A VPN protects one part of the connection. It does not erase account history, stop you from typing a password into a phishing page, or replace endpoint security. Marketing that blurs those lines is selling comfort, not a threat model.
Editorial rule: keep the original evidence boundaries. Do not turn untested speed, access, pricing, or support claims into facts.
Where this advice breaks down
- An encrypted tunnel cannot undo credentials submitted to an attacker.
- A DNS-level blocker is not an antivirus engine.
- Signed-in accounts and browser sync can retain activity regardless of the VPN.
What changed — and what didn’t
A decade ago, much of the web sent data unencrypted. Someone on the same café network could read a great deal of what you did. That specific threat has shrunk considerably: encrypted connections are now the default across most of the web, and browsers flag the exceptions.
So the old advice — “anyone can read your passwords on public Wi-Fi” — overstates the current situation for most ordinary browsing.
What has not gone away:
- Traffic metadata. Even with encrypted connections, the network operator can see which sites you connect to.
- DNS visibility. Depending on your configuration, name lookups may be visible or handled by the network’s own resolver.
- Captive portals and redirection. Networks intercept your first request by design; that same mechanism can be abused.
- Deceptive access points. A network named to resemble a legitimate one is trivial to create.
- Unencrypted or misconfigured services. Not everything is encrypted, and older apps vary.
- Device-level exposure. File sharing left on, discoverable services, automatic connections to remembered names.
That last category is where most practical risk sits today, and it is the one a VPN does the least about.
What a VPN actually does
It creates an encrypted tunnel between your device and a server operated by the VPN provider. Traffic inside the tunnel is opaque to anyone on the local network — including the network operator.
Concretely, on a public network it prevents:
- The network operator from seeing which sites you visit
- Others on the same network from observing your traffic patterns
- DNS queries from being handled by, or visible to, the local network
- Some forms of local interception and redirection
That is a real and well-defined benefit. On a network you do not control and cannot verify, it is the clearest use case a VPN has.
What a VPN does not do
It does not make you anonymous. Sites still identify you by your account login, cookies, browser characteristics, and behavior. Signing into an account identifies you regardless of routing.
It does not protect a compromised device. If malware is running locally, it operates inside the tunnel.
It does not stop phishing. A convincing fake login page works identically through an encrypted tunnel.
It does not secure a weak password. Nor does it substitute for two-factor authentication.
It does not eliminate trust — it relocates it. Your traffic is no longer visible to the café’s network. It is now visible to the VPN provider instead. Whether that is an improvement depends on which party you would rather trust, and on what the provider’s own documentation says about handling and retention. Read that documentation directly rather than marketing summaries.
It does not make the connection faster. A tunnel adds a step.
A layered setup for travel
Ordered by how much protection they deliver per unit of effort.
1. Device hygiene — do this before you leave
- ☐ Operating system and applications fully updated
- ☐ Device encryption enabled
- ☐ Screen lock with a strong code, short timeout
- ☐ File sharing and network discovery turned off
- ☐ Automatic connection to open networks disabled
- ☐ Saved networks you no longer use, removed
- ☐ Backups current
The last item matters more than people expect. Loss and theft are more probable travel outcomes than network interception.
2. Account hardening
- ☐ Two-factor authentication on email, banking, and primary accounts
- ☐ Recovery codes stored somewhere you can reach without your phone
- ☐ A password manager, so credentials are unique per service
- ☐ Reviewed which devices are signed in
If you do only one thing from this article, make it two-factor authentication. It defends against far more realistic threats than network eavesdropping.
3. Connection habits
- ☐ Verify the network name with staff — do not guess from the list
- ☐ Prefer your phone’s tethering for anything sensitive
- ☐ Treat captive portals with suspicion; never enter account credentials into one
- ☐ Disconnect when you are finished
- ☐ Turn Wi-Fi off entirely when you are not using it
Tethering deserves emphasis. Your own mobile connection is not shared with strangers, and for short sensitive tasks it is often the simpler answer.
4. Then a VPN
With the above in place, a tunnel closes the remaining gap: it removes the local network’s visibility into where you go.
Practical notes:
- Enable it before you begin browsing, not after
- Understand what happens if the tunnel drops mid-session
- Prefer an endpoint that makes geographic sense for where you are
- Know that the provider’s policies, jurisdiction, and handling practices are what you are relying on — read them
Country rules matter
VPN use is regulated differently across jurisdictions. Some countries restrict or license it. The rules that apply to you are those of the country you are physically in, not the country your account belongs to.
Before traveling, check the current position for your destination through official sources. This is not something to rely on forum posts for, and it changes.
Separately, services you use — streaming, banking, gaming — have their own terms about connection methods and account region. Those are contractual matters between you and the service. Read the current terms directly.
What protects against what
| Risk | VPN helps? | What actually addresses it |
|---|---|---|
| Network sees which sites you visit | Yes | VPN |
| DNS visible to local network | Yes | VPN, or encrypted DNS |
| Local interception / redirection | Partly | VPN, plus verifying the network name |
| Phishing page | No | Password manager, 2FA, attention |
| Malware on device | No | Updates, care with downloads |
| Weak or reused password | No | Password manager |
| Account takeover | No | Two-factor authentication |
| Device lost or stolen | No | Encryption, screen lock, backups |
| Site identifies you | No | Nothing — you signed in |
The pattern is clear. A VPN covers the network layer well and nothing above it. Most realistic travel risks live above it.
FAQ
Is public Wi-Fi still dangerous? Less than the common warnings suggest, because most web traffic is now encrypted by default. The remaining exposure is metadata, DNS, deceptive access points, and device-level settings. Those are worth addressing.
Do I need a VPN on hotel Wi-Fi? It closes a genuine gap — the operator’s visibility into your browsing. Whether that matters to you depends on what you are doing. It is not a substitute for two-factor authentication or an updated device.
Is tethering from my phone safer than public Wi-Fi? For most purposes, yes. Your mobile connection is not shared with strangers on the same network. For short sensitive tasks it is often the simplest choice.
Does a VPN make me anonymous? No. It changes which party can see your traffic. Sites still identify you by login, cookies, and browser characteristics. Anonymity is a different problem with different tools.
Should I use a free VPN while traveling? The question to ask about any provider — free or paid — is how it funds itself and what it does with your traffic. Read its own policy documentation and jurisdiction. A tunnel means routing everything through that operator, so the answer matters.
What if the VPN disconnects mid-session? Your traffic reverts to the local network. Know how your client handles that before you rely on it, and check what happens on reconnection.
Is VPN use legal everywhere? No. Rules vary by country and change. The law that applies is that of the country you are physically in. Check official sources for your destination before traveling.
What is the single most useful thing I can do? Two-factor authentication on your important accounts. It addresses the most probable threats — credential theft and account takeover — which network encryption does nothing about.
Closing
A VPN does one thing well on public networks: it removes the local operator’s view of where you go. That is worth having on a network you cannot verify.
But it sits at one layer, and the risks that actually cost travelers money and time sit above it — reused passwords, missing two-factor authentication, unpatched devices, phishing, and lost hardware. Handle those first. Then add the tunnel to close the remaining gap.
This article covers general security practice. VPN use is regulated differently by jurisdiction, and services set their own terms about connection methods. Check official sources for the country you are in and the current terms of the services you use.
Related privacy and connection guides
Who should not use this approach
- Anyone looking for one app to replace MFA, updates, and antivirus
- Anyone who will ignore device or employer security policy
- Anyone who assumes a connected icon proves every threat is blocked
When this approach actually helps
- Users who separate connection privacy from device and account security
- People who pair a VPN with MFA, updates, and careful link handling
- Travelers using untrusted networks with a defined threat model
