise tool for a precise problem: hiding the destination of your traffic from whoever sits along the route.

It does not protect the content — that is already protected. It does not protect against deception — that passes through the tunnel like everything else. And it does not remove whoever watches you: it moves the watching onto a party you choose, which is an advantage only if you choose well.

Something to think about. If you use a VPN, could you say what it protects that the browser’s padlock does not already protect? If the answer does not come immediately, it is worth clarifying before the next renewal.

Explore this recommendation

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.